THREAT BRIEFING · 09.09.2026 DEENFRES

Strategy & Governance

Incident Response Made in Germany: BSI & Company Collaboration

By Tobias Massow · January 22, 2026 · 13 min read

119 new vulnerabilities per day. 461 data leaks related to Germany in twelve months. 80 percent of ransomware attacks target small and medium-sized enterprises. The figures from the BSI’s 2025 situation report are alarming. But they only tell half the story. The other half: Germany has built an incident response ecosystem that is unmatched in Europe. CERT-Bund, the German Cyber Security Organization, and the Telekom SOC with 250 experts form a three-tier defense system that catches businesses in emergencies. NIS2 mandates professional incident response. And that’s becoming a competitive advantage.

Key Takeaways

The Three-Stage IR Ecosystem

What distinguishes Germany from other European countries is not a single authority or a single company, but the interplay of three levels: governmental (BSI/CERT-Bund), semi-governmental (DCSO), and private-sector (Telekom-SOC and other MSSPs). This three-tiered system has organically evolved and proven its effectiveness in handling major incidents over the past few years.

Level 1: CERT-Bund (Governmental). The Computer Emergency Response Team of the BSI serves as the central point of contact for security incidents at the federal level. CERT-Bund operates a 24/7 service in collaboration with the IT Situation Center and the IT Crisis Response Center. The Warning and Information Service (WID) provides real-time technical security advice. As a member of FIRST, CERT-Bund is globally networked and exchanges threat information with CERTs worldwide.

Level 2: DCSO (Semi-Governmental/Private-Sector). The German Cyber Security Organization is a unique entity: established in 2015 as a public-private partnership, equally supported by Allianz, BASF, Bayer, and Volkswagen. With 115 employees across locations in Europe and North America, DCSO delivers Threat Intelligence Services and SOC services. The Advisory Board develops strategies to combat cybercrime, digital industrial espionage, and sabotage. DCSO acts as a bridge between large corporations and authorities.

Level 3: Telekom CERT and Private-Sector SOCs. The Telekom Master-SOC in Bonn, with over 250 cybersecurity experts, is one of the largest in Europe. It analyzes approximately one billion security-relevant data points daily from about 3,000 data sources using AI. The CERT has been certified according to the SIM3 standard since 2020. Additionally, there are private-sector SOCs from G DATA, Atos, Sophos, and dozens of specialized MSSPs serving small and medium-sized enterprises.

726
Critical Incidents Reported to BSI in 2024
24h
Reporting Deadline Under NIS2
22 APTs
Active Groups in Germany

Sources: BSI Situation Report 2024, NIS2UmsuCG

250+
Cybersecurity Experts in the Telekom Master-SOC Bonn
Source: Deutsche Telekom Corporate Responsibility Report, 2024

What the BSI Situation Report 2025 Really Reveals

The BSI Situation Report 2025 (reporting period July 2024 to June 2025) marks a significant shift by delivering quantitative metrics for the first time, moving away from purely narrative descriptions. The report highlights an average of 119 new vulnerabilities per day, a 24% increase compared to the previous year. Additionally, it identifies 461 data leaks with a German connection and reveals that 47% of all .de IP addresses accessible via the internet expose sensitive information publicly.

BSI President Claudia Plattner emphasizes the critical nature of the situation: “Any institution or individual accessible via the internet is fundamentally at risk. Attackers are targeting the most vulnerable points with precision. Only those who actively protect themselves can avoid damage.”

However, there are also positive developments: The number of financially motivated attacks has decreased by 9%, primarily due to the successful investigations by the BKA and BSI against organized cybercrime. Furthermore, the reduction in ransomware attacks on major hospitals is notable, with incidents dropping from 35 attacks on large clinics in 2021/2022 to 21 in 2023 and just 3 in 2024. The KRITIS investment program in the healthcare sector is proving effective.

The threat landscape is evolving: Russian actors are increasingly targeting German companies, municipalities, and private individuals. State-sponsored attackers are focusing on energy suppliers, cloud providers, and the automotive industry. The trend is shifting from opportunistic ransomware attacks to more targeted industrial espionage and sabotage. For incident response, this means that incidents are becoming more complex and require different skills than simply restoring encrypted backups.

Two Incidents That Put the System to the Test

Südwestfalen-IT (October 2023): The ransomware attack by the Akira group on the municipal IT service provider was one of the most severe cyber incidents in German administrative history. Over 70 municipalities in North Rhine-Westphalia were affected, leaving 1.6 million citizens unable to conduct digital administrative affairs for months. The cause was a weak password, the lack of multi-factor authentication, and an unpatched VPN appliance. No ransom was paid. Two managing directors were dismissed for breaching basic security duties.

For the IR ecosystem, this incident served as a stress test: The CERT-Bund coordinated communication between the affected municipalities and the BSI. Private incident response teams supported forensic analysis. The lesson learned is that municipal IT service providers represent a systemic risk and must be strictly regulated under NIS2.

Continental AG (August 2022): The LockBit group stole approximately 40 terabytes of data, including potentially sensitive information from VW, BMW, and Mercedes. The attack remained undetected for four weeks. Continental refused to pay a ransom initially set at $50 million, later reduced to $40 million. The FBI conducted investigations. Here too, the three-tier system demonstrated its strength: Government investigations (BKA/FBI), private-sector forensics, and cross-industry information sharing (DCSO) complemented each other.

The most recent warning came in February 2026: A major DDoS attack on bahn.de and the DB Navigator slowed the Deutsche Bahn website’s performance for several hours. This incident highlighted that critical infrastructure in passenger transport remains vulnerable.

119 / Day
New vulnerabilities daily (+24% vs. previous year)
Source: BSI Situation Report 2025

NIS2: How the Incident Response Reporting Obligation is Professionalizing

As of December 6, 2025, the NIS2 Implementation Act will be in effect in Germany. For incident response, Article 23 of the NIS2 Directive is crucial, implemented as a three-tier reporting system: 24 hours for the Early Warning (suspicion of illegal or malicious intent? Cross-border impact?), 72 hours for the incident notification with initial severity assessment and indicators of compromise, and one month for the final report.

For businesses, this means incident response is no longer optional. Without a documented IR plan, a team capable of formulating an early warning within 24 hours, or a process for the 72-hour report, companies will be in violation of the law from the first incident. Management will be held personally liable.

The impact: The NIS2 reporting obligation is forcing professionalization. Companies that previously only contacted IT after an incident (which might not have been reachable on weekends) must now demonstrate a 24/7 capable process. This is driving demand for managed security services and professional retainer agreements with IR service providers.

BSI President Plattner emphasizes the urgency: “We cannot afford this level of uncertainty.” In the context of the approximately 179 billion euros that cybercrime costs Germany annually, professional incident response is not just a compliance requirement but an economic imperative.

Germany’s International Standing

The International Institute for Strategic Studies (IISS) ranks Germany as a “Tier Two Cyber Power,” alongside the Netherlands and Singapore. Tier One: only the USA. Germany’s strength lies in its structured CERT ecosystem with multiple layers: CERT-Bund, Citizen-CERT, Bundeswehr-CERT, and country-specific CERTs, as well as private-sector entities like the Telekom-CERT and DCSO.

In offensive cyber capabilities, Germany lags behind key partners USA and UK. However, for Germany as an economic location, the defensive side is crucial: Can German companies detect attacks, respond, and limit damage? The infrastructure for this exists and is being further strengthened by NIS2.

At the 2025 European Cybersecurity Challenge (ECSC), Germany finished third behind Italy and Denmark. This shows: The talent pool for security professionals is there, with training programs at TU Darmstadt, Ruhr-Universität Bochum, and Saarland University producing internationally competitive experts.

The Honest Counterargument

The three-tier system has its gaps. The biggest one is the Mittelstand (small and medium-sized enterprises). CERT-Bund serves federal authorities and rarely reaches small businesses. DCSO serves large corporations, and the Telekom-SOC is a commercial service. A company with 80 employees that detects a ransomware attack at 2 AM often faces the challenge alone.

The NIS2 reporting obligation theoretically helps by enforcing processes. However, 24 hours for an early warning is ambitious if the only “IR team” is the CEO with a personal laptop. Managed security services are the answer, but they cost between 500 and 2,000 euros per month, making them a luxury rather than a necessity for many Mittelständler.

Additionally, 47 percent of all .de IP addresses accessible from the internet expose sensitive information, indicating that even basic hygiene measures are lacking in nearly half of German organizations. Incident response is important, but prevention would be better.

Five Steps to Professional Incident Response

1. Write and test an IR plan. Develop a written incident response plan that includes defined roles, contact lists, and escalation procedures. Conduct a tabletop exercise at least once a year to simulate the plan’s effectiveness. The plan must integrate NIS2 reporting deadlines (24h/72h/1 month).

2. Secure a retainer contract with an IR service provider. If you don’t have an in-house IR specialist, establish a contract with an external partner who can respond within hours. Providers like DCSO, Telekom Security, G DATA Advanced Analytics, or specialized boutique firms like HiSolutions offer such retainers.

3. Implement 24/7 monitoring. Whether through your own SOC or a managed service, continuous monitoring is essential. Without it, attacks may go unnoticed until significant damage has occurred. For example, Continental was compromised for four weeks before the breach was detected.

4. Set up BSI reporting channels. Familiarize yourself with the BSI portal for incident reporting before an actual crisis. Waiting until a crisis to locate the reporting form can waste valuable time.

5. Institutionalize lessons learned. After every incident (including thwarted attempts), conduct a thorough review. Determine what worked and what didn’t. For instance, Südwestfalen-IT incurred significant costs due to two breaches. The question of whether the attacks could have been prevented must be addressed to improve future responses.

Conclusion

Germany’s incident response ecosystem is more robust than its reputation suggests. The CERT-Bund, DCSO, and private-sector SOCs form a tripartite system that is unmatched in Europe. NIS2 further professionalizes this system through mandatory reporting requirements and personal liability. Incidents at Südwestfalen-IT and Continental have demonstrated that the system functions under stress. However, it still does not adequately serve small and medium-sized enterprises. For Germany, professional incident response is not just a cost factor; it is a prerequisite for ensuring that the 735 billion euros of the Made-in-Germany initiative are protected within a secure digital infrastructure.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What is CERT-Bund and when should I contact it?

CERT-Bund is the Computer Emergency Response Team of the BSI, responsible for coordinating national-level responses to security incidents. It operates a 24/7 service and requires NIS2-covered entities to report incidents through the BSI portal. Non-NIS2 companies can also contact CERT-Bund, but will receive only threat intelligence and technical advice rather than dedicated incident response support.

What is DCSO and who can become a member?

The Deutsche Cyber-Sicherheitsorganisation (DCSO) is a GmbH backed by Allianz, BASF, Bayer, and VW. It provides threat intelligence services and managed SOC solutions. Membership is open to companies willing to share threat information and contribute to operational costs. While direct membership for small and medium-sized enterprises (SMEs) is not available, DCSO insights are incorporated into the BSI’s situational awareness reports, indirectly benefiting these businesses.

How much does a managed SOC cost for SMEs?

A basic monitoring service (SIEM/XDR as a service, 24/7 alerting, monthly reporting) typically costs between 500 and 2,000 euros per month. Dedicated IR retainers can add an additional 1,000 to 5,000 euros per month, depending on the guaranteed response time. The alternative of setting up an in-house SOC with three analysts on shift work can cost upwards of 300,000 euros annually.

What happens if I don’t report a NIS2 incident within 24 hours?

Fines of up to 10 million euros or 2% of global annual revenue may be imposed. Company executives may face personal liability. Additionally, the BSI can request interim reports and take measures up to temporary management exclusion for repeated violations.

How do I prepare for an IR incident?

Three immediate steps: First, develop an IR plan that includes defined roles and contact information. Second, secure a retainer contract with an IR service provider. Third, conduct a tabletop exercise to test the plan’s effectiveness under stress. By completing these three steps, you will be better prepared than 80% of German SMEs.

Further Reading

NIS2 in Germany: What Companies Need to Implement Now (SecurityToday)

NIS2 as a Location Advantage (SecurityToday)

Reboot Germany: 735 Billion Euros in Investments (MyBusinessFuture)

Board Governance: Digital Competence on the Supervisory Board (Digital Chiefs)

Source Image: Pexels / Tima Miroshnichenko (px:5473955)

Further reading

Strategy & Governance · July 17, 2026

NIS2 Patchwork: Four States Face EU Court

The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.

A magazine by Evernine Media GmbH