THREAT BRIEFING · 13.08.2026 DEENFRES

Strategy & Governance

The Top 30 Cybersecurity Threat Scenarios

By Benedikt Langer · February 14, 2023 · 6 min read

The threat landscape for cybersecurity, now crucial success factors for organizations and companies, is growing day by day. Once the IT infrastructure is compromised, it’s about losing horrendous sums, trust, and reputation. A chart list shows the latest data and facts as well as interesting information on the topic of cybersecurity.

Cybercrime is today a massive industry with a revenue of 1.5 trillion US dollars – and a serious risk for global trade. The German economy alone suffers damages of 203 billion euros annually, according to the Digital Association Bitkom. The BSI (Federal Office for Information Security) assesses the cybersecurity situation in its current report on IT security as highly concerning and expects the situation to worsen.

“Knowing which threats exist, understanding trends, and recognizing the impact of cybercrime on businesses is crucial for building protective measures and improving security precautions,” says Dr. Sebastian Schmerl, Director Security Services EMEA at Arctic Wolf, a provider of security operations. However, companies often lack the necessary information to best prepare for cyberattacks.

A first step towards a more comprehensive understanding of the methods used by cybercriminals is knowledge of relevant data and facts about cybersecurity.

 

30 Relevant Cybersecurity Statistics – Globally and in Germany:

  1. The insider threat: 19 % of data breaches are caused by internal errors.
  2. Users in the crosshairs: 58 % of data breaches target personal data.
  3. Organized crime: Approximately four out of five data breaches are attributed to organized crime.
  4. Human factor: Misconduct remains a significant security risk and is responsible for 14 % of breaches.
  5. Beware of misconfigurations: Eight out of ten companies (81 %) consider vulnerabilities and misconfigurations the greatest threat to their infrastructure.
  6. Increase in vulnerabilities: In Germany, 10 % more vulnerabilities in software solutions were discovered in 2021 compared to the previous year, 13 % of which were severe.
  7. Popular attack vectors: Compromised login credentials were the most common attack vector, followed by phishing and vulnerabilities.
  8. Supply chain security: The supply chain was involved in 61 % of incidents this year.
  9. Lack of MFA: In 80 % of cases involving compromised business emails, the affected companies did not use multi-factor authentication.
  10. Major security incident: 53 % of German companies admit to having experienced at least one major security incident.
  11. Ransomware is booming: The number of ransomware attacks has increased by 435 % since 2020.
  12. Ransomware attacks in the millions: 700 million ransomware attacks occurred in 2021.
  13. Top ransomware exploits: Microsoft Exchange (ProxyShell) and VMWare Horizon (Log4J) remain the two most important external exploits used to spread ransomware.
  14. Access for money: Ransom demands more than doubled in 2022.
  15. Dangerous “phishers”: 64 % of companies cite phishing as their main problem.
  16. Knowledge protects: 48 % of companies see the need to gain more expertise in combating phishing.
  17. Security budgets 2022: Companies spent 170 billion USD on security products and services in 2022.
  18. Costs drive security investments: Costs are the most important factor that companies consider when implementing a security program.
  19. Cloud challenge: 28 % of companies name cloud security as their biggest infrastructure problem.
  20. Expanding cloud security: 22 % of companies plan to expand cloud security within a year.
  21. Expensive data breach: 4.35 million USD are the average total costs of a data breach worldwide.
  22. Cybersecurity budget: Despite increasing cyber threats, 23 % of German companies do not plan to increase their security budget in 2023.
  23. Skills shortage: 76 % of companies cannot achieve their security goals due to a lack of personnel.
  24. Security experts needed: It is estimated that there will be 3.5 million unfilled positions in the cybersecurity sector worldwide by 2025.
  25. Insufficient IT workforce: Germany is already missing 137,000 IT experts.
  26. Responsibility: 56 % of companies see the responsibility for protecting the infrastructure with IT staff.
  27. Blame for cyber incidents: If cyber incidents actually occur, 47 % of German companies also look for the culprits in the IT and cybersecurity teams.
  28. Help welcome: 53 % of companies either already work with a service provider or will hire one within a year.
  29. Managed Detection and Response: By 2025, 50 % of companies will use MDR services for monitoring, detecting, and responding to threats that offer functions for containing and mitigating threats.
  30. Mandatory security standards: By 2023, government regulations that require companies to ensure consumer protection rights will affect five billion citizens and more than 70 % of global GDP.

 

This article is based on a press release from Arctic Wolf.

Fact: Every third German company has reported at least one data breach since the GDPR came into force, according to Bitkom.

Fact: German companies invest an average of 14 % of their IT budget in cybersecurity, according to Bitkom.

TL;DR

 

Key Facts

Damage Volume: Cybercrime causes damages of over 8 trillion euros worldwide annually.

Skills Shortage: Over 3.5 million cybersecurity professionals are missing globally.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What is the difference between data protection and data security?

Data protection regulates the lawful handling of personal data (legal basis, purpose limitation, data subject rights). Data security encompasses the technical and organizational measures to protect all data from loss, manipulation, or unauthorized access.

Does every company need a data protection officer?

In Germany, a data protection officer is mandatory if at least 20 people are regularly involved in the automated processing of personal data, or if special categories of data (e.g., health data) are processed.

What rights do individuals have under the GDPR?

Right to information, right to rectification, erasure, restriction of processing, data portability, and right to object. Companies must respond to requests within one month.

Related Articles

More from the MBF Media Network

cloudmagazinCloud & infrastructure news on cloudmagazin.comDigital ChiefsIT strategies for decision-makers on digital-chiefs.de

Further reading

Strategy & Governance · July 17, 2026

NIS2 Patchwork: Four States Face EU Court

The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.

A magazine by Evernine Media GmbH