TU meets usd, Person sitting on windowsill with laptop and a cup of coffee

TU meets usd: Students Gain Hands-On Insights into Information Security and Pentesting 

28. May 2025

During the winter semester 2024/25, students from Technische Universität Darmstadt had the opportunity to participate in two academic cooperations with usd AG. As part of this collaboration, various usd AG colleagues were responsible for the content design of the courses. Our colleague Maximilian Müller, Managing Consultant at Security Consulting, once again led the lecture “Information Security Management”. The second course “Hacker Contest” was professionally supervised by our colleagues Matthias Göhring, Head of usd HeroLab, together with Tim Wörner and Tobias Hamann, Managing Consultants at the usd HeroLab. 

On May 21, 2025, the time had come once again: As the concluding event of the semester, participants were invited to “TU meets usd”, where they had the opportunity to put their theoretical knowledge of information security into practice and gain valuable hands-on insights while still studying. 

Exploring the world of Information Security and Ethical Hacking 

The central focus of the information security lecture was the question of how information security can be systematically established in companies. Key topics included ISO 27001, the implementation of an Information Security Management System (ISMS), risk and asset management, incident management, and the secure operation of IT systems, including vulnerability and vendor management. 

Complementing the lecture, the Hacker Contest provided in-depth knowledge of penetration testing, vulnerability analysis, and the responsible disclosure of discovered security flaws. In the usd PentestLab, students applied this knowledge in realistic scenarios: They tested various attack techniques, analyzed real open-source software, and identified critical vulnerabilities — with results that went far beyond theoretical exercises. 

“In the lecture, we focus on the theoretical implementation of information security in corporate environments. TU meets usd offers the ideal practical counterpart – it shows students how we deal with these topics in our day-to-day work.”

Maximilian Müller, Managing Consultant, usd AG

Zitat Maximilian Müller Managing Consultant zu ISMS

IT Security disciplines up close 

To illustrate how these concepts are implemented in practice, usd AG’s departments presented real-world examples during the next part of the program. Bartosz Milejski, Senior Consultant in the team Security Audits & PCI, joined Maximilian Müller and Matthias Göhring in demonstrating how the content from the lectures is applied in day-to-day project work. Together with the students, they discussed real-world challenges from the IT security field. The topic of penetration testing sparked particularly strong interest: How does a pentest work? What are the challenges in working with clients? Which skills are essential? 

Behind the scenes at usd AG

Following the technical sessions, students from TU Darmstadt were given a behind-the-scenes tour of usd AG’s Neu-Isenburg location. They visited offices, training rooms, and the usd HeroLab. The tour also covered day-to-day questions such as: What does a typical workday look like? What development opportunities does usd AG offer? And what defines the team spirit? Many participants were especially impressed by the professional yet open working environment and the personal exchange about career paths within the company. 

Rounding off with networking and dialogue 

The day concluded with a shared pizza dinner alongside usd colleagues, creating a relaxed setting for open conversation and informal exchange. Again, pentesting and hacking remained hot topics and the welcoming atmosphere made it easy for participants to ask follow-up questions and reflect on what they had learned. 

Conclusion: A day with lasting impact 

Everyone agreed: TU meets usd was once again a great success. The concept of combining theory with tangible real-world experience proved its value yet again. The event offered orientation, inspiration – and perhaps the first spark for future careers in IT security. 

Also interesting:

Security Advisories on PRTG Network Monitor

Security Advisories on PRTG Network Monitor

The pentest professionals at usd HeroLab examined the PRTG Network Monitor web application as part of web application pentests and identified several vulnerabilities. Two vulnerabilities relate to cross-site scripting (XSS), which allows attackers to inject JavaScript...

PCI Secure Software Standard v2.0: What You Should Know

PCI Secure Software Standard v2.0: What You Should Know

On 15 January 2026, the PCI Security Standards Council (PCI SSC) released version 2.0 of the PCI Secure Software Standard. This is the first comprehensive revision since the introduction of the standard. Insight into the Key Changes The new version streamlines the...

Part-IS and ISO 27001: How to Leverage Synergies for Your Compliance

Part-IS and ISO 27001: How to Leverage Synergies for Your Compliance

On 22 February 2026, the EU Regulation Part-IS for aviation organizations will come into force. They must manage information security risks in a way that best protects civil aviation safety. Many already rely on an ISMS according to ISO 27001 – but is that enough for...

Categories

Categories