Last year, 87% of companies in Germany experienced attacks, and Russia has now matched China's level.
According to the industry association Bitkom, around 87% of German businesses experienced data theft, espionage, or sabotage in the last year, an increase from 81% the previous year, with the total damage estimated at €289.2 billion. What distinguishes this year’s report is not the trend itself but the methodology; Bitkom has merged its company survey with evaluations from Germany’s domestic intelligence agency, especially significant in a context where public sector defenses have faced ongoing challenges.
This combination is crucial because companies often struggle with attribution. They might recognize that they have been breached but rarely know who is responsible. By merging survey results with state intelligence on active threat campaigns, a more comprehensive understanding emerges than either source could provide independently.
The attribution aspect is particularly noteworthy. Both Russia and China are implicated in 46% of the incidents attributed externally, with Russia's share rising from 39% the previous year, reaching parity with China. Russia's seven-point increase in one year is a notable change in such a large dataset. This aligns with a broader trend in Europe, reflecting a shift in Russian actions from espionage to disruption, as evidenced by Dutch authorities who recently seized 800 servers linked to Russian hacking efforts.
Out of the total estimated damages, approximately €202.4 billion is directly attributed to cyberattacks, while the remainder involves physical theft and sabotage. This figure has risen from €267 billion the previous year. It's important to interpret these numbers as estimates rather than precise accounts; they are derived from self-reported survey data regarding losses that businesses frequently find difficult to quantify, incorporating indirect costs such as reputational harm that do not appear in company financial statements.
The methodology is at least clear-cut. Bitkom Research conducted telephone surveys with companies that have a minimum of ten employees and €1 million in annual revenue, making it a suitable demographic and approach for such a challenging question to measure.
However, rising percentages also present a measurement issue worth highlighting; improved detection capabilities might lead to a greater number of reported incidents. Thus, the jump from 81% to 87% may indicate that companies are recognizing pre-existing issues rather than experiencing an increase in incidents.
Nearly 59% of organizations expressed feeling economically threatened by cyber incidents, representing a significant concern for businesses. This indicates that a majority of German firms perceive this as an existential threat, influencing their spending decisions.
Malware, ransomware, and phishing continue to be the primary attack vectors, with phishing often serving as the initial point of entry. The persistence of this trend is notable since these are not new tactics, and they remain effective.
Germany's industrial sector presents a particularly appealing target for a specific reason. The Mittelstand consists of thousands of mid-sized companies that possess world-class engineering intellectual property but maintain security budgets proportionate to their revenue rather than the worth of their knowledge.
In response to the increasing threat from foreign powers, Germany has been bolstering its measures by enhancing its intelligence service capabilities. Concurrently, NATO has established cyber partnerships with companies like Microsoft, Palo Alto, and ESET. This situation underlines a familiar tension, as European institutions fortify their defenses partly by increasing reliance on American vendors.
This dynamic is evident throughout the discourse, as Europe’s dependency on cloud technology represents both a political and technical risk. Separate research from Bitkom indicates that a significant majority of German companies feel their reliance on US cloud services is excessive.
The intelligence-sharing aspect outlined in the report may serve as a model for other European nations. While most national industry associations regularly survey their members about breaches, few integrate those findings with the insights security services have regarding the individuals conducting these campaigns.
However, the report does not clarify what specific actions any individual company should take moving forward. While attribution has improved, the reported damages have increased, and the attack methods remain consistent with those described in the sector over the past decade.
Other articles
Last year, 87% of companies in Germany experienced attacks, and Russia has now matched China's level.
Bitkom estimates the cost of damage to German companies at €289.2 billion, attributing 46% of the attacks to both Russia and China.
