Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 8/10

Cyber Risks 2026: Homemade Vulnerabilities Threaten Businesses

YouGov study shows: Social engineering, missing backups and weak IT infrastructure are becoming the biggest threat to German companies.

What happened?

A recent YouGov study titled "Digitalization Needs of Companies 2026," conducted on behalf of 1&1 Versatel, shows that many cyber risks in German companies are homemade. A total of 533 decision-makers in German companies were surveyed between January 5 and 13, 2026. The results focus on two central vulnerabilities: growing threats from social engineering and a lack of resilience in companies' own IT infrastructure, for example due to missing backups and redundancies.

The Details

The share of companies classifying social engineering — the targeted manipulation of employees to obtain sensitive information or bypass security measures — as a relevant risk has risen by a third since 2024, from 15 to 20 percent. At the same time, 18 percent of respondents cite a lack of redundancy and backups as a concrete weakness in their IT infrastructure.

Technical threats continue to dominate companies' risk awareness: 47 percent cite DDoS attacks and 31 percent cite malware as relevant threats. At the same time, the "human factor" is increasingly coming into focus. Phishing, manipulated phone calls, or fake identities can bypass even modern protective systems. 35 percent of the companies surveyed consider human or organizational failure to be a significant security risk.

The picture regarding investments in security measures is mixed: 40 percent of companies have already invested, while another 31 percent are planning corresponding expenditures. Nevertheless, almost a third of companies still have no concrete security strategy.

Frank Rosenberger, CEO of 1&1 Versatel, puts the results into perspective: "Cybersecurity doesn't end with employees or firewalls. Without redundant connections, stable networks, and well-thought-out backup strategies, companies remain vulnerable. Security begins with infrastructure."

Assessment

The study results highlight an important trend: while classic technical threats such as DDoS attacks and malware continue to dominate corporate awareness, organizational and human factors are gaining increasing importance. Social engineering specifically targets the human vulnerability and can undermine even technically well-secured systems when employees are manipulated.

It is also notable that despite the growing threat landscape, almost a third of companies have so far pursued no concrete security strategy. This reveals a clear gap between perceived risk and actual action. In particular, the combination of missing backups, insufficient redundancy, and inadequate staff awareness creates an entry point that attackers can specifically exploit.

This development is also relevant for companies in the security technology sector: physical security measures such as access control systems or video surveillance are increasingly networked and thus themselves potential attack surfaces for cyberattacks. A holistic security strategy must therefore combine IT security and physical protective measures.

Practical Tips

  • Develop a security strategy: Companies without a concrete security concept should treat this as a priority, as the study indicates significant room for improvement here.
  • Establish backup and redundancy concepts: Missing backups were cited as a weakness by 18 percent of respondents — regular, redundant data backups are a fundamental building block of resilience.
  • Raise employee awareness: Since social engineering has significantly increased as a risk, training on recognizing phishing, manipulated calls, and fake identities should be a fixed part of the security culture.
  • View infrastructure as a security factor: According to the assessment cited by 1&1 Versatel, resilient network connections and stable IT landscapes are a necessary foundation on which further security measures can be built.
  • Continue investments consistently: The 31 percent of companies planning investments should implement them quickly to close the gap with the 40 percent that have already invested.

Outlook

The study makes clear that risk awareness in German companies is changing: moving away from a purely technical view of cyber threats toward a more holistic understanding that more strongly incorporates organizational weaknesses and the human factor. The significant increase in the perception of social engineering as a risk is likely to continue given the growing professionalization of corresponding attack methods.

Providers such as 1&1 Versatel are increasingly positioning themselves as partners for fail-safe and protected network infrastructures — from connectivity to managed security services. For companies, this means that the topics of resilience, backup strategies, and employee awareness are likely to move even more into focus in the coming years in order to close the existing gap between risk awareness and actual protection.