Johannes Schoenborn

Johannes has been active in offensive cybersecurity since 2006. With a Master’s degree in Computer Science and a strong academic foundation, he pushes the boundaries of the field through advanced execution, AI-driven innovation, and next-generation talent development. As a certified OffSec instructor, he is dedicated to training the future leaders of cyber offense.

TIBER-DE vs. DORA: Wegweiser für Intrusion Tests im Finanzsektor 2026

10 min read

TIBER-DE vs. DORA: Wegweiser für Intrusion Tests im Finanzsektor 2026

Fast jedes zweite deutsche Finanzinstitut kämpft 2026 noch mit der Umsetzung von DORA, während die BaFin bereits die ersten Bußgelder von bis zu 5 Millionen Euro vorbereitet. Die Unsicherheit ist greifbar. Die regulatorische Überlappung im Bereich...

Read More

3 min read

Beyond the Certificate: Why Continuous, Role-Based Training is the Future of Cyber Readiness

Hackers don’t care what certifications your team held three years ago. They care about the vulnerabilities your team missed today and whether their...

Read More

3 min read

Attackers’ Truth: Adapting the Storm-2949 Cloud Breach for Red Teaming

In February 2026, a critical manufacturing organization was compromised not by zero-day malware, but by their own cloud architecture.

Read More

1 min read

Cybersecurity Breakfast Session together with the Austiran Business Council, Netherlands Business Council and the German Emirati Joint Council for Industry & Commerce

Speaking at the recent Austrian Business Council UAE cybersecurity event reinforced a critical market reality. The region is building the future, but...

Read More

3 min read

One-Off vs. Managed Pentesting: What Financial Institutions Must Know

Banks and large enterprises are not defined by a single website or mobile app. A modern financial institution might operate hundreds of...

Read More

2 min read

Pandas, Bears and Threat Actors: Why Red Teaming Goes Beyond CVEs

Why are there a panda and a bear in our current social media banners? They are not random mascots – they represent real-world threat actors (e.g.,...

Read More

1 min read

We have security solution X, do we even need a pentest?

"We already run Vectra and CrowdStrike — do we still need pentests?" This caught me a bit off-guard.

Read More