"This site requires JavaScript to work correctly"

CAMPUS VILSHOFEN

Cybersecurity – Research, Services, Education

Whether it be communication, mobility or energy supply, digitalisation is firmly embedded in our lives, both socially and economically. One of the most important challenges we face in this regard is cybersecurity: the protection of information technology and data against attacks or manipulation.

This is the mission of Campus Vilshofen, which we pursue in the areas of research, services and education.

About the "Cybersecurity campus"

Services

Our experienced team of penetration testers and researchers helps companies and organisations to assess and optimise their IT security through a range of specialist services.

Research

The campus-based research group DiSecT works closely with partners from industry and academia to develop technologies and methods with practical applications.

Education

Education at Campus Vilshofen includes degree programmes, doctorate opportunities, (professional) further education and the promotion of STEM subjects.

Campus Vilshofen is a research location of Deggendorf Institute of Technology specialising in cyber security. Our team of around 30 people comprises professors, academic and technical staff as well as students.

The campus was established as a technology transfer centre for digital security as part of the ‘Hightech Transfer Bayern’ initiative. As such, we strive to facilitate active knowledge and technology transfer between the institute, industry and society in everything we do.

 

Get in touch!

Whether company, organisation or public institution, we are your expert partner for general to detailed enquiries on all aspects of cybersecurity.

 

 

 

SERVICES

Digitalisation has become an integral part of our lives: processes are being automated and systems interconnected, data is stored in the cloud, and critical business applications are web-based.

Yet cybersecurity threats tend to be treated as little more than a footnote. In reality, ransomware and the like have significant financial and legal consequences.

 

Our experienced penetration testers and researchers put the security of your network or system through its paces. The team of ‘ethical hackers’ identifies vulnerabilities before attackers do.

Are you ready to strengthen your cyber security? Get in touch for a non-binding initial consultation!

Email us at tcv-itsecurity@th-deg.de or use the enquiry form.

A pentest (short for penetration test) is a targeted security assessment in which our experts identify vulnerabilities in a computer system, network or application and, depending on the agreement, may also exploit them. The aim is to find security vulnerabilities before attackers can do so.

Penetration tests come in various forms. These may, for example, cover a single system, a specific (web) application or a larger scope of systems.

Generally, a distinction is made between tests of internal and external infrastructure. When conducting a penetration test on internal infrastructure, additional aspects can be examined, such as SMB shares or Active Directory.

The Assumed Breach approach assumes that someone has already gained unauthorised access to the system or network. In this scenario, our specialists simulate how potential attackers might operate within your system to exfiltrate data (gain access to and export data) or cause further damage within the system (alter or encrypt data).

This approach enables us to analyse and assess the system’s resilience to advanced, internal threats. Specific, enhanced security measures are then recommended to minimise the consequences of a successful attack.

Active Directory is the central repository for all identities (users, computers, clients, groups, printers, etc.) on the corporate network.

During an Active Directory audit, our security experts identify vulnerabilities and potential attack vectors. To do this, they simulate various scenarios relating to, amongst other things, (Windows) configuration, permissions and security policies. 

The aim is to provide your organisation with recommendations for improving your security measures and policies in order to prevent unauthorised access and potential compromises.

An undetected data breach costs companies an average of 4.88 million dollars. If your data falls into the wrong hands, we can intervene at an early stage.

Cybercriminals operate in secret – on illegal platforms and on the dark web. This is where stolen data is traded, attacks are planned and vulnerabilities are discussed.

Our monitoring service covers the clearnet, the darknet and other relevant digital channels. It analyses billions of data points and detects leaked corporate information, compromised login credentials, exposed API keys and vulnerabilities in your digital infrastructure.

In a free initial consultation, including a demonstration, we’ll show you exactly how Darknet Monitoring protects your business.

As your Managed Service Provider, we take care of the complete implementation, configuration and ongoing operation of the Darknet Monitoring platform.

  • Seamless integration into your IT security infrastructure
  • Continuous 24/7 monitoring (analysis carried out during our business hours)
  • Regular threat reports, including recommendations for action
  • Incident response support in the event of critical findings
  • Half-yearly coverage reviews to ensure your monitoring is optimally configured

 

To assess how aware your staff are of the risks of phishing, we offer phishing simulations.

You can choose from three test packages of varying durations. In phishing campaigns lasting three to four days, we test your employees’ reactions to fake emails. Content can be selected from prepared templates and different scenarios

Should employees interact – for example, by clicking on links or entering login details – they will be redirected to a warning page.

Analyses can be carried out either after each campaign or at the end of the overall duration. The following parameters are taken into account:

  • Email open rate
  • Number of link clicks
  • Entry of login details
  • Activation of macros in documents sent
  • Percentage analysis based on all recipients

The security audit of a web application is designed to identify potential vulnerabilities and security gaps in a website and its underlying code.

A combination of penetration testing and secure code review ensures a comprehensive security assessment that not only takes external threats into account but also uncovers internal vulnerabilities in the application logic and code.

Security auditors use various methods for this purpose, including automated scans and manual testing. By simulating attack scenarios – such as SQL injections or cross-site scripting (XSS) – they test whether an attacker could gain access to confidential data or take control of the system.

Whilst a penetration test aims to identify vulnerabilities through active attacks, a secure code review focuses on an in-depth analysis of the source code. This process enables the identification of potential security vulnerabilities rooted in the programming itself. 

Design decisions, data validation methods, authentication systems and other critical elements are examined. This ensures that the application has been developed in a robust and secure manner from the outset. 

A final report contains recommendations for rectifying the vulnerabilities found and for improving the overall security of the web application.

SMB shares enable access to and sharing of files and services within a local network. This allows user accounts to access a shared drive, or various programmes to access a printer. However, potentially confidential or sensitive information is often stored without proper controls.

An SMB share check includes, amongst other things, a search for sensitive data and an analysis of the associated access permissions. Furthermore, it assesses whether inappropriate access rights exist and whether these could enable attackers to access sensitive data.

The test aims to identify weaknesses in access control and data security and to provide the organisation with appropriate recommendations.

This check assesses whether appropriate security measures have been put in place in the event that a company-owned device with access to the corporate network is lost or stolen.

It checks whether unauthorised access to sensitive information is prevented and whether the system is able to respond appropriately to the loss of the device.

A password audit provides valuable insights into an organisation’s password security. It involves cracking the hashes of all user accounts in Active Directory (the central repository for all network users) and analysing them statistically.

(Hashing is a method of storing passwords. Each password is represented by a unique string of characters, known as a hash value. Even if unauthorised parties obtain this value, they cannot reconstruct the password.)

By cracking hashes, security auditors can identify weak passwords – and thereby weaknesses in password choice in general.

One method is the so-called brute-force attack, in which we attempt to reconstruct the hash value by simply trying out different combinations. The simpler a password is, the quicker it can be cracked.

 

Statistical analysis in password audits

Statistical analysis reveals patterns and trends in password choice, which can serve as a basis for improved password policies and user training. 

This process helps the organisation to implement more robust security measures and strengthen the integrity of Active Directory.

Service Enquiries

Are you ready to take your cybersecurity to the next level?

Get in touch for a free non-binding consultation!

As your competent partner with expertise in both research and application we help you and your business to evaluate and optimise your security levels.

 

 

Research

Applied Cryptography

 

  • Cryptographic Engineering
  • Post-Quantum-Cryptography(PQC)

 

Professorship: Embedded IT Security and Mathematics – Prof. Dr. Martin Schramm

AI & Cybersecurity

 

  • AI for Cybersecurity
  • Cybersecurity for AI

 

Professorship: Artificial Intelligence for Cyberescurity – Prof. Dr. Michael Heigl

Human-Centered Security

 

  • the human factor in security architectures
  • security awareness and security culture

 

Professorship: Human-Centered Security – Prof. Dr. Manfred Vielberth

Our research group DiSecT carries out applied research and development work as part of publicly funded programmes and on behalf of companies. It is part of the cross-campus Institute for Secure, Autonomous and Connected Systems (ISACS).

In collaboration with our industrial partners, we develop methods and technologies to protect the digital space – from simple embedded systems to industrial automation technology and even critical infrastructure. This distinguishes our work from the basic research traditionally carried out at universities.

DiSecT is part of the cross-campus Institute for Secure, Autonomous and Connected Systems (ISACS). This institute brings together expertise in communication networks, artificial intelligence, mobility and cyber security, and develops solutions for complex cyber-physical systems.

You can find detailed information about our research activities as well as opportunities for collaboration on our research group’s webpage (english page coming soon).

EDUCATION

University Study

AI agents must not disclose our private data, and autonomous vehicles must not be controlled by unauthorised persons. On our cybersecurity degree programme, you’ll learn what security in IT systems means and how to achieve it.

This involves far more than just computer science with a sprinkling of security aspects: penetration testing, cryptology and digital forensics, for example. Graduates have a wide range of specialisation options open to them, from programming to management.

Primary teaching location for these degree programmes is the main campus in Deggendorf. Students come to our campus as part of practical courses, work placements, Bachelor’s and Master’s theses, and as student assistants (‘studentische Hilfskräfte’). Interested? Further details about this and promotion opportunities can be found on our research group’s webpage.

STEM Initiatives

We strive to inspire children and young people to engage with cybersecurity and programming. Thus, we regularly organise events, activities and workshops in collaboration with local secondary schools. During these, pupils can try their hand at assembling and programming a mini-PC, for example.

For vocational classes specialising in computer science, the programme goes even further: they can try their hand at finding vulnerabilities in a virtual environment on our gamified learning platform.

Depending on their career interests, pupils also have the opportunity to gain work experience at our campus.

MORE ABOUT THE CAMPUS

Founded: 2023

Location: Vilshofen (a. d. Donau), Germany

Academic Director: Prof. Dr. Martin Schramm, Prof. Dr. Michael Heigl

Operative Manager: Stefan Anthuber

Staff: 30

 

 

  • 2012
    DIT’s first cybersecurity research project: ANSII – Anomaly detection and embedded security in industrial information systems (led by Prof. Dr.-Ing. Andreas Grzemba)
     
  • 2013
    Establishment of the ProtectIT Institute with the following core areas of expertise: securing and hardening networked embedded systems; detecting anomalies and attacks; designing, developing and analysing appropriate response measures (led by Prof.-Ing. Andreas Grzemba, Prof. Dr.-Ing. Peter Fröhlich)

 

  • 2017
    Appointment of Dr Michael Schramm as Professor of “Applied Cryptography”

 

  • 2018
    Launch of the part-time Master’s programme Cyber Security, M.Eng.

 

  • 2019
    Launch of the Bachelor’s degree programme Cyber Security, B.Sc.

 

  • 2020
    Approval of Technology Transfer Centre for Digital Security in Vilshofen

 

  • 2021
    Start of construction of the new building, comprising workspaces, laboratories and training rooms

 

  • 2022
    – Appointment of Dr Michael Heigl as Professor of ‘Artificial Intelligence and Cybersecurity’
    – Completion of construction and relocation of the ProtectIT Institute to Campus Vilshofen (academic directors: Dr Schramm, Dr Heigl, Dr.-Ing. Grzemba)

 

  • 2023
    Grand opening of the Vilshofen Campus (academic directors: Dr Martin Schramm and Dr Michael Heigl; operational manger: Stefan Anthuber)

 

  • 2025
    Appointment of Dr Manfred Vielberth as Professor of “Human-Centred Security”

 

  • 2026
    The ProtectIT Institute takes the next step and becomes the research group DiSecT within the cross-site and interdisciplinary 'Institute for Secure, Autonomous and Connected Systems (ISACS)'

Not a fruit basket, but a job that makes a difference: we are regularly looking for academic and technical staff who want to help shape the future of digitalisation.

Current vacancies and general information can be found under Your Career at DIT.

The ‘Freunde und Förderer des Technologie Campus Vilshofen’, an association of supporters (‘Förderverein’), actively assist our campus on a not-for-profit basis in order to

  • promote research, teaching and professional development
  • support the maintenance and expansion of Campus Vilshofen
  • raise awareness of Campus Vilshofen and enhance its public reputation
  • promote the creation and expansion of networks amongst business, society, politics and academia
  • promote STEM activities for children and young people in collaboration with schools

 

For example, the association recognises outstanding final-year projects by our students or raises funds to support our STEM events.

 

Are you interested in becoming a member of the association? Write to us at info.tc-vilshofen@th-deg.de!

 

Founded: 2024
Chair: Florian Gams, Mayor of Vilshofen
Deputy Chairs: Prof. Dr Martin Schramm, Stefan Anthuber
Members: 27

directions

Technische Hochschule Deggendorf
Campus Vilshofen

Aidenbacher Straße 32
94474 Vilshofen an der Donau
Germany

Email: info.tc-vilshofen@th-deg.de

 

 

 

Click image to enlarge plan