Jens Lucius - Cybersecurity Professional

Welcome

I'm Jens Lucius, a cybersecurity professional from Germany with more than 20 years in IT and information security, and a TÜV-certified Information Security Officer. I currently work as Senior Security Expert at IQSIGHT — formerly Bosch Building Technologies — where I lead product security certifications and manage the company's PSIRT and CVE Numbering Authority (CNA).

Focus Areas

  • Product security certification: IEC 62443-4-1 / -4-2, UL 2900-2-3, India STQC
  • PSIRT & CNA management – coordinated vulnerability handling and CVE assignment
  • Information security management: ISO 27001 / TISAX – built and ran a group-wide ISMS across 11 locations
  • Product security risk management: Threat Modeling and risk process

Career at a Glance

I started out as a network administrator in 2001 and moved through QA, IT trainings and project management into information security. After building an ISO 27001 / TISAX compliant ISMS as Information Security Officer for the Buehler Motor Group, I joined Bosch Building Technologies as Senior Security Expert in 2021 and continue that role at IQSIGHT since the unit became an independent company. The full history is on the experience page.

Contact

You can reach me at web@jenslucius.de.

Experience

Senior Security Expert
IQSIGHT
June 2025 – Today

Formerly Bosch Building Technologies, now an independent company
Successful Certification of IQSIGHT Products according to IEC 62443-4-1, IEC 62443-4-2, UL2900-2-3, India STQC
Managing PSIRT and CNA for IQSIGHT
Conduct Product Risk Assessments


Senior Security Expert
Bosch Building Technologies
January 2021 – June 2025

Certification of Bosch BT Products according to IEC 62443-4-1, IEC 62443-4-2, UL2900-2-3
Applying the Bosch Secure Engineering process to products
Conduct Product Risk Assessments


Information Security Officer
Buehler Motor GmbH
April 2018 – December 2020

Responsible for Information Security and the introduction of an ISO 27001 / TISAX compliant ISMS for the Buehler Motor Group
- 11 locations worldwide
- 1,700+ employees


IT Security Expert
Buehler Motor GmbH
December 2015 – March 2018

IT Security Expert for the Buehler Motor Group
- 11 locations worldwide
- 1,700+ employees
Security Incident Management
Planning and management of IT security projects


Owner
Custotec
May 2014 – December 2016

Project Management for a secure VoIP Product
Development of a secure network protocol
Concept design for a secure operating system
Consulting on embedded products, bootloader, kernel security
Consulting on trusted computing technologies / TPM


Secure Solution Specialist / Project Manager
NCP engineering GmbH
March 2012 – April 2014

Project Manager for development of a secure embedded product.
Project Manager at NCP for ESUKOM project
Project Manager at NCP for SIMU project
Primary contact for Trusted Computing Group (TCG).
Test Management and technical coordination between QA, R&D and product management.
IT Trainings for NCP VPN products for customers and network partners


QA Manager / Trainings / Project Manager
NCP engineering GmbH
February 2010 – February 2012

Technical Manager for QA department
Project Manager at NCP for ESUKOM project
Test Management and Coordination of tests between QA and R&D department.
IT Trainings for NCP VPN products for customers and network partners


QA Engineer / Trainings
NCP engineering GmbH
October 2007 – January 2010

Installation of complex test environments, planning of tests
IT Trainings for NCP VPN products for customers and network partners


Network Administrator
NCP engineering GmbH
September 2001 – October 2007

Network Administration for server and client systems (Active Directory, IMAP, DNS, DHCP, Router, Firewalls, Fileserver, Webserver etc.) with special background in IT Security

Esukom

The ESUKOM project was a research project funded by the German Federal Ministry of Education and Research which lasted 2 years (2010 - 2012).

Partners

The project consortium consisted of 3 enterprises and 2 research organizations:

  • NCP engineering GmbH
  • Decoit GmbH
  • macmon GmbH
  • Fraunhofer SIT
  • University of Applied Sciences Hanover

Goals

ESUKOM aims to develop a real-time security solution for enterprise networks that works based upon the correlation of metadata. A key challenge for ESUKOM is the steadily increasing adoption of mobile consumer electronic devices (smartphones) for business purposes which generates new threats for enterprise networks. The ESUKOM approach focuses on the integration of available and widely deployed security measures (both commercial and open source) based upon the Trusted Computing Group’s IF-MAP specification. The idea is to operate on a common data pool that represents the current status of an enterprise network. Currently deployed security measures will be integrated and will be able to share information as needed across this common data pool. This will enable the ESUKOM solution to provide real-time security measures.

Results

During the project a thorough security analysis of smartphones and central network infrastructure was done.

Several prototypes were created during the implementation. One demonstration of the ESUKOM project was given by Jens Lucius at the NSA Trusted Computing Conference 2011.

Web

https://www.esukom.de/english/homepage.7.html
https://trustedcomputinggroup.org/

GovNet Box

The secure transmission of data is not a simple task for government agencies - especially after the disclosures of Edward Snowden. Main goal of this project was to develop a simple but secure solution to transmit this kind of data. In this case a certification of the German BSI (Federal Office for Information Security) for data up to restricted level was necessary.

The main tasks of this project were:

  • development of an embedded hardware
  • changing and integrating the available VPN software
  • create a security concept according to Common Criteria EAL4+
  • e.g. a concept for secure configuration of the device
  • complete test for vulnerabilities
  • test and certification through the German BSI


Highly secure solutions are mostly created concentrating on the security aspect of the solution neglecting usability completely or thinking about it after the project is mostly done. This leads to many secure, but unusable products. Therefore usability was a key requirement in this project from the start and has been carefully viewed during the development process.

The solution is essentially a hardware VPN client that can be attached to any laptop via USB. The complete communication is handled by the device (integrated LAN, Wi-Fi and 3G). When attached to a laptop the device is shown as a standard network adapter and all data that is transmitted through this adapter is transparently encrypted and transmitted. There are no limitations that a routing or NAT device would generate (e.g. problems with VoIP).

The device offers a simple and fast configuration for the administrator. The solution is multi-user capable and so different workers can share one device. A professional GUI offers the user feedback about the status of the connection and potential error messages. The user is securely authenticated by a smartcard that can be inserted into the device.

Links:
https://www.sit.fraunhofer.de/en/news/latest/press-releases/details/news-article/show/abhoersicherheit-in-a-box/

Trusted Computing Group

The Trusted Computing Group (TCG) is an industry standards body consisting of more than 120 companies, (research) organizations and universities that creates open standards in the area of "trusted computing". In different workgroups that meet several times a year these standards are developed and refined. The most widely known development of the TCG is the TPM (Trusted Platform Module) chip.

TCG not only standardises the TPM but also several open network protocols for security like TNC (Trusted Network Connect) or IF-MAP (InterFace for Metadata Access Point).

Most standards are developed to secure devices and central network infrastructure. The TNC protocol enables central components to ask clients for their health status (virusscan, patchlevel) and make decisions according to the result. A hostile or unpatched system can be denied access to the network. When integrating the TPM in this scenario the problem of the "lying endpoint" can be solved (that is when an endpoint is compromised and lying about its actual health level - no virus found for example). In addition to that the IF-MAP protocol enables central components to share important information and inform each other of security violations.

Links:
https://trustedcomputinggroup.org/
trustedcomputing.eu (archived)

Speaker / Media

Speaker Slots

DateTitle
25.05.2013CAST Workshop Germany 2013 - Speaker Slot: "Security requirements for mobile embedded systems in government usage"
27.02.2013Embedded World Germany 2013 - Speaker Slot: "Establishing Trust in Embedded Systems Using the TPM and Integrated Real-Time Network Security"
10.09.2012ISC2 Security Congress USA 2012 - Speaker Slot: "Establishing Trust in Embedded Systems"

Web

DateTitle
01.03.2014TCG IF-MAP Standard 2.2 (Listed in Acknowledgements)
06.12.2012The case for integrating security silos

Data Privacy Policy

German version below / Deutsche Version unten

The protection and security of personal information is a high priority for me. The collection and processing of your personal data takes place in compliance with the applicable data protection regulations, in particular the EU General Data Protection Regulation (GDPR). This statement describes how and for what purpose your data is collected and used and what options you have in relation to personal information.

By using this site, you consent to the collection, use and transfer of your information in accordance with this Privacy Policy.

1 Responsible Body

Responsible body for the collection, processing and use of your personal data within the meaning of the GDPR is:

Jens Lucius
Boehmerwaldstr. 2
91174 Spalt
Germany
web@jenslucius.de

If you wish to object to the collection, processing or use of your data by me in accordance with this Privacy Policy as a whole or for individual measures, you can address your objection to the above-mentioned responsible body. You can save and print this privacy policy at any time.

2 Access data
When visiting this page, the web server automatically logs log files that can not be assigned to a specific person. This data includes for example browser type and version, operating system used, referrer URL (previously visited page), IP address of the requesting computer, server request date and time of access, and client file request (file name and URL). These data are collected only for the purpose of statistical evaluation. A transfer to third parties, for commercial or non-commercial purposes, does not take place.

3 Use of Personal Information
Personal data will only be collected or processed if you voluntarily provide such information, e.g. in the context of a request. Unless there are any necessary reasons in coherence to a business query, you may at any time revoke the previously granted approval of your personal data storage with immediate effect in written form (e.g. by email). Your data will not be disclosed to third parties, unless disclosure is required by law.

4 Your rights as a concerned party
Under applicable law, you have various rights regarding your personal information. If you would like to assert these rights, please send your request by e-mail or by mail with a clear identification of your person to the address specified in section 1. Below is an overview of your rights.

4.1 Right to confirmation and information
You have the right at any time to obtain confirmation from us as to whether personal data relating to you is being processed. If this is the case, you have the right to obtain free information from us about the personal data you have stored together with a copy of this data.

4.2 Right to rectification
You have the right to demand immediate correction of incorrect personal data concerning you. Taking into account the purposes of this, you have the right to request the completion of incomplete personal data, including by means of a supplementary statement.

4.3 Right to cancel ("right to be forgotten")
You have the right to ask us to delete your personal data without delay.

4.4 Data transferability right
You have the right to receive the personal information that you have provided us in a structured, common and machine-readable format, and you have the right to transfer that information to another person without hindrance, provided that

1. the processing is based on a consent pursuant to Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR or a contract pursuant to Article 6 (1) (b) GDPR; and
2. the processing is done using automated procedures.

4.5 Right to object
You have the right, for reasons of your own particular situation, to object at any time to the processing of personal data relating to you pursuant to Article 6 (1) (e) or (f) of the GDPR; this also applies to profiling based on these provisions. I no longer process personal information unless we can demonstrate compelling legitimate grounds for processing that outweigh your interests, rights and freedoms, or processing for the purposes of asserting, exercising or defending legal claims.

4.6 Automated decisions including profiling
You have the right not to be subjected to a decision based solely on automated processing - including profiling - that will have legal effect or similarly affect you in a similar manner.

4.7 Right to revoke a data protection consent
You have the right to revoke your consent to the processing of personal data at any time.

4.8 Right to complain to a supervisory authority
You have the right to complain to a supervisory authority, in particular in the Member State of your residence, employment or the place of the alleged breach, that you consider that the processing of your personal data is unlawful.

5 Data Security
I make every effort to ensure the security of your data within the possibilities of applicable data protection laws and technical possibilities.
To safeguard your data, I maintain technical and organizational security measures that I always adapt to the state of the art.
I also do not guarantee that my offer will be available at specific times; Disturbances, interruptions or failures can not be excluded.

6 Automated Decision Making
There is no automated decision-making based on personal data collected.

7 Disclosure of data to third parties, no data transfer to non-EU countries

If and as far as I engage third parties in the context of the fulfillment of contracts (such as webhosting providers), they will receive personal data only to the extent that is required for the corresponding service.
In the event that we outsource certain parts of the data processing ("order processing"), I contractually obligate the processor to use personal data only in accordance with the requirements of data protection laws and to ensure the protection of the data subject's rights. Data is not transmitted to agencies or persons outside the EU.

8 Changes to this Privacy Policy
I will update these policies to protect your personal information from time to time. By using the website, you agree to the terms of these privacy policies.

Datenschutzerklärung

Der Schutz und die Sicherheit von persönlichen Daten hat für mich eine hohe Priorität. Die Erhebung und Verarbeitung Ihrer personenbezogenen Daten geschieht unter Beachtung der geltenden datenschutzrechtlichen Vorschriften, insbesondere der EU-Datenschutzgrundverordnung (DSGVO). Diese Erklärung beschreibt, wie und zu welchem Zweck Ihre Daten erfasst und genutzt werden und welche Wahlmöglichkeiten Sie im Zusammenhang mit persönlichen Daten haben.

Durch Ihre Verwendung dieser Website stimmen Sie der Erfassung, Nutzung und Übertragung Ihrer Daten gemäß dieser Datenschutzerklärung zu.

1. Verantwortliche Stelle

Verantwortliche Stelle für die Erhebung, Verarbeitung und Nutzung Ihrer personenbezogenen Daten im Sinne der DSGVO ist:

Jens Lucius
Böhmerwaldstr. 2
91174 Spalt
web@jenslucius.de

Sofern Sie der Erhebung, Verarbeitung oder Nutzung Ihrer Daten durch uns nach Maßgabe dieser Datenschutzbestimmungen insgesamt oder für einzelne Maßnahmen widersprechen wollen, können Sie Ihren Widerspruch an oben genannte verantwortliche Stelle richten. Sie können diese Datenschutzerklärung jederzeit speichern und ausdrucken.

2. Zugriffsdaten
Beim Besuch dieser Seite verzeichnet der Web-Server automatisch Log-Files, die keiner bestimmten Person zugeordnet werden können. Diese Daten beinhalten z. B. den Browsertyp und -version, verwendetes Betriebssystem, Referrer URL (die zuvor besuchte Seite), IP-Adresse des anfragenden Rechners, Zugriffsdatum und -uhrzeit der Serveranfrage und die Dateianfrage des Client (Dateiname und URL). Diese Daten werden nur zum Zweck der statistischen Auswertung gesammelt. Eine Weitergabe an Dritte, zu kommerziellen oder nichtkommerziellen Zwecken, findet nicht statt.

3. Nutzung persönlicher Daten
Persönliche Daten werden nur erhoben oder verarbeitet, wenn Sie diese Angaben freiwillig, z.B. im Rahmen einer Anfrage mitteilen. Sofern keine erforderlichen Gründe im Zusammenhang mit einer Geschäftsabwicklung bestehen, können Sie jederzeit die zuvor erteilte Genehmigung Ihrer persönlichen Datenspeicherung mit sofortiger Wirkung schriftlich (z.B. per E-Mail) widerrufen. Ihre Daten werden nicht an Dritte weitergeben, es sei denn, eine Weitergabe ist aufgrund gesetzlicher Vorschriften erforderlich.

4. Ihre Rechte als von der Datenverarbeitung Betroffener
Nach den anwendbaren Gesetzen haben Sie verschiedene Rechte bezüglich ihrer personenbezogenen Daten. Möchten Sie diese Rechte geltend machen, so richten Sie Ihre Anfrage bitte per E-Mail oder per Post unter eindeutiger Identifizierung Ihrer Person an die in Ziffer 1 genannte Adresse. Nachfolgend finden Sie eine Übersicht über Ihre Rechte.

4.1 Recht auf Bestätigung und Auskunft
Sie haben jederzeit das Recht, von uns eine Bestätigung darüber zu erhalten, ob Sie betreffende personenbezogene Daten verarbeitet werden. Ist dies der Fall, so haben Sie das Recht, von uns eine unentgeltliche Auskunft über die zu Ihnen gespeicherten personenbezogenen Daten nebst einer Kopie dieser Daten zu erlangen.

4.2 Recht auf Berichtigung
Sie haben das Recht, von uns unverzüglich die Berichtigung Sie betreffender unrichtiger personenbezogener Daten zu verlangen. Unter Berücksichtigung der Zwecke der haben Sie das Recht, die Vervollständigung unvollständiger personenbezogener Daten – auch mittels einer ergänzenden Erklärung – zu verlangen.

4.3 Recht auf Löschung („Recht auf Vergessenwerden“)
Sie haben das Recht, von uns zu verlangen, dass Sie betreffende personenbezogene Daten unverzüglich gelöscht werden.

4.4 Recht auf Datenübertragbarkeit
Sie haben das Recht, die Sie betreffenden personenbezogenen Daten, die uns bereitgestellt haben, in einem strukturierten, gängigen und maschinenlesbaren Format zu erhalten, und Sie haben das Recht, diese Daten einem anderen Verantwortlichen ohne Behinderung durch uns zu übermitteln, sofern

1. die Verarbeitung auf einer Einwilligung gemäß Artikel 6 Absatz 1 Buchstabe a DSGVO oder Artikel 9 Absatz 2 Buchstabe a DSGVO oder auf einem Vertrag gemäß Artikel 6 Absatz 1 Buchstabe b DSGVO beruht und
2. die Verarbeitung mithilfe automatisierter Verfahren erfolgt.

4.5 Widerspruchsrecht
Sie haben das Recht, aus Gründen, die sich aus Ihrer besonderen Situation ergeben, jederzeit gegen die Verarbeitung sie betreffender personenbezogener Daten, die aufgrund von Artikel 6 Absatz 1 Buchstaben e oder f DSGVO erfolgt, Widerspruch einzulegen; dies gilt auch für ein auf diese Bestimmungen gestütztes Profiling. Ich verarbeiten die personenbezogenen Daten nicht mehr, es sei denn, wir kann zwingende schutzwürdige Gründe für die Verarbeitung nachweisen, die Ihre Interessen, Rechte und Freiheiten überwiegen, oder die Verarbeitung dient der Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen.

4.6 Automatisierte Entscheidungen einschließlich Profiling
Sie haben das Recht, nicht einer ausschließlich auf einer automatisierten Verarbeitung – einschließlich Profiling – beruhenden Entscheidung unterworfen zu werden, die Ihnen gegenüber rechtliche Wirkung entfaltet oder Sie in ähnlicher Weise erheblich beeinträchtigt.

4.7 Recht auf Widerruf einer datenschutzrechtlichen Einwilligung
Sie haben das Recht, eine Einwilligung zur Verarbeitung personenbezogener Daten jederzeit zu widerrufen.

4.8 Recht auf Beschwerde bei einer Aufsichtsbehörde
Sie haben das Recht auf Beschwerde bei einer Aufsichtsbehörde, insbesondere in dem Mitgliedstaat ihres Aufenthaltsorts, ihres Arbeitsplatzes oder des Orts des mutmaßlichen Verstoßes, Sie der Ansicht sind, dass die Verarbeitung der Sie betreffenden personenbezogenen Daten rechtswidrig ist.

5 Datensicherheit
Ich bin um die Sicherheit Ihrer Daten im Rahmen der geltenden Datenschutzgesetze und technischen Möglichkeiten maximal bemüht.
Zur Sicherung Ihrer Daten unterhalten ich technische- und organisatorische Sicherungsmaßnahmen, die ich immer wieder dem Stand der Technik anpasse.
Ich gewährleisten außerdem nicht, dass mein Angebot zu bestimmten Zeiten zur Verfügung steht; Störungen, Unterbrechungen oder Ausfälle können nicht ausgeschlossen werden.

6 Automatisierte Entscheidungsfindung
Eine automatisierte Entscheidungsfindung auf der Grundlage der erhobenen personenbezogenen Daten findet nicht statt.

7 Weitergabe von Daten an Dritte, Keine Datenübertragung ins Nicht-EU-Ausland

Wenn und soweit ich Dritte im Rahmen der Erfüllung von Verträgen einschalte (etwa Webhosting Anbieter) erhalten diese personenbezogene Daten nur in dem Umfang, in welchem die Übermittlung für die entsprechende Leistung erforderlich ist.
Für den Fall, dass ich bestimmte Teile der Datenverarbeitung auslager („Auftragsverarbeitung“), verpflichte ich Auftragsverarbeiter vertraglich dazu, personenbezogene Daten nur im Einklang mit den Anforderungen der Datenschutzgesetze zu verwenden und den Schutz der Rechte der betroffenen Person zu gewährleisten. Eine Datenübertragung an Stellen oder Personen außerhalb der EU findet nicht statt und ist nicht geplant.

8. Änderungen dieser Datenschutzbestimmungen
Ich werde diese Richtlinien zum Schutz Ihrer persönlichen Daten von Zeit zu Zeit aktualisieren. Mit der Nutzung der Webseite erklären Sie sich mit den Bedingungen dieser Richtlinien zum Schutz persönlicher Daten einverstanden.