CyOne Security AG
Hard
Standard IT: Identifying and Closing Security Vulnerabilities
- 07 August 2026
- 100%
- Permanent position
- Hard
Job summary
IT infrastructure in public authorities is crucial for safety.
Tasks
- Ensure secure and efficient use of IT resources.
- Protect sensitive data from cyber threats effectively.
- Implement additional security measures for COTS products.
Skills
- Experience in IT security and risk management required.
- Knowledge of cybersecurity practices and standards.
- Ability to configure and monitor security solutions.
Is this helpful?
About the job
The demands on a good IT infrastructure in the public sector are high. It must be secure and efficient in use, while also cost-effective. For end devices, server hardware, software, printers, and more, authorities often rely on proven products from the common standard range (COTS). This is sensible – but also carries cyber risks. This blog post explains which measures can ensure that even standard IT ultimately meets the high security requirements of public authorities.
Public sector employees often process particularly sensitive information – such as confidential protocols, infrastructure plans, or strategic concepts. If this data falls into the wrong hands, unforeseeable consequences up to political crises can arise. Therefore, it is especially important for authorities to protect their IT infrastructure from cyber-attacks. At the same time, cost pressure is enormous. For reasons of efficiency and to use resources optimally, authorities often purchase mass-produced standard products for hardware and software, so-called COTS (Commercial off-the-shelf).
COTS devices carry high cyber risks
The use of COTS devices presents additional challenges for authorities: on the one hand, standard products are usually not sufficiently hardened and often have unnecessary software packages pre-installed. On the other hand, supply chains for standard IT components are generally difficult to trace and control. The lack of this necessary visibility and verifiability can increase cyber risks for authorities, as supply chain attacks are expected to become more frequent in the future. Hardware or software may already be compromised at the factory; additional danger also arises from manipulated updates that can be installed on authority end devices.
Entry point for cyber criminals
Fundamental changes in the working world exacerbate this threat situation. New smart forms of collaboration such as hybrid working models and home office are increasingly being adopted by public sector organisations. To enable public sector employees to perform their tasks at any time, they receive access to sensitive information from home or on the go – even though mobile devices are often not adequately protected. The same applies to peripherals such as printers. Weak device management, inadequate configuration and security settings, or missing security updates are additional vulnerabilities and can be exploited by cyber criminals as entry points.
Standard IT requires additional security measures
IT managers in authorities face the challenge of enabling external data access while guaranteeing a high level of cyber resilience in their IT landscape. The good news: a high level of security is also possible with existing standard IT. However, the existing hardware must be extended with additional, securely configurable and monitorable security functionalities such as security hardware and security firmware elements. These complement the existing standard security mechanisms and are thus additionally hardened and managed. With these additional security measures, a top security level can be achieved even with standard IT components, right out to the periphery. And this is cost-effective, as the existing infrastructure can be used.
CyOne Security supports authorities in protecting their information. Based on security hardware, peripherals and mobile IT components are securely connected via IP / VPN to the central IT infrastructure. With the highest cryptographic expertise and many years of experience in 360° security concepts and solutions up to the "Secret" level, all necessary security requirements can be met, ensuring that even standard IT in authorities is maximally protected against cyber-attacks.
Would you also like to bring your existing IT infrastructure to a top level in terms of IT security? Together with you, we develop individual solutions for your specific security requirements and implement them professionally.