INTELLIGENT
piXel
One company. No open doors. One standard.
Liability
The deadline has passed. Just under 18,900 entities are registered. The legislature had counted on roughly 29,500.
Germany’s NIS2 Implementation Act (NIS2UmsuCG) took effect on December 6, 2025, with no general transition period. Under section 33 of the German BSI Act (BSIG), anyone covered has to register with the BSI within 3 months, counted from the day they first qualify, or qualify again, as a covered entity. For everyone who already qualified when the act took effect, the deadline was March 6, 2026. In June 2026 the BSI wrote to industry associations that it expects every entity not yet registered to complete registration by July 31, 2026. That was not a statutory extension. That date has passed too. Just under 18,900 entities are registered, about 6,500 of them essential entities. The legislature had counted on roughly 29,500, using figures from the Federal Statistical Office. Whether that estimate holds is now being reexamined at the Interior Ministry’s request. None of that changes the obligation.
Whether you are covered comes down to 2 questions: your industry and your size. Annexes 1 and 2 of the BSIG list the sectors, from energy, transport, health, water, banking, and digital infrastructure to chemicals, food, machinery, waste management, and research. Within those sectors you generally count as an important entity if you employ at least 50 people, or if both your annual revenue and your balance sheet total exceed 10 million euros. Essential status starts at 250 employees, and only in the Annex 1 sectors. Some businesses are covered regardless of size, among them operators of critical installations, DNS service providers, and trust service providers. Energy grids, telecommunications, and financial firms fall under separate regimes that displace parts of the BSIG duties. It sounds clear-cut, and in a specific case it rarely is, not least because figures from affiliated companies can be counted toward yours. If you are not sure, we can sort through your activities, systems, and numbers together, so that the legal classification rests on figures that hold up. Write to me.
Registration is only the price of admission. What counts are the risk management measures under section 30 BSIG: appropriate, proportionate, and effective, with a minimum catalog of 10 items and a duty to document. And section 38 BSIG puts management personally on the hook: implement the measures, monitor their implementation, attend training regularly. On this point the directive requires approval; the German act requires implementation. You can delegate the work itself: to your IT staff, to a contractor, to me. The duty is addressed to management. That stays with you.
Under section 65 BSIG the fine lands on the entity, which means your company. For breaches of risk management, documentation, and reporting duties, that is up to 10 million euros for essential entities and up to 7 million for important ones. Where the worldwide total revenue of the undertaking to which the entity belongs exceeds 500 million euros, a percentage can take the place of the fixed amount: 2 percent for essential entities and 1.4 percent for important ones. Missing the registration alone costs up to 500,000 euros. Whether a company can recover from its managing director a fine imposed on the company is unsettled. For antitrust fines the question has been before the Court of Justice of the European Union since February 2025; for NIS2 fines nobody has decided it yet. Internal liability runs on a separate track: section 38(2) BSIG points to company law, which for a GmbH means section 43(2) GmbHG, liability to the company for losses caused by a breach of the duty of care; ordinary negligence is enough. Those losses can include business interruption, restoration costs, and third-party claims.
And if NIS2 does not apply to you, you are no better off. Art. 32 GDPR requires every controller and every processor to maintain a level of security appropriate to the risk, whenever personal data is involved. No headcount threshold, no industry filter. The question is never whether a duty applies. Only which one.
A firewall cannot be held liable. You can. IPServerSec explains how I harden servers. See IPServerSec.
Start
Here
You just read that you are liable. Now close the door.
You get me, not a ticket system, and I answer personally.
You can talk about ability, or you can put it out in the open.
rauscher.xyz carries more than 170 in-depth articles in German and English, plus Antrometric, a calculator that turns long bone measurements into a stature estimate and reports the formula, the model interval, and the accuracy index right alongside it, so a court can follow the arithmetic. I wrote IPServerSec myself, and it grew over years out of real attacks on real servers. 2 tools you can use right now, no sign-up, no invoice: encryptor.app encrypts messages and files up to 2 GB with AES-256-GCM, entirely inside your browser, so the plaintext never leaves your device. IP Beacon shows you what a stranger’s server learns about you the moment you visit it, and hands you a report as a PDF. Both are MIT-licensed, so you can read the code and take it with you. Nothing here is off the shelf. Nothing here is a framed certificate on a wall. You do not have to take my word for any of it. Read it, then decide.
Vibe
Coding
The most expensive code is the code that was easy to write.
The math now works in the attacker’s favor. What a specialist once built by hand now runs as a script against 10,000 servers at once. At the same time, new targets appear every day, because sole proprietors and managing directors have AI build their website or their application without the experience the job actually demands. The cost of an attack keeps falling while the attack surface keeps growing. That is not a forecast. That is this week.
It feels productive. It looks like it works. And almost every time, it opens holes nobody in the room can see.
Here is what most people miss. A single hole in an AI-built application is rarely the end of it. An attacker who gets in does not stop at that one site. He moves laterally through every application and all the data sitting on the same server. If that server also touches your corporate network, this is no longer a website problem. It is a company problem.
From 2000 to 2025 I worked as a court-appointed expert for public prosecutors and courts. That experience is why I will put it plainly. If you have security-critical code written by an AI and you cannot review the output, you are in a bad position when something goes wrong. The standard always depends on the specific case. That is exactly where the personal liability at the top of this page begins, and your legal structure does not change that. As a freelancer or a sole proprietor, you are already liable for everything you own, business and private. In a single-member GmbH, the company is initially the one on the hook to the outside world. Your problem starts when the incident kills the company. Then the insolvency administrator comes to the table, examines what duties you owed as managing director, and takes the loss out of your private assets. At that point, the fact that you signed off on yourself as the shareholder will only get you so far.
I use the same AI models. The difference is 42 years of writing code, which is what tells me where these models get it wrong, and a review of the generated code before anything goes live.
IPServerSec
Server protection I wrote myself.
IPServerSec is my own hardening and early-warning system for Linux servers. Not a plugin someone else built, not a subscription, but a system grown over years out of real attacks on real servers. It runs across my entire server fleet and on my clients’ systems.
It blocks, it detects, it alerts, and it documents. That last part is the one most people underestimate. When something goes wrong, nobody asks whether you had a security system. They ask whether you can prove it.
Nothing here comes off the shelf. Every server gets its own rule set, built over 3 weeks against your real traffic, because a mail server needs different rules than an online store and a database server needs different rules than a VPN gateway. If you want, I will take over your servers entirely: hardened, monitored, and run by me in EU data centers.
Software
I build what runs on your systems.
I have been writing code for 42 years. It started on Commodore and Amiga, application software and games, back when you answered for every byte yourself. Websites came in 1998, and the applications behind them soon after. Every common language since, because a language is a tool, not a belief. Today it is apps for iOS and macOS, systems that run on servers, web applications, and the interfaces in between, so your tools talk to each other instead of past each other.
Underneath that sits the infrastructure: my own DNS, registration of any domain you need, and my own mail server, run on hardware inside the EU and built to meet GDPR requirements. Whatever software you need comes from one pair of hands.
One boundary, so we can skip that part of the first call: I build and run servers on Linux only. I answer for what I can fully inspect, verify, and maintain myself. Why I pass on Windows servers is a longer story, and it does not belong on a website. If Windows is what you need, a Windows specialist will serve you better than I will.
AI
Intelligence you can actually deploy.
Beyond the security work, I build AI where it earns its place. AI systems, real-time voice agents, and chatbots, designed, deployed, and hosted inside the EU, wired into your existing tools through the APIs you already run. Not a pilot that never ships. Something that works on real data, at real scale, and stays yours.
Underneath that sits the layer nobody talks about: databases. Classic relational systems where structure matters, and vector databases like Qdrant where meaning matters, so your own material becomes searchable, not just your folder tree. Then the analysis. Most companies are sitting on answers nobody ever asked for, because nobody showed them which questions their data will actually support. That is exactly what I show you.
Advisory
Not only the systems but also the people in front of them.
I advise managing directors and the self-employed on how to set up and harden their own devices: the phone, the laptop, the hardware that holds half a life. The open door is often not the server in the data center. It is the phone in your pocket.
Remote support runs over RustDesk on my own relay and server hardware inside the EU, not through a third-party cloud. The connection to it runs over your provider’s public networks and is end-to-end encrypted. That is the difference from the usual remote-support tools that route your session through a vendor’s cloud. I do not hand the keys to someone else.
Forensics
After the breach, I write what actually happened.
When a Linux system has been compromised, I reconstruct the case: how the server was protected at the moment of the attack, how the attackers got in, and what they did once inside. I build that reconstruction with help from capable AI models. Personal data from your systems goes to them only under a prior written agreement, and only to providers covered by a data processing agreement under Art. 28 GDPR. Otherwise the analysis stays local. I document the reconstruction so that it is technically verifiable and meets the requirements for use in court. Whether a court follows it is for the court alone to decide. It is the point where 25 years of forensic work and the security work speak the same language.
What has crossed my desk in 25 years as a court-appointed expert stays in the files. I do not tell case stories, not even anonymized ones.
For traditional forensic anthropology, the assessment of bones and skulls, see rauscher.xyz.
Origin
I was online while the network still screamed.
In 1998 I registered my first business and built websites when a single gigabyte of data transfer still cost 300 German marks. I did that worldwide, back when the word “cloud” still meant weather.
By then I had been at a keyboard for 14 years. An Amstrad, a C64 with a freezer cartridge I built myself, then every Amiga there was, and a 20 MB hard drive the size of a printer. You reached the network through an acoustic coupler, the telephone handset pressed into the rubber cups. I did not learn the tools. I watched them grow, from the ground up, layer by layer.
This is not nostalgia. It is the reason I can see where a system is about to break before it breaks. If you know how something was built from the bottom up, you see the cracks at the top first.
Relationships
My clients stay. Some since 1998.
I look after clients who have been with me for more than 25 years. That is no accident. It is what happens when you solve problems instead of managing them. Those are exactly the relationships I am looking for: people and companies who want one fixed point of contact who will still know their systems years from now, not a ticket system and not a different name in support every time.
If you are looking for someone who will still know how your infrastructure is built 10 years from now, because he built it, you are in the right place. My clients are spread across the world, from medical practices to law firms, across industries and time zones.
Worldwide
I work worldwide. There is a reason, and it is not a pleasant one.
I have worked across borders since 1998, back then over an acoustic coupler, today over networks that did not exist at the time. Where my desk sits has never mattered to the work. For you, that means time zone and mailing address are irrelevant. Accountability is not.
The second reason is less comfortable. The German economy is weakening, and I do not see that in statistics. I see it in my own client list. Long-standing clients are shutting down, filing for insolvency, or they literally cannot afford anything anymore. I am talking about companies that did well for 20 years.
I say that openly because I am not going to dress it up. I would not start a business in Germany today. Who knows. In a few years I may be working from somewhere that still rewards effort. None of that changes our working relationship, because it never depended on an address in the first place. Your servers stay in the EU. Your point of contact stays the same.
German and English, EU-hosted, location-independent. That has always been true. It is just more visible right now.
George A.
Rauscher
Started coding at 14. Built his own operating system at 16.
He took systems apart to find out whether the walls everyone assumed were solid actually held. Most of the time they did not. That same instinct later moved him to the other side of the table, where, from 2000 to 2025, he reconstructed for prosecutors and the courts how a system was broken, and by whom.
The attacker’s mindset never went away. It just changed employers.
Contact
The one door that should be open.
The fastest way to get in touch, with no obligation, is Telegram. Telegram is operated by a provider in the United Arab Emirates, and the EU has issued no adequacy decision for that country under Art. 45 GDPR. For confidential or personal content, please use the contact form or email. Anonymous first inquiries are welcome through any of these routes. I do not ask who you are, and I require no proof. To reply, I need an email address, and it does not have to point back to you.
Telegram: @intelligentpixel
Email: my@intelligent-pixel.com
The legal statements on this page reflect the general position as of August 8, 2026. They explain the background for my technical services and are not legal advice. They do not replace an assessment of your individual case by a qualified lawyer.