There are topics in IT that nobody speaks about. Not because they are taboo — but because they are inconvenient. Because they touch a privilege sacred to many managing directors: the assumption that IT runs anyway. That you don’t have to look as long as nothing burns. That security, quality and cleanliness are nice ideas that pay off, if at all, only in a fiscal quarter that isn’t theirs.

This text is about what gets lost in the process.

The two sentences

Two sentences I have heard more often in twenty-five years of professional life than is dear to me. The first: “Security only costs money, it runs anyway.” The second usually follows a few sentences later: “We’ve never had a problem.”

Both sentences sound pragmatic. Neither is. Both are rationalisations of an attitude that essentially says: I don’t want to look, and I’m looking for a formulation that makes that sound responsible.

In the 2000s this attitude was negligent. Today it is grossly negligent. The difference is not rhetorical — it is the gap between a system that occasionally fails and one that systematically fails the moment someone seriously examines it.

IT security: the penny saved before the mind’s eye

There is an attitude I have never understood. It belongs to a certain kind of so-called businessman for whom every cent that doesn’t immediately yield revenue is a cent lost. Security appears to them as a cost item with no equivalent — insurance that never pays out, a fire extinguisher never needed. So they cut it. Year after year. Until eventually something burns.

Back then, in the 2000s, you could call it negligent. Dim, even. The world was more manageable, the attack surface smaller, attackers rarer. Those who did nothing often got lucky. Luck held because hardly anyone was actively looking.

Today the situation is different. Threat hasn’t developed linearly but exponentially. What used to be a lone attacker with plenty of time is now an automated scanner combing tens of thousands of networks overnight. What used to be a hand-typed exploit chain is now an AI-assisted proof-of-concept available within hours of a vulnerability’s disclosure. Whoever cuts security in this climate acts no longer negligently. Gross negligence is the term. Legally a different word. Morally the same.

The new threat landscape

Three developments have sharpened the picture in recent years.

First: artificial intelligence discovers security problems that previously stayed hidden. What a human auditor took weeks to find, an AI-supported scanner finds in hours. That holds for defenders — and a fortiori for attackers. Vulnerabilities that rested in half-light are now brightly lit. Whoever leaves them open must reckon with someone else opening them.

Second: patching grows harder. Dependencies interlock deeper, supply chains grow longer, one update pulls the next. Whoever patches must test. Whoever doesn’t patch risks a published flaw being exploited within days. The window closes. Short-term reaction becomes the norm, not the exception.

Third: exploits today mean dramas. No longer merely a defective server, but compromised customer data, extorted hospitals, idled industrial plants, exposed inboxes. Damages are no longer abstract — measurable, legally tangible, reputationally fatal.

Whoever keeps the saved penny before their eyes in this situation hasn’t grasped the calculation. The question isn’t whether security costs money. The question is whether the damage incurred without it is bearable. And the answer, in most cases, is no.

Software as a matter of honour

But it isn’t only security. It’s also the willingness to build software well.

“Well” is a word used inflationarily in this industry. Let me make it precise. Well means: it doesn’t simply collapse in an unexplained exception. It is tuned for edge cases, not only for the happy path. It behaves in a defined manner even when inputs are undefined. It produces no exploitable gaps. It does what it promises — and keeps doing it when conditions aren’t ideal.

Beyond that, well means: maintained. Documented. Comprehensible. Whoever reads it later understands what it does and why. Whoever modifies it can do so without breaking three other places.

That isn’t self-evident. It’s a decision. One taken anew every day, in every line, in every commit. And it is, I say deliberately, a matter of honour.

Running a software company and ignoring the self-evident duties because saving pressure is constant ignores more than duties. It ignores one’s own sense of honour. It excuses the mediocre with the economic. And eventually the mediocre stops being the exception and becomes the programme.

Making software is a matter of honour. When it’s shit, it’s shit. When it’s brilliant, it’s brilliant. That isn’t naïve. It’s the sharpest verdict there is, because it isn’t negotiable.

Visions of rubbish heaps

Call the bit about honour naïve. I, by choice, prefer to work with people who carry a vision of a product. People who want to build something that works. That lasts. That respects the user instead of exploiting them.

Some people, however, have visions of rubbish heaps. They dress them up, label them colourfully, display them prominently in advertising, garnish them with buzzwords nobody understands, and in truth simply cash in. Ideally without lifting a finger. Ideally without support, maintenance, guarantee. Ideally monthly, auto-renewing, uncancellable.

That’s an attitude foreign to me. I want to produce something. Were my service, offered now for over twenty years, shit, I would quit instantly. Not from moral compulsion — from a sense of honour. Whoever delivers bad work knowingly lies to himself. Whoever delivers bad work unknowingly ought to know.

Earning money is entirely legitimate. Whoever performs may charge. Yet what some companies extract from you today while delivering a crap service — that’s simply cheek. It’s the claim to render performance while merely billing. It’s entitlement to fees without the duty that justifies them.

A different biography

At this point it gets personal, and this once that’s permitted.

Counting the apprenticeship, last year, 2025, was my twenty-fifth professional anniversary. Twenty-five years in which I didn’t merely work with computers professionally but in which my life revolved around them. Since the mid-1990s.

That’s a biography that runs differently from many others’. In their leisure time the share of occupational topics tends asymptotically to zero. End of workday means end of workday. Occasionally there are ranting stories, told at the bar, filed under “Work that annoys”. Then it ends.

With me it’s different. Since the mid-1990s everything revolved around the computer, and that intensified steadily. At a level a normal wife wouldn’t endure forever. I say that without pride and without complaint. It’s a statement. Whoever takes this craft seriously doesn’t stop when the screen goes dark. He never stops.

That isn’t sacrifice. It’s preference. Living like that gives you a relationship with your craft beyond mere duty. You don’t build only because you’re paid. You build because whether it’s built well interests you. Because you notice when it isn’t. Because the mediocre bothers you even when it works.

Exactly that preference is the foundation of what I offer professionally. Not twenty-five years of experience as paper — twenty-five years of attitude.

What libcom.de means

libcom.de isn’t a company selling IT security as a product. libcom.de is a person who has operated IT for a quarter century such that it holds. Security isn’t an add-on bolted on afterwards. It’s a property that emerges when infrastructure is planned with understanding, maintained consistently and operated honestly.

Whoever comes to me doesn’t get a patent solution. They get an inventory: what runs, what does it protect, what doesn’t, where should it develop? Then they get a plan fitting their reality — their budget, their risk appetite, their obligations. And they get someone who doesn’t stop when the project is accepted. Who stays on as long as necessary.

That isn’t a service you list on a pricing page. It’s an attitude. And I believe precisely that attitude is missing from a market where security is often treated as a cost centre, software as fast-perishing goods, and service as justification for a subscription.

If you wonder whether your IT is still adequately protected, whether your software is well-built, or whether you seek someone who means it honestly: write to contact@libcom.de. We take an honest inventory. Without sales pressure. With a view to what lasts long-term.


Let’s stop being shit. Let’s work together on something that lasts — and thereby do ourselves all a favour.