New strategy: from passive defence to active cyber defence
The German government is planning a fundamental change of strategy in national cybersecurity. A draft law adopted by the cabinet is intended to grant the Federal Office for Information Security (BSI), the Federal Police and the Federal Criminal Police Office (BKA) expanded powers for "active cyber defence". These measures go significantly beyond previous preventive approaches and, for the first time, permit direct intervention in attacker structures.
Federal Interior Minister Alexander Dobrindt (CSU) describes the new approach as proactive: "We strike back, we neutralise the threat if we are attacked, we will be able to disrupt attackers and destroy their infrastructure." This announcement marks a paradigm shift from a purely defensive to an offensive cyber strategy.
Concrete powers and measures in detail
The draft law provides for various new tools to be made available to the security authorities:
- Prohibiting the operation of information technology systems that pose a danger
- Redirecting data traffic to analyse and interrupt attacks
- Reading, deleting or altering data in third-party systems
- Taking action against shifting malicious internet domains
The BSI is to be authorised, at the request of institutions, to search their IT systems for preparatory measures by attackers and to identify them. A particular focus lies on combating the distribution of malware via compromised domains.
Implementing the planned changes will require a total of 37 additional staff, which illustrates the expected workload for the new areas of responsibility.
Rationale: Germany in the crosshairs of international cyberattacks
The federal government justifies the legislative change with the increasing threat situation. As Europe's leading economic nation, Germany is said to be increasingly in the focus of cyberattacks, some of which could have a major impact. Hybrid threats in particular are gaining in significance.
Foreign powers, state actors or organisations associated with them are increasingly said to be the originators of cyberattacks against Germany. The attacks are directed against business, industry, state bodies and politics, with the following aims:
- Espionage
- Sabotage
- Extortion
- Demonstration of power in the digital sphere
According to the draft law, "preventive measures within one's own IT systems alone offer no sufficient protection" against large-scale cyberattacks with substantial damage potential. The authorities must therefore be given additional means of directly preventing such attacks.
Distinction between threat prevention and criminal prosecution
The additional powers for the Federal Police are intended exclusively for threat prevention, not for criminal prosecution. Special defensive measures are envisaged only in certain cases, for example where the danger is directed against "authorities or institutions whose functioning is of essential importance to the community or to national defence".
Critical voices from business
The digital industry association Bitkom welcomes the government's stronger commitment to cyber defence in principle but sees problematic aspects. Bitkom is particularly critical of the new intervention powers for the Federal Police and the BKA that enable counterattacks on attacker systems.
The main point of criticism: "Because cyberattacks frequently cannot be attributed with technical certainty and perpetrators lay false trails, uninvolved third parties are at risk of being hit." This assessment points to the technical complexity of attributing cyberattacks and to possible collateral damage.
The Federation of German Industries (BDI) also sees a need for improvement. Its criticism is directed at the state-centred approach: "So far the draft relies too heavily on state intervention and too little on cooperation with the business community." The obligations for companies to cooperate would have to be defined more precisely and proportionately.
Significance for the security industry
The planned legislative changes have far-reaching implications for the entire security industry. Companies must prepare for greater scope for official intervention and adapt their IT security concepts accordingly. This affects both the technical infrastructure and legal compliance requirements.
New business areas are emerging for providers of security technology, since increased state activity also makes corresponding protective measures necessary for companies. Demand for robust security solutions is likely to continue rising.
Outlook: a paradigm shift with open questions
The draft law marks a fundamental change in German cybersecurity strategy. For the first time, state bodies are to be able not only to act defensively but to intervene actively in third-party systems. This brings with it legal and technical challenges that have not yet been fully resolved.
The criticism from business associations shows that striking a balance between effective cyber defence and protecting uninvolved third parties represents a central challenge. Whether this active cyber defence proves itself in practice, and whether the legal framework is sufficiently precise, will only become apparent in application.
Companies should already be preparing for the changed legal situation and adapting their security concepts accordingly. Cooperation between state bodies and the private sector will be of decisive importance for the success of the new strategy.