Focus

IT-Security

Secure software starts with solid architecture, from classic web applications to agentic AI systems.

Security as Part of the Architecture

IT security should be considered from the outset across architecture, development, and operations. For existing systems, the focus is on systematically identifying vulnerabilities, assessing risks, and developing appropriate measures rather than adding security only as an afterthought.

This applies to traditional web applications and APIs as well as to agentic systems and LLM-powered applications. These introduce additional attack vectors, such as prompt injection, unsafe tool interactions, and data exfiltration, placing new demands on existing security approaches.

We offer the following formats covering different aspects of IT security:

  • Agentic Software Security: A two-day training on the security risks of agentic systems and LLM-based applications.
  • Web Security: Designing secure web applications and avoiding common vulnerabilities.
  • OWASP Top Ten in Practice: Understanding and fixing web application vulnerabilities from an attacker’s perspective.

This page brings together articles, the Security Podcast, talks, and case studies on IT security.

Our Services

We advise honestly, think innovatively and love to build. The result: successful software solutions, infrastructures and business models.

Primers

Case Studies

Case Study

DEVK: Standardizing Security and Compliance Across a Complex Software Landscape

Avatar of Christopher Stolle
Principal Consultant

We’d love to assist you in your digitalization efforts from start to finish. Please do not hesitate to contact us.

Get in touch!

Kontaktformular

Frequently Asked Questions

Do you have questions about IT Security? Here you will find answers to questions we are frequently asked.

Why should IT security be part of your software architecture?

Retrofitting security at the end costs you twice: expensive rework and software that remains vulnerable. That’s why we treat IT security as an integral part of software architecture – from authentication and access control to secure communication between services.

What does Identity and Access Management (IAM) involve, and when do I need support?

Identity and Access Management governs who can access which resources in your systems. In mature system landscapes with microservices and APIs, this quickly becomes complex. We support you with the selection and integration of IAM solutions, authorization architectures, and the implementation of concepts such as role-based, policy-based, or relationship-based access control.

How can security be integrated into the development process (DevSecOps)?

By embedding security checks into your CI/CD pipeline – for example with tools for static and dynamic code analysis (SAST, DAST) and Software Composition Analysis (SCA). Security champion programs and secure coding guidelines further help teams treat security as part of their daily work.

What security risks do AI applications and agentic systems introduce?

AI-powered applications and AI agents open up new attack vectors that traditional security concepts only partially cover. These include prompt injection, tool misuse, and data exfiltration. We help you address these risks from the outset through threat modeling, guardrails, sandboxing, and secure architectures – guided by the OWASP Top 10 for LLM and Agentic Applications.

What is a security review, and when does it make sense?

A security review analyzes your security-critical components – from source code and APIs to architectures and protocols. It makes sense when you want to identify vulnerabilities before they become risks. The result: prioritized recommendations for action, tailored to your audience – from the development team to the C-suite.

How does INNOQ ensure our team can manage security independently going forward?

As long as necessary, as briefly as possible. We enable your teams through knowledge transfer, security champion programs, and working alongside them. We also offer hands-on training – from web security and OWASP Top 10 to agentic software security.