
German SMEs Face High Cyber Risk - But Progress Has Been Made in Resilience and Support Services
The Federal Office for Information Security (BSI) has once again warned that the cybersecurity situation in Germany is serious, but not hopeless: a large increase in new malware, a growing threat of ransomware and data breaches, but also increased resilience through international cooperation and improved security measures, which are the hallmarks of the 2024 situation report.
Ransomware attacks, in particular, remain the biggest threat to German companies. In addition to large businesses, small and medium-sized companies are increasingly being targeted. The cost to businesses is rising sharply: In the third quarter of 2023, the average ransom paid after a ransomware attack was $850,000. Another worrying trend is the rise of malware, with an average of 309,000 new variants registered every day, a 26 percent increase compared to the same period last year. Despite these circumstances, increased international cooperation has begun to show positive results, such as the successful takedown of several international ransomware groups. IT security standards and Crisis Preparedness (KRITIS) for critical infrastructure operators have also been further developed.
For Germany’s 3.1 million SMEs, the cyber security situation remains tough. Smaller companies in particular, which often do not have their own IT staff and whose IT security tasks are limited by time or cost, are often unable to implement basic protection measures. Many SMEs also lack awareness of current threats and their own security risks.
Cyber Risk Check as A New Standard For German SMEs
To help in a targeted way, Der Mittelstand. BVMW has partnered with BSI to develop the Cyber Risk Check - a standard specifically tailored to the needs of small and micro businesses, Derived from the “mIT Standard sicher” project funded by the Federal Ministry of Economic Affairs and Climate Protection (BMWK) in the “Enterprise IT Security” initiative. The inspection is carried out by way of structured interviews with certified IT service providers and provides companies with specific recommendations for action to improve their cyber security. Funding programs at the federal and state levels provide financial support for participation activities and provide an important basis for SMEs” IT security strategies.
Marc Dönges, Project Manager of the SME Cyber Security Transfer Office, stressed: “With the cyber risk check, we create real added value for SMEs. Above all, the simple, time-saving application makes it easier for businesses to start working on cybersecurity.” The SME Cyber Security Transfer Center also offers an additional service for small businesses: “CYBERsicher Check”, a free online tool, helps companies conduct an initial self-assessment of their IT security. As part of CYBERDialogues, businesses can gain individual advice on actions to take so that they can develop targeted protection measures.
For more information about the Cyber Security Transfer Center for smes, visit: transferstelle-cybersicherheit.de.
