
Digital Counterattacks: Should the Government Be Allowed to Hack Back?
Cyber security is crucial to the success of digital business models, to trust in the digital transformation of numerous areas of life, and thus to the digital society as a whole. At the same time, there has been a steady rise in criminal activity in cyberspace, characterised by increasingly potent DDoS attacks, botnets and other attack vectors. Nowadays, cybercriminals by no means target only government institutions, operators of critical infrastructure or individuals. Rather, German industry faces tens of thousands of attacks every day, both directly (in factories, throughout the entire supply chain and via attacks on its employees) and indirectly (via attacks on the products it manufactures), from cybercriminals and government agencies from all over the world.
Nowadays, cybercriminals attack government institutions, businesses and individuals on a daily basis. To give one example: in mid-September 2026, a major German telecommunications network operator, together with its partner companies, recorded around 115 million attacks on its honeypots – deliberately set traps – within a 24-hour period. As telecommunications networks play an increasingly vital role in maintaining public life with the growing interconnectedness of society, it is clear that the protection of digital and other critical infrastructure, as well as that of other businesses and government bodies, must be a top priority. This requires decisive and concerted action by the state and the private sector.
Germany's response to defend itself: New legislative competencies
Given the sheer volume of malicious software already in existence today, the increasing commercialisation of cybercrime and the expected rise in the number of connected devices, the question arises as to what capabilities a resilient state will require in cyberspace – in both the civilian and military spheres – in future to ensure safety and security. Whilst cybercriminals operate globally, Germany’s domestic policy response remains fragmented. Sixteen regulatory laws enacted by the Länder, together with numerous federal laws, form the legal basis for action in cyberspace in accordance with the rule of law.
BDI appreciates that the Federal Government has agreed in its coalition agreement to strengthen Germany’s digital resilience. Efficient state cyber defence capabilities are a fundamental component of safeguarding cyber security and, consequently, public safety. Improved information-sharing on cyber risks, as well as expanded and effective response mechanisms, are essential to this end. It is crucial that new powers and obligations are proportionate and closely integrated with existing structures. It is a long-overdue step that the security authorities are being given additional powers to thwart cyber-attacks in order to avert or minimise serious consequential damage. The proposed act to enhancing cybersecurity creates the urgently needed powers for the security authorities. At the same time, a spiral of escalation between the state and cybercriminals operating both nationally and internationally must be avoided.
