
The 10 mandatory measures under §30 BSIG in detail – with specific email relevance for each individual measure.
§30 of the revised BSI Act is the centerpiece of NIS2 implementation in Germany. It defines ten specific areas of measures that affected companies must implement. Many of them have a direct connection to email security – the No. 1 attack vector.
Legal requirement: Concepts for risk analysis and security for information systems.
Email relevance: Email is the most important attack vector. Every risk analysis must centrally consider the email infrastructure:
Conbool solution: The dashboard provides real-time transparency across the entire mail flow. Compliance reports provide the basis for risk analysis.
Legal requirement: Detection, analysis, containment, and management of security incidents.
Email relevance: Most incidents start via email. Required are:
Conbool solution: MailGuard detects threats with AI-based analysis. Quarantine, tracing, and audit logs enable rapid incident management.
Legal requirement: Business continuity management and crisis management.
Email relevance: Email availability is business-critical. Backup strategies for email configurations and archiving are required.
Legal requirement: Security in the supply chain including security-related aspects of relationships between entities and their service providers.
Email relevance: Communication with suppliers and partners must be encrypted. Even small suppliers without their own encryption must be included.
Conbool solution: The Message Portal enables encrypted communication with partners – even without their own S/MIME or PGP infrastructure.
Die neuesten Beiträge aus unserem Blog.

Die richtige Konfiguration eines Secure Email Gateways entscheidet über Sicherheit und Nutzererfahrung. Diese 10 Best Practices helfen IT-Teams bei der optimalen Einrichtung.

Die Auswahl des richtigen Email Security Gateways ist entscheidend für die Sicherheit der Unternehmenskommunikation. Dieser Vergleich zeigt die wichtigsten Kriterien und typische Fallstricke.

Microsoft 365 bietet Basis-Sicherheit, aber kein vollständiges Email Security Gateway. Dieser Guide zeigt, welche Lücken bestehen und wie ein externes Gateway sie schließt.
Legal requirement: Vulnerability management and disclosure.
Email relevance: Email systems must be regularly checked for vulnerabilities and updated. Gateway solutions handle updates automatically.
Legal requirement: Concepts for assessing the effectiveness of risk management measures.
Email relevance: The effectiveness of spam filters, encryption, and access controls must be regularly evaluated. Audit logs and reports are essential for this purpose.
Legal requirement: Basic cyber hygiene practices and cybersecurity training.
Email relevance: Employee training on phishing detection is mandatory. Technical measures like MailGuard complement the human line of defense.
Legal requirement: Concepts and procedures for the use of cryptographic methods and, where applicable, encryption.
Email relevance – THE central measure for email:
Conbool solution: SecureMail automates all email encryption. Central certificate and key management with MPKI integration. BSI TR-02102 compliant algorithms.
Legal requirement: Personnel security, access control concepts, and asset management.
Email relevance: Access to email administration and quarantine must be role-based. MFA for administrative access.
Conbool solution: Role-based access management with Entra ID/LDAP integration and SAML SSO.
Legal requirement: Use of multi-factor authentication solutions, secured voice, video, and text communication, as well as secured emergency communication.
Email relevance:
Conbool solution: Gateway encryption + Secure Message Portal for external recipients. Verifiable delivery with complete audit trail.
The cryptographic methods used must reflect the state of the art. The BSI Technical Guideline TR-02102 defines the approved algorithms:
Permitted:
No longer permitted:
Conbool SecureMail exclusively uses BSI TR-02102 compliant algorithms and automatically updates when new recommendations are issued.
§30 BSIG requires not only the implementation but also the documentation of measures. For email, this means:
Of the 10 mandatory measures under §30 BSIG, at least 6 directly affect email security. Email is not a peripheral topic of NIS2 compliance – it is the central attack point where encryption, threat protection, and auditing converge.
Conbool makes implementation simple: One platform for all email requirements, set up in minutes and auditable.
Further reading: