{"id":7125,"date":"2023-04-28T12:28:37","date_gmt":"2023-04-28T12:28:37","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-3229\/"},"modified":"2026-05-10T19:05:58","modified_gmt":"2026-05-10T19:05:58","slug":"how-to-prevent-cyberattacks-on-critical-infrastructures","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2023\/04\/28\/how-to-prevent-cyberattacks-on-critical-infrastructures\/","title":{"rendered":"How to Prevent Cyberattacks on Critical Infrastructures"},"content":{"rendered":"<p><strong>The recent DDoS attacks (Distributed Denial of Service, a cyberattack through flooding with malicious traffic) on German airports, state authorities, and the police in spring 2023 show: The vulnerability of critical infrastructures (KRITIS) is more acute than ever. Even the first wave in autumn 2022 (including attacks on Nord Stream pipelines) was alarming.<\/strong><\/p>\n<p>How vulnerable are critical infrastructures, and what measures must companies and organizations mandatorily take to protect themselves? The KRITIS whitepaper by Link11 and Schalast, \u201cCritical Infrastructures in the Crosshairs,\u201d provides an overview.<\/p>\n<p>In addition to physical sabotage or accidents, cyberattacks on these systems have primarily increased in 2022\/23. According to a Bitkom study, 51 percent of critical infrastructure operators even expect a further increase in the near future. The Federal Office for Information Security (BSI) therefore states in its current situation report: The threat level is \u201chigher than ever.\u201d No wonder, then, that regulation by the EU and the federal government is constantly increasing.<\/p>\n<p>Critical infrastructures  &#8211;  including the sectors of energy, finance, health, telecommunications, government and administration, transportation, or water  &#8211;  are essential for the functioning of our society and economy. For this very reason, they are also in the focus of cybercriminals:<\/p>\n<p>Attackers can steal data, extort money, and cause physical damage. With far-reaching consequences: million-euro production outages and supply shortages that can endanger or even cost human lives. The damage alone for the German economy in 2022 amounted to around 203 billion Euro. This can affect corporations, small and medium-sized enterprises, the administration, and civil society alike. For the affected population, cyberattacks on KRITIS mean direct damage to public supply.<\/p>\n<p>In view of increasing cyberattacks, operators of critical infrastructures and companies must deal more intensively with digital threats and protection mechanisms. Because as soon as it&#8217;s about more than ransom, cyberattacks can not only impair business capability (data loss and manipulation or reputational damage) but also affect society as a whole. Companies should therefore structure their IT systems so that an attack has only minimal impact and critical parts of the network cannot be reached.<\/p>\n<p>Lisa Fr\u00f6hlich (Corporate Spokesperson Link11) comments:<\/p>\n<p><i>\u201cBecause KRITIS are so important to our lives, pronounced and constantly evolving regulations from the federal government and the EU set the framework for the necessary IT security. At the same time, the recent series of DDoS attacks in Germany shows that effective DDoS protection is indispensable so that operators of critical infrastructures are not impaired by such attacks.\u201d<\/i><\/p>\n<p style=\"text-align: center;\"><strong><em>This graphic shows more about the results of the report:<\/em><\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3231 aligncenter\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2023\/04\/Link11_One-Pager_Die-Lage-ist-KRITISCH-700x990.jpg\" alt=\"\" width=\"564\" height=\"798\" srcset=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2023\/04\/Link11_One-Pager_Die-Lage-ist-KRITISCH-700x990.jpg 700w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2023\/04\/Link11_One-Pager_Die-Lage-ist-KRITISCH-250x353.jpg 250w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2023\/04\/Link11_One-Pager_Die-Lage-ist-KRITISCH-768x1086.jpg 768w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2023\/04\/Link11_One-Pager_Die-Lage-ist-KRITISCH-120x170.jpg 120w\" sizes=\"auto, (max-width: 564px) 100vw, 564px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li>DDoS attacks on German airports, authorities, and police highlight the acute vulnerability of critical infrastructures<\/li>\n<li>The economic damage from cyberattacks in 2022 amounted to around 203 billion Euro<\/li>\n<li>Regulation by the EU and the federal government is steadily increasing  &#8211;  effective DDoS protection is indispensable for KRITIS operators<\/li>\n<\/ul>\n<h2>Key Facts<\/h2>\n<p><strong>Damage Amount 2022:<\/strong> 203 billion Euro for the German economy<\/p>\n<p><strong>Expectation:<\/strong> 51 percent of KRITIS operators expect a further increase in cyberattacks<\/p>\n<p><strong>BSI Assessment:<\/strong> According to the BSI, the threat level is higher than ever before<\/p>\n<p><strong>Affected Sectors:<\/strong> Energy, finance, health, telecommunications, transportation, water, public administration<\/p>\n<p><strong>Fact:<\/strong> 75 percent of consumers trust companies more that handle data transparently, according to Cisco.<\/p>\n<p><strong>Fact:<\/strong> The average processing time for a data protection complaint with German supervisory authorities is 8 months, according to the BfDI.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>What are critical infrastructures (KRITIS)?<\/h3>\n<p>KRITIS includes organizations and facilities that are essential for the functioning of society and the economy. These include the sectors of energy, finance, health, telecommunications, transportation, water, and public administration.<\/p>\n<h3>Why are KRITIS operators particularly at risk?<\/h3>\n<p>Outages of critical infrastructures can directly affect millions of people  &#8211;  from supply shortages to dangers to human life. It is precisely this high impact that makes KRITIS preferred targets for cybercriminals and state-sponsored actors.<\/p>\n<h3>What are DDoS attacks and how do they work?<\/h3>\n<p>DDoS stands for Distributed Denial of Service. In this type of attack, a system is overwhelmed with a flood of malicious traffic, making it inaccessible to regular users. The attacks can paralyze entire infrastructures for hours or even days.<\/p>\n<h3>What regulatory requirements apply to KRITIS?<\/h3>\n<p>KRITIS operators are subject to strict requirements under the IT Security Act 2.0 and the EU Directive NIS2. These include reporting obligations in the event of security incidents, minimum standards for IT security, and regular evidence of implementation.<\/p>\n<h3>How can KRITIS operators protect themselves against DDoS attacks?<\/h3>\n<p>Effective DDoS protection requires specialized defense solutions that detect and filter malicious traffic before it reaches the actual infrastructure. Network segmentation and emergency plans additionally minimize the impact of successful attacks.<\/p>\n<h2>Further Reading in the Network<\/h2>\n<p><a href=\"https:\/\/www.cloudmagazin.com\">Cloud-based KRITIS protection on cloudmagazin.com<\/a><\/p>\n<p><a href=\"https:\/\/www.mybusinessfuture.com\">Cybersecurity and regulation on mybusinessfuture.com<\/a><\/p>\n<p><a href=\"https:\/\/www.digital-chiefs.de\">KRITIS security as a strategic priority on digital-chiefs.de<\/a><\/p>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2023\/04\/28\/post_id-3221\/\">Multi-Carrier Access as a Guarantee Against System Failure<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/?p=2836\">IT Security &amp; Data Protection: The Federal Cabinet is Putting Pressure on<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/26\/gdpr-2026-whats-changing-and-what-companies-need-to-know\/\">DSGVO 2026: What Will Change and What Companies Need to Pay Attention To<\/a><\/li>\n<\/ul>\n<p style=\"text-align: right;\">Header Image Source: Adobe Stock \/ <a href=\"https:\/\/stock.adobe.com\/de\/contributor\/208483344\/eakrin?load_type=author&amp;prev_url=detail\" data-ingest-clicktype=\"details-contributor-link\">Eakrin<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"The recent DDoS attacks (Distributed Denial of Service, a cyberattack through flooding with malicious traffic) on German airports, state authorities, and the police in spring 2023 show: The vulnerability of critical infrastructures (KRITIS) is more acute than ever. Even the first wave in autumn 2022 (including attacks on Nord Stream pipelines) was alarming. How vulnerable [&hellip;]","protected":false},"author":55,"featured_media":3233,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"cyberattacks","_yoast_wpseo_title":"How to Prevent Cyberattacks on Critical Infrastructures","_yoast_wpseo_metadesc":"Cyberattacks on critical infrastructure: Learn how to prevent DDoS threats and protect vital systems\u2014discover actionable defense strategies now.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-3229"],"footnotes":""},"categories":[217,251],"tags":[],"class_list":["post-7125","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-innovation","category-news"],"evm_reading_time_minutes":5,"wpml_language":"en","wpml_translation_of":3229,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7125","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=7125"}],"version-history":[{"count":5,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7125\/revisions"}],"predecessor-version":[{"id":11898,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7125\/revisions\/11898"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/3233"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=7125"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=7125"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=7125"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}