
Insights · IT security
IT security: hackers are becoming increasingly aggressive
The number of cyberattacks and the scale of the damage are increasing across Germany — and NIS2 is being put on hold at precisely this moment
- Published
- 8 July 2025
- Author
- Dr. Markus Hülper
- Reading time
- 3 min read
The state of IT security in Germany is alarming. “The digital attack surface is steadily increasing, vulnerabilities all too often provide serious opportunities for intrusion, and attackers are finding ever faster and more skilful ways to exploit them,” says the recently published 2024 report on the state of IT security by the German Federal Office for Information Security (BSI). The threat situation is “continuing to develop rapidly”, while the number of attacks is rising “immensely”. According to the report, the consequences are “serious” and the damage “considerable”.
The BSI records 22 APT groups currently active in Germany. The abbreviation stands for “Advanced Persistent Threat”. It refers to highly trained, usually state-sponsored hackers who target a network or system over an extended period. Their objective: espionage — or sabotage. Their targets include companies as well as public authorities. The BSI holds the Russian group APT28 responsible for cyberattacks on companies in logistics, defence and aerospace, as well as on IT service providers. In other European countries, operators of critical infrastructure, such as energy suppliers, have been affected by APT attacks.
Improving cybersecurity with the help of NIS2
“The cybersecurity situation remains tense,” said Federal Minister of the Interior Nancy Faeser (SPD) when presenting the BSI report. “At the same time, however, we can see that resilience to attacks is increasing and that more is being invested in cybersecurity.” This applies above all to companies required to implement the NIS2 Directive. NIS2 (NIS stands for Network and Information Security) aims to ensure a high and consistent level of cybersecurity throughout the EU. The directive affects around 30,000 organisations across Germany, primarily companies. The NIS2 Directive applies to all companies with more than 50 employees or annual revenue of more than EUR 10 million. Even if they are smaller, companies may fall within the scope of the NIS2 rules if they are considered structurally important.
Germany will transpose the European Union’s NIS2 Directive into national law through the BSI Act, even though the original deadline in October 2024 could not be met. While the NIS Directive initially applied only to what is known as critical infrastructure, its scope is now being widened considerably. It is therefore time for companies to examine the technical, operational and organisational requirements that apply to them and consider liability risks under the new sanctions regime.
Here you can learn how NIS2 is being implemented in Germany and how companies can meet the cybersecurity requirements. One thing is already clear: failure to implement the NIS2 requirements may result in heavy fines.
Those unable to protect themselves become victims
According to the BSI report on the state of IT security in Germany, extortion involving stolen data is also developing into a mass business. In addition to large corporations, hackers are increasingly targeting small and medium-sized enterprises. Cybercriminals tend to seek out victims that are easy to attack. According to the BSI, outdated Android systems in particular are strikingly vulnerable. BSI President Claudia Plattner says: “It is essential that we, and that local authorities and companies, better protect ourselves.”
For now, this is on a voluntary basis. The NIS2 Implementation Act has not yet been finally adopted. Following the collapse of the governing coalition, it is highly doubtful whether it can pass the Bundestag in the near future.
Do you have questions about this topic?
We can assess what the development means for your organisation and advise you directly.


