THREAT BRIEFING · 14.09.2026 DEENFRES

Practice & Implementation

How Decision-Makers Can Prevent Attacks on Mail Servers

By Tobias Massow · April 7, 2021 · 4 min read

According to the German Association of the Internet Industry (eco), decision-makers must urgently bolster their defenses against the rising tide of attacks targeting email servers. Patch management is the single most critical component of corporate security strategy.

Against the backdrop of recently disclosed attacks on email servers, eco – the German Association of the Internet Industry – urges companies to rigorously review both their incident response planning and their patch management practices. Markus Schaffrin, eco’s cybersecurity expert and Head of Member Services, states: “Security vulnerabilities in software that can be exploited quickly underscore, time and again, just how vital up-to-date patch management and robust incident preparedness are for any organization.”

Cybersecurity experts confirm the paramount importance of both topics when strengthening IT security. According to eco’s 2021 IT Security Study, 88 percent of companies surveyed by eco rate patch management as a very important element of their security strategy.

Implementation Falls Short

Yet execution remains inconsistent across many organizations. Eco’s IT Security Study reveals that only around 69 percent of companies have established internal processes to respond effectively to incidents. Another 19 percent at least plan to implement such an incident response plan in the near term. Equally essential is maintaining continuous awareness of emerging threats.

“Up-to-date intelligence on the status of deployed systems and software forms the foundation for sound decision-making – and for effective patching and incident response,” says Schaffrin. He offers five concrete tips to help prevent security vulnerabilities – especially in email servers – in the future:

 

 

 

Key Facts

Average dwell time: Attackers remain undetected inside corporate networks for an average of 204 days.

SMEs in the crosshairs: 43 percent of all cyberattacks target small and medium-sized enterprises (SMEs).

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What’s the difference between data protection and information security?

Data protection governs the lawful handling of personal data – including legal basis, purpose limitation, and data subject rights. Information security encompasses the technical and organizational measures designed to protect all data against loss, tampering, or unauthorized access.

Does every company need a Data Protection Officer (DPO)?

Under German law, appointing a DPO is mandatory if at least 20 people are regularly engaged in the automated processing of personal data – or if special categories of personal data (e.g., health data) are processed.

What rights do data subjects have under the GDPR?

The right of access, the right to rectification, the right to erasure (“right to be forgotten”), the right to restriction of processing, the right to data portability, and the right to object. Companies must respond to such requests within one month.

Related Articles

More from the MBF Media Network

Digital ChiefsStrategic IT Decisions for ExecutivesMyBusinessFutureBusiness Future: Trends for Decision-Makers

TL;DR

Further reading

Practice & Implementation · July 31, 2026

Anthropic: Claude Breached Three Companies

Anthropic's Claude compromised three organizations in cyber evaluations. Harness misconfiguration, PyPI malware, and CISO checklist insights.

Practice & Implementation · July 29, 2026

Codex Security: Open Client Feeds OpenAI

Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.

A magazine by Evernine Media GmbH