THREAT BRIEFING · 09.10.2026 DEENFRES

Strategy & Governance

Qualified Staff: Your Most Important Security Measure

By Tobias Massow · March 5, 2020 · 4 min read

Employee expertise determines a company’s security posture. As a study by the German digital association Bitkom reveals, qualified IT security specialists are essential for protecting against sabotage, data theft, or espionage. In fact, 99 percent of respondents rated qualified staff as an appropriate security measure – and 69 percent deemed them highly appropriate.

The survey included over 1,000 CEOs and security officers across all industries. It explored questions such as: Which companies are affected by espionage, sabotage, and data theft? Who are the suspected perpetrators? And is the economy already adequately protected today?

AI and Blockchain to Protect Your Business

Security awareness training for employees is also viewed as highly effective: 97 percent of companies consider it an appropriate security measure, and 76 percent rate it as highly appropriate. Bitkom Executive Board member Ralf Wintergerst shares this view: “The cybersecurity skills shortage is especially acute in IT security. That makes investing in continuing education and training all the more critical. Companies that skimp here become significantly more vulnerable.”

Alongside skilled personnel, technological solutions are also cited as key enablers. Nearly half of respondents (47 percent) consider artificial intelligence and machine learning highly suitable security measures – particularly for detecting anomalies. A total of 86 percent of companies regard the “security-by-design” approach for Internet of Things (IoT) devices as sensible – a principle requiring security considerations to be integrated from the earliest stages of device development. In this context, 80 percent of respondents see blockchain technologies as useful for protection against sabotage, data theft, or espionage.

Sabotage, data theft, and espionage alone cost the German economy over €100 billion annually. Economic protection in the digital world has thus become more urgent than ever.

 

Key Facts

Damage volume: Cybercrime causes global annual damages exceeding €8 trillion.

Skills gap: More than 3.5 million cybersecurity professionals are missing worldwide.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What are the most common cyber threats facing businesses?

According to the BSI (Federal Office for Information Security) Threat Landscape Report, ransomware, phishing, DDoS attacks, and supply-chain compromises are the most frequent threats. For German companies, regulatory risks – including the GDPR and the NIS2 Directive – add further complexity.

How much should a company invest in cybersecurity?

Industry experts recommend allocating 10 to 15 percent of the IT budget to cybersecurity. According to Bitkom, German companies average 14 percent. What matters most is not just the amount – but the strategic allocation across prevention, detection, and response.

Does every company need a CISO?

Not every company requires a full-time Chief Information Security Officer (CISO), but every organization needs clearly defined IT security accountability at the executive level. SMEs can engage an external CISO (Virtual CISO). With NIS2, management-level responsibility for cybersecurity is now legally mandated.

Related Articles

More from the MBF Media Network

Digital ChiefsIT Strategies for Digital TransformationcloudmagazinCloud as an Enabler of Digitalization

TL;DR

Further reading

A magazine by Evernine Media GmbH