INTELLIGENT
piXel
One company. No open doors. One standard.
Liability
The deadline has passed. Roughly 10,500 entities have not registered. That number is the gap between 2 figures the BSI itself published.
Germany’s NIS2 Implementation Act (NIS2UmsuCG) took effect on December 6, 2025, with no transition period. Under section 33 of the German BSI Act (BSIG), affected entities must register within 3 months of first meeting the criteria. For everyone who already met them when the act took effect, that deadline fell on March 6, 2026. The BSI then stated publicly that it would initially refrain from enforcement where registration was completed by July 31, 2026. That was not a statutory extension, and that date has passed too. Just over 19,000 entities have registered against the roughly 29,500 the BSI expects, and the agency has explicitly reserved the right to impose fines.
Registration is only the price of admission. What counts are the risk management measures under section 30 of the German BSI Act (BSIG), and section 38 BSIG puts management personally on the hook: approve the measures, monitor their implementation, attend training regularly. You can delegate the work itself, to your IT staff, to a contractor, to me. The responsibility for seeing that it happens stays with you.
Your company pays the fine. For essential entities, up to 10 million euros or 2 percent of global annual revenue, whichever is higher; for important entities, up to 7 million euros or 1.4 percent. The missed registration on its own carries a fine of up to 500,000 euros. Whether a company can recover from its managing director a fine imposed on the company remains unsettled at Germany’s highest courts. Separately, a managing director is liable to the company under section 43(2) GmbHG for losses caused by a breach of his duty of care, and ordinary negligence is enough. Those losses include business interruption, restoration costs, and third-party claims.
And if NIS2 does not apply to you, you are no better off. Art. 32 GDPR requires every controller and every processor to take measures appropriate to the risk, with no headcount threshold and no industry filter. The question is never whether a duty applies. Only which one.
A firewall cannot be held liable. You can. IPServerSec explains how I harden servers. See IPServerSec.
The legal statements on this page reflect the general position at the time of publication. They explain the background for my technical services and are not legal advice. They do not replace an assessment of your individual case by a qualified lawyer.
Start
Here
You just read that you are liable. Now close the door.
You get me, not a ticket system, and I answer personally.
You can talk about ability, or you can put it out in the open.
rauscher.xyz carries more than 170 in-depth articles in German and English, plus Antrometric, a calculator that turns long bone measurements into a stature estimate and reports the formula, the model interval, and the accuracy index right alongside it, so a court can follow the arithmetic. I wrote IPServerSec myself, and it grew over years out of real attacks on real servers. Nothing here is off the shelf. Nothing here is a framed certificate on a wall. You do not have to take my word for any of it. Read it, then decide.
Vibe
Coding
The most expensive code is the code that was easy to write.
The math now works in the attacker’s favor. What a specialist once built by hand now runs as a script against 10,000 servers at once. At the same time, new targets appear every day, because sole proprietors and managing directors have AI build their website or their application without the experience the job actually demands. The cost of an attack keeps falling while the attack surface keeps growing. That is not a forecast. That is this week.
It feels productive. It looks like it works. And almost every time, it opens holes nobody in the room can see.
Here is what most people miss. A single hole in an AI-built application is rarely the end of it. An attacker who gets in does not stop at that one site. He moves laterally through every application and all the data sitting on the same server. If that server also touches your corporate network, this is no longer a website problem. It is a company problem.
From 2000 to 2025 I worked as a court-appointed expert for public prosecutors and courts. That experience is why I will put it plainly. Handing security-critical code to an AI when you lack the expertise to review the output is a breach of your duty of care. That is exactly where the personal liability at the top of this page begins: your own company’s claim against you.
I use the same AI models. The difference is 42 years of writing code, which is what tells me where these models get it wrong, and a review of the generated code before anything goes live.
IPServerSec
Server protection I wrote myself.
IPServerSec is my own hardening and early-warning system for Linux servers. Not a plugin someone else built, not a subscription, but a system grown over years out of real attacks on real servers. It runs across my entire server fleet and on my clients’ systems.
It blocks, it detects, it alerts, and it documents. That last part is the one most people underestimate. When something goes wrong, nobody asks whether you had a security system. They ask whether you can prove it.
Nothing here comes off the shelf. Every server gets its own rule set, built over 3 weeks against your real traffic, because a mail server needs different rules than an online store and a database server needs different rules than a VPN gateway. If you want, I will take over your servers entirely: hardened, monitored, and run by me in EU data centers.
Software
I build what runs on your systems.
I have been writing code for 42 years. It started on Commodore and Amiga, application software and games, back when you answered for every byte yourself. Websites came in 1998, and the applications behind them soon after. Every common language since, because a language is a tool, not a belief. Today it is apps for iOS and macOS, systems that run on servers, web applications, and the interfaces in between, so your tools talk to each other instead of past each other.
Underneath that sits the infrastructure: my own DNS, registration of any domain you need, and my own mail server, run on hardware inside the EU and built to meet GDPR requirements. Whatever software you need comes from one pair of hands.
AI
Intelligence you can actually deploy.
Beyond the security work, I build AI where it earns its place. AI systems, real-time voice agents, and chatbots, designed, deployed, and hosted inside the EU, wired into your existing tools through the APIs you already run. Not a pilot that never ships. Something that works on real data, at real scale, and stays yours.
Advisory
Not only the systems but also the people in front of them.
I advise managing directors and the self-employed on how to set up and harden their own devices: the phone, the laptop, the hardware that holds half a life. The open door is often not the server in the data center. It is the phone in your pocket.
Remote support runs over RustDesk on my own relay and server hardware inside the EU, not through a third-party cloud. The connection to it runs over your provider’s public networks and is end-to-end encrypted. That is the difference from the usual remote-support tools that route your session through a vendor’s cloud. I do not hand the keys to someone else.
Forensics
After the breach, I write what actually happened.
When a Linux system has been compromised, I reconstruct the case: how the server was protected at the moment of the attack, how the attackers got in, and what they did once inside. I build that reconstruction with help from capable AI models. Personal data from your systems goes to them only under a prior written agreement, and only to providers covered by a data processing agreement under Art. 28 GDPR. Otherwise the analysis stays local. I document the reconstruction so that it is technically verifiable and meets the requirements for use in court. Whether a court follows it is for the court alone to decide. It is the point where 25 years of forensic work and the security work speak the same language.
For traditional forensic anthropology, the assessment of bones and skulls, see rauscher.xyz.
Origin
I was online while the network still screamed.
In 1998 I registered my first business and built websites when a single gigabyte of data transfer still cost 300 German marks. I did that worldwide, back when the word “cloud” still meant weather.
By then I had been at a keyboard for 14 years. An Amstrad, a C64 with a freezer cartridge I built myself, then every Amiga there was, and a 20 MB hard drive the size of a printer. You reached the network through an acoustic coupler, the telephone handset pressed into the rubber cups. I did not learn the tools. I watched them grow, from the ground up, layer by layer.
This is not nostalgia. It is the reason I can see where a system is about to break before it breaks. If you know how something was built from the bottom up, you see the cracks at the top first.
Relationships
My clients stay. Some since 1998.
I look after clients who have been with me for more than 25 years. That is no accident. It is what happens when you solve problems instead of managing them. Those are exactly the relationships I am looking for: people and companies who want one fixed point of contact who will still know their systems years from now, not a ticket system and not a different name in support every time.
If you are looking for someone who will still know how your infrastructure is built 10 years from now, because he built it, you are in the right place. My clients are spread across the world, from medical practices to law firms, across industries and time zones.
George A.
Rauscher
Started coding at 14. Built his own operating system at 16.
He took systems apart to find out whether the walls everyone assumed were solid actually held. Most of the time they did not. That same instinct later moved him to the other side of the table, where, from 2000 to 2025, he reconstructed for prosecutors and the courts how a system was broken, and by whom.
The attacker’s mindset never went away. It just changed employers.
Contact
The one door that should be open.
The fastest way to get in touch, with no obligation, is Telegram. Telegram is operated by a provider in the United Arab Emirates, and the EU has issued no adequacy decision for that country under Art. 45 GDPR. For confidential or personal content, please use the contact form or email. Anonymous first inquiries are welcome through any of these routes. I do not ask who you are, and I require no proof. To reply, I need an email address, and it does not have to point back to you.
Telegram: @intelligentpixel
Email: my@intelligent-pixel.com