
Enhancing Germany's resiclience against analogue, hybrid and digital attacks
German industry is closely intertwined with global value chains. Therefore, it presents a significant target f, which is increasingly exploited by competing economic actors, states, extremists, terrorists and criminals. The establishment of a protective shield that treats physical economic protection and cyber security as a single entity is long overdue.
With a comprehensive security shield, Germany can become significantly more resilient to analogue, hybrid and digital attacks – an absolute necessity given the heightened threat level. Since Russia’s attack on Ukraine in February 2022, which contravened international law, German companies have increasingly come under the spotlight of attackers: last year, 87 per cent of companies in Germany faced data theft, industrial espionage and sabotage. More than half of companies even expect a further increase in security incidents.
According to the federal police statistics, in 2025 alone, excluding offences committed abroad, more than 126,000 cases of cybercrime were reported – and that is likely to be just the tip of the iceberg, as the majority of those affected do not report cybercrime. The same applies to physical attacks. These range from graffiti and smashed windows to surveillance using drones and arson attacks. According to information from the Federal Office for the Protection of the Constitution (BfV), the companies targeted come from sectors as diverse as energy, defence, aerospace, logistics, software, semiconductors, finance, management consultancy and auditing. The consequences are equally varied, ranging from financial losses and production downtime to reputational damage.
A holistic approach to prevention, encompassing all aspects of physical security – including that of staff, production facilities, logistical infrastructure and supply chains – as well as cyber security, staff background checks, and training and awareness-raising, can significantly reduce risks.
Comprehensive measures to ensure the security of our businesses also promote long-term economic resilience and prevent social cohesion in this country from being jeopardised. After all, a stable economy is the foundation of our modern society, of the success of innovative ideas, and of Germany’s engagement in foreign, development and security policy. Short-term changes at the operational level within public authorities and businesses are not sufficient to achieve this. Only a long-term, holistic and strategic adjustment of the framework conditions will sustainably strengthen the protection and resilience of Germany as a business location in the face of security risks.
Policy recommendations
- Implementing integrated security, strategies to protect our economy: As a guarantor of prosperity, German industry is a central pillar of our national security. BDI therefore appreciates that the new National Security Strategy follows the principle of integrated security: The geopolitical and security challenges facing our globally interconnected economy require a coherent and strategically guided foreign, security and defence policy. To achieve this, the relevant ministries and federal authorities must be closely integrated with one another, and the silo mentality that still persists must be overcome.
- Consistently implementing the National Economic Security Strategy: The National Economic Security Strategy sends an important signal regarding economic security as a central pillar of national security. Implementation is now crucial: clear priorities, reliable lines of responsibility and targeted support for businesses – particularly start-ups and small and medium-sized enterprises – are necessary. This requires strategic, cross-departmental coordination – for example, through the recently established National Security Council.
- Achieve clear responsibilities for the protection of critical infrastructures: In order to enhance the security of critical infrastructure (KRITIS) in light of the geopolitical situation, it is urgently necessary to eliminate the existing confusion over responsibilities and to establish uniform regulations and responsibilities across the federal government. At the same time, existing institutions and processes should be modernised through a greenfield approach that integrates tried-and-tested elements into a more efficient overall system. A new strategic vision, taking current threat scenarios into account, must be developed and implemented to strengthen Germany’s resilience in the long term. This requires sufficient resources to enable a cooperative security structure involving the state, the private sector and society, whilst avoiding unnecessary bureaucracy or structural duplication of regulation. The aim must be to base Germany's security architecture on an ‘all-hazards approach’.
- Integrating analogue, hybrid and digital protection: In order to protect German economy as effectively as possible against attacks in the context of increasing hybrid threats, a holistic approach is required that addresses digital, hybrid and physical protection across ministries and authorities. A division of regulatory responsibilities and corporate reporting obligations into analogue and digital incidents does not reflect the current threat landscape. To this end, the umbrella legislation for critical infrastructures, and the NIS2 Implementation Act must be integrated as closely as possible at the regulatory level.
- Institutionalising the bidirectional exchange of information: BDI supports the ‘Single Entry Point for Incident Reporting’ proposed by the European Commission in the Digital Omnibus. A streamlined reporting system that makes it easier for companies across Europe to report analogue, digital or hybrid security incidents is an important first step. A daily updated security situation report must be compiled on the basis of these reports.
- Cybersecurity ‘made in Germany’: Tax incentives must be introduced for investment in cybersecurity products and solutions. As part of this, public administration should act as an anchor client for cybersecurity measures ‘made in Germany’. To this end, it is also absolutely essential to tackle the shortage of skilled workers, for example by creating new degree programmes and apprenticeship schemes, promoting women in IT security, and facilitating the recruitment of skilled workers from third countries.
- Supporting trustworthiness checks for employees: Government bodies must support businesses in minimising the risk posed by so-called ‘insiders’, for example by enabling applications to be made for trustworthiness checks for employees in cybersecurity roles. As part of the current roll-out of the European Union’s NIS 2 and CER Directives, this option should be implemented for all organisations, in conjunction with ongoing training and awareness-raising measures.
Related Links

Kerstin Petretto
