Cybersecurity 2026

GERMANY Trends and Developments Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton

German companies in strategically relevant sectors are particularly exposed. This includes critical infra - structure, energy, manufacturing, logistics, health - care, telecommunications and companies involved in defence-related supply chains. However, hybrid threats are not limited to these sectors. Organisations with valuable data, technological know-how or central positions in supply chains may be targeted regardless of size or public profile. Supply chains play a key role in geopolitical cyber- strategies. Attackers increasingly target suppliers, ser - vice providers or software components to gain indirect access to larger organisations or to disrupt entire eco - systems. In Germany’s highly interconnected industrial environment, such attacks can have cascading effects across multiple industries and regions. This reinforces the importance of supply chain visibility and resilience beyond immediate contractual relationships. Hybrid threats also exploit organisational and human factors. Social engineering, manipulation of commu - nication channels and targeted disinformation can be used to create confusion during incidents or to influence internal decision-making. In crisis situations, uncertainty about the nature and origin of an attack can delay responses and amplify damage. Effective crisis management therefore requires not only tech - nical expertise but also strategic communication and co-ordination at senior management level. Another challenge lies in the long-term nature of many geopolitical cyber campaigns. Unlike opportunistic cybercrime, state-linked actors may remain dormant in systems for extended periods, collecting informa - tion or preparing for future disruption. This persistence requires organisations to adopt a long-term security mindset that goes beyond perimeter defence and focuses on detection, monitoring and resilience. In response to these developments, German organi - sations increasingly integrate geopolitical risk con - siderations into their cybersecurity strategies. This includes scenario planning for large-scale disruptions, assessment of dependencies on foreign technology providers and closer co-ordination between cyberse - curity, risk management and strategic planning func - tions. Cybersecurity is thus becoming an integral part

of broader resilience and continuity strategies in an uncertain geopolitical environment. Cybersecurity as a Board-Level Responsibility By 2026, cybersecurity has firmly established itself as a board-level issue in German companies. Executive management is expected to understand cyber-risks in business terms and to integrate them into strategic decision-making. Cybersecurity is no longer delegat - ed solely to technical teams but is treated as a core governance responsibility. Boards are increasingly involved in defining risk appe - tite, approving cybersecurity budgets and overseeing incident-response preparedness. This includes under - standing dependencies on digital infrastructure, third- party providers and cloud platforms, as well as the potential financial and operational impact of cyber- incidents. Scenario-based exercises have become a common tool to test decision-making under pressure. These simulations highlight the importance of clear roles, fast escalation paths and effective communication. They also reveal that cyber-incidents often require balancing competing priorities, such as operational continuity, legal obligations and reputational consid - erations. Executive Accountability and Internal Governance The elevation of cybersecurity to board level also affects perceptions of accountability. Executives are increasingly aware that inadequate cyber govern - ance can result in personal reputational damage, shareholder disputes or contractual claims. Even in the absence of regulatory enforcement, stakeholders expect demonstrable oversight and informed deci - sion-making. As a result, companies are investing in clearer gov - ernance structures. Responsibilities for cybersecurity are more precisely defined, often combining technical, legal and operational perspectives. Documentation of decisions, risk assessments and response measures have become a critical element of corporate defence. This trend reflects a broader shift towards transpar - ency and traceability. Organisations are expected

159 CHAMBERS.COM

Powered by