{"id":15203,"date":"2026-05-18T09:21:43","date_gmt":"2026-05-18T09:21:43","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/05\/20\/nis2-compliance-in-medium-sized-businesses-achievable-steps-avoidable-mistakes\/"},"modified":"2026-07-09T16:38:25","modified_gmt":"2026-07-09T16:38:25","slug":"nis2-compliance-in-medium-sized-businesses-achievable-steps-avoidable-mistakes","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/05\/18\/nis2-compliance-in-medium-sized-businesses-achievable-steps-avoidable-mistakes\/","title":{"rendered":"NIS2 for Mid-Sized Firms: Achievable Steps, Avoidable Mistakes"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">6 min read<\/p>\n<p><strong>The NIS2 Implementation Act has been in force in Germany since 6 December 2025 \u2013 with no transition period. The registration deadline with the BSI expired on 6 March 2026. Around 29,500 companies in Germany now fall under the new obligations, many of them mid-sized and many still unregistered. The question is no longer whether NIS2 is coming, but how a mid-sized company can pragmatically implement it without turning it into a major project.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">The deadline has passed, but the obligation remains.<\/strong> NIS2 has applied since December 2025 without any transition period. Those who are not yet registered must catch up \u2013 the late registration process is still possible.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Ten areas of action, not a mega-project.<\/strong> The law requires structured risk management. Most mid-sized companies already have the building blocks in place \u2013 they just aren\u2019t documented.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Senior management is personally liable.<\/strong> NIS2 makes the approval and oversight of measures a board-level responsibility. This duty cannot be delegated to IT.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">The reporting chain must be practiced.<\/strong> 24-hour early warning, 72-hour notification, one-month final report. An untrained reporting path will burn the first deadline with administrative overhead.<\/li>\n<\/ul>\n<\/div>\n<p><strong>What is NIS2?<\/strong> NIS2 is the EU Directive on Network and Information Security, transposed into German law via the NIS2 Implementation Act (NIS2UmsuCG). It obliges companies classified as essential or important to maintain documented cybersecurity risk management, register with the BSI, and report significant security incidents.<\/p>\n<p style=\"font-size:0.88em;color:#b8c5ce;margin:20px 0 32px 0;border-top:1px solid rgba(230,227,218,0.12);border-bottom:1px solid rgba(230,227,218,0.12);padding:10px 0;\"><span style=\"color:#69d8ed;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/16\/nis2-technical-minimum-requirements-2026\/\" style=\"color:#333;text-decoration:underline;\">Where mid-sized firms still fall short on NIS2\u2019s technical minimums<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/28\/eu-ai-act-high-risk-deadline-august-2026-supervisory-gap\/\" style=\"color:#333;text-decoration:underline;\">EU AI Act: 2 August 2026 \u2013 Where the high-risk compliance gap yawns<\/a><\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">The deadline has already passed<\/h2>\n<p>Most NIS2 articles over the past two years ended with a future date. This one doesn\u2019t. The NIS2 Implementation Act was published in the Federal Law Gazette on 6 December 2025 and has been in force ever since. There is no phased roll-out or grace period, as many companies had hoped. The obligations take effect immediately upon publication.<\/p>\n<p>According to estimates by the BSI and BMI, this affects around 29,500 companies. The range spans from classic KRITIS operators deep into the mid-market, across sectors such as mechanical engineering, logistics, food production, chemicals, and IT service providers. Some of these companies still aren\u2019t sure whether they\u2019re affected. That\u2019s the first practical mistake: NIS2 requires self-assessment. No one will send you an official notice.<\/p>\n<div style=\"background:#003340;color:#fff;text-align:center;padding:40px 24px;margin:32px 0;border-radius:8px;\">\n<div style=\"font-size:3.4em;font-weight:800;color:#69d8ed;letter-spacing:-0.03em;line-height:1;\">around 29,500<\/div>\n<div style=\"font-size:1em;color:rgba(255,255,255,0.88);margin-top:12px;max-width:520px;margin-left:auto;margin-right:auto;line-height:1.5;\">companies in Germany fall under NIS2 obligations, a significant portion of them mid-market enterprises.<\/div>\n<div style=\"font-size:0.78em;color:rgba(255,255,255,0.5);margin-top:12px;\">Source: BSI \/ BMI, estimate on NIS2 implementation<\/div>\n<\/div>\n<p>The registration deadline with the BSI ended on 6 March 2026. Missing it doesn\u2019t let you off the hook \u2013 you\u2019re simply late. Registration via the BSI portal remains possible and must be completed; it requires an ELSTER organisation certificate. This step is small but essential, and in practice it\u2019s the one most often postponed.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What practical implementation demands<\/h2>\n<p>NIS2 doesn\u2019t impose an exotic set of requirements. The law mandates risk management across ten areas: risk analysis, incident response, business continuity including backup management, supply-chain security, secure procurement and development, effectiveness assessment, basic cyber hygiene and training, cryptography, personnel security and access control, and multi-factor authentication plus secure communication.<\/p>\n<p>The good news for most mid-market firms: much of this already exists in operations. Backups are running, access is managed, updates are applied. What\u2019s often missing isn\u2019t the substance but the structured documentation and proof that measures are effective. NIS2 doesn\u2019t just ask whether a backup exists \u2013 it asks when it was last successfully restored.<\/p>\n<p>The second component is the reporting obligation. A significant security incident triggers a three-tier timeline: an early warning to the BSI within 24 hours, a more detailed report within 72 hours, and a final report within one month. The 24-hour clock starts when the incident is known. Companies without an internal escalation path burn most of that window on internal coordination instead of reporting.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">The roadmap in four steps<\/h2>\n<p>NIS2 implementation can be run as a major project or as a structured sequence of four steps. For mid-market companies, the second approach is more reliable. It follows risk: clarify status first.<\/p>\n<h3>Step 1: Determine scope and register<\/h3>\n<p>Start with self-assessment: does the company fall under NIS2 based on size and sector, and if so, as an essential or important entity? This classification determines supervisory intensity and penalties. Once decided, register via the BSI portal. Without this step, every subsequent measure remains legally incomplete.<\/p>\n<h3>Step 2: Gap analysis across the ten areas<\/h3>\n<p>For each measure, honestly record what already exists, what exists but isn\u2019t documented, and what\u2019s missing. The result is usually less daunting than feared. The effort rarely lies in new technology but in making existing measures visible and verifiable.<\/p>\n<h3>Step 3: Establish and rehearse the reporting chain<\/h3>\n<p>The reporting path needs named roles, substitute rules, and fallback communication. The decisive factor is a dry run. Companies that simulate the 24-hour path from detection to BSI acknowledgment uncover organisational gaps before an actual incident \u2013 not during one.<\/p>\n<h3>Step 4: Involve Management and Secure Evidence<\/h3>\n<p>NIS2 requires management to approve risk measures and monitor their implementation. This duty cannot be delegated. In practice, this means: a documented resolution, regular review, and traceable evidence storage. Anything not documented may, in doubt, be considered undone.<\/p>\n<blockquote style=\"background:#f0f9fa;padding:24px 28px;margin:32px 0;font-style:italic;font-size:1.08em;color:#003340;border-radius:8px;\">\n<p>NIS2 doesn\u2019t ask whether a backup exists, but when it was last successfully restored.<\/p>\n<\/blockquote>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Costly Implementation Mistakes<\/h2>\n<p>Four patterns reliably cause problems in practice, and none of them are technical.<\/p>\n<p>The first mistake is postponing registration because it seems unimportant. It is the formal anchor of all compliance and the first point an authority examines. The second mistake is ignoring the supply chain. NIS2 explicitly holds service providers and suppliers accountable. Focusing only on your own IT draws the scope too narrowly.<\/p>\n<p>The third mistake is management attempting to delegate liability to the IT department. The law does not allow this, and an uninvolved leadership becomes immediately visible during audits. The fourth mistake is a reporting chain that exists on paper but has never been tested. An escalation path first used during an incident will not meet the 24-hour deadline.<\/p>\n<p>The technical side \u2013 what specific minimum measures a mid-sized company still owes \u2013 is explored in more depth in our analysis <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/16\/nis2-technical-minimum-requirements-2026\/\">on NIS2 technical minimums<\/a>. This article stays on the organizational level because most implementations fail there.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;padding-top:64px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>When did NIS2 enter into force in Germany?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The NIS2 Implementation Act was promulgated on 6 December 2025 and has been in force since then. There is no transition or grace period; obligations apply immediately upon enactment. The originally planned phased rollout never materialized.<\/p>\n<\/details>\n<details>\n<summary><strong>My company missed the registration deadline \u2013 what now?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The registration window at the BSI closed on 6 March 2026, but late registration remains possible and should be completed without delay. It is filed via the BSI portal and requires an ELSTER organization certificate. Registration is the prerequisite for all subsequent measures to be legally complete.<\/p>\n<\/details>\n<details>\n<summary><strong>What reporting deadlines apply to a security incident?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">A significant incident triggers three deadlines: an early warning to the BSI within 24 hours, a detailed report within 72 hours, and a final report within one month. The clock starts when the company becomes aware of the incident, not upon external notification.<\/p>\n<\/details>\n<details>\n<summary><strong>Is management personally liable?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes. NIS2 obliges management to approve risk-management measures and monitor their execution. This duty cannot be fully delegated to the IT department. A documented resolution and regular oversight by management are therefore part of compliance.<\/p>\n<\/details>\n<details>\n<summary><strong>Is NIS2 a major project for mid-sized firms?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Usually not. Most of the ten measure areas are already partially covered in daily operations. The effort lies mainly in structured documentation, effectiveness assessment, and establishing a tested reporting chain \u2013 not in building fundamentally new technology.<\/p>\n<\/details>\n<div style=\"background:#f0f9fa;border-radius:8px;padding:20px 24px;margin:24px 0;\">\n<!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/17\/72-percent-of-cyber-defense-comes-from-abroad\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/sicherheits-souveraenitaet-reboot-germany-c3a-katalog-cover-hero-2-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">72 percent of cyber defense comes from abroad<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/15\/copilot\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/copilot-cowork-autonome-agenten-soc-angriffsflaeche-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Copilot Cowork Acts Alone, the SOC Doesn\u2019t See It<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/privacy-watchdogs-target-mid-sized-firms\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/dsgvo-bussgeld-2026-mittelstand-aufsichtsbehoerden-72h-meldepflicht-cover-hero-1-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Privacy Watchdogs Target Mid-Sized Firms<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-bsi-kritis-cloud-multi-cloud-compliance-61618487.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Architecture Drives Compliance Costs: How to Cut Them<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/process-optimization-without-permanent-project-medium-sized\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-prozessoptimierung-ohne-dauerprojekt-mit-1854962-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Process Optimization Without Permanent Project<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/nis2-compels-cios-to-bring-edge-devices-into-audit-scope\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-industrial-iot-security-2026-warum-edge-97073470-250x187.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">NIS2 Compels CIOs to Bring Edge Devices Into Audit Scope<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"NIS2 takes effect from December 2025 without a transition period. A practical implementation roadmap for SMEs: feasible steps and costly mistakes.","protected":false},"author":10,"featured_media":15133,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"","_yoast_wpseo_title":"NIS2 Compliance in Medium-Sized Businesses: Achievable Steps, Avoidable Mistakes","_yoast_wpseo_metadesc":"NIS2 takes effect December 2025\u2014no grace period. Practical roadmap for SMEs: actionable steps & costly mistakes to avoid.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[255,259],"tags":[],"class_list":["post-15203","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en","category-strategie-governance-en"],"evm_reading_time_minutes":8,"wpml_language":"en","wpml_translation_of":15129,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/15203","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=15203"}],"version-history":[{"count":7,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/15203\/revisions"}],"predecessor-version":[{"id":21313,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/15203\/revisions\/21313"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/15133"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=15203"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=15203"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=15203"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}