A new dimension of cyber defence: the BKA gains expanded powers
Germany's security architecture faces a significant shift: under the planned act to strengthen cybersecurity, the Federal Criminal Police Office (BKA) is to be authorised in future to take active measures against attacker infrastructures. Federal Interior Minister Alexander Dobrindt (CSU) described the plan as a "milestone for Germany's security architecture" and announced: "We strike back, we neutralise the threat. If we are attacked, we will be able to disrupt the attackers and destroy their infrastructure."
This new form of "active cyber defence" marks a paradigm shift in German cybersecurity strategy. Whereas defensive measures have so far been the primary focus, it is now to become possible to act preventively against potential threats.
From passive protection to active defence
Until now, German cyber defence has been confined mainly to reactive measures. "So far we have responded to attacks by attempting to redirect them into harmless areas of the network", Minister Dobrindt explained of the previous approach. These methods had been effective, he said, but represented the maximum of active defensive measures to date.
In future, it will also be possible to target attackers' software and servers located abroad. Politically, this expansion of powers is justified by the changed security situation and the heightened urgency in cyberspace.
Concrete deployment scenarios for the new powers
Under the new rules, the BKA is to be authorised to combat various types of attacker infrastructure:
- IoT devices misused for cyberattacks
- Servers acting as command and control centres
- Hijacked cloud instances
- Command & control servers used to coordinate DDoS attacks
The aim is to be able to intervene early in order to prevent attacks such as DDoS assaults from the outset, before they can cause damage.
Distinction from the controversial hackback concept
Minister Dobrindt stressed that the planned measures do not constitute a hackback. A hackback, he said, is an "untargeted retaliatory strike", whereas the focus here is on concrete threat prevention by the Federal Criminal Police Office, the Federal Police and the Federal Office for Information Security.
To illustrate the point, the minister drew an analogy: "If an unattended suitcase poses a danger, we take action against it and do not first establish who the suitcase belongs to." Exactly who is behind an attacking system is irrelevant for threat prevention, he argued. All that matters is that the server structure poses a concrete threat.
On the basis of this distinction, the federal government sees no need to amend the Basic Law. The planned measures are intended to operate within existing constitutional possibilities.
Critical voices from civil society
Despite the government's assurances, critics see the provision as a problematic authorisation to conduct hackbacks. Their main concern: professional cyberattacks regularly misuse third-party devices, meaning the measures could hit uninvolved third parties rather than the actual perpetrators.
The planned cybersecurity measures form part of a series of legislative projects intended to grant police forces and public prosecutors expanded powers. Following the plans for data retention, the implementing acts on digital evidence preservation and the powers for data analysis and biometric internet matching, this is already the third major package of its kind.
The planned pace of legislation is drawing particular criticism, as the projects are due to pass through the Bundestag at high speed.
Context and significance for the security industry
The new powers represent a considerable expansion of state cybersecurity measures. For companies and organisations this means, on the one hand, potentially stronger protection against cyberattacks; on the other, new legal and technical challenges are arising.
Active cyber defence is seen as a necessary complement to existing protective measures such as hardening IT systems or statutory obligations to improve IT security under the NIS2 rules.
Effects on the security technology industry
The expanded state powers could change the requirements placed on private security solutions. Companies may increasingly be able to rely on robust, state-coordinated defensive measures, while at the same time the documentation and transparency of their own security measures becomes more important.
Outlook: legal and technical challenges
Implementing the new powers will bring various challenges. Aspects of international law must be taken into account, as must the practical distinction between legitimate systems and those being misused.
New opportunities for cooperation with state bodies are emerging for the security industry, but at the same time the requirements for documenting and tracing security measures are increasing.
The coming months will show how the debate over the expanded powers develops and what concrete effects the new rules will have on Germany's cybersecurity landscape.