IT Security: The Scale of the Cyber Threat

- Ransomware is the greatest threat and is increasingly targeting SMEs and municipalities.
- Cybercrime-as-a-Service: Hackers are offering attacks as a service.
- Vulnerabilities in enterprise software are increasing at an alarming rate.
- AI is being misused to create more authentic spam and phishing emails.
- Companies must strengthen cyber resilience through upgrades and training.
Cybercrime has long been a part of everyday digital life: according to the Ministry of Defence , both individuals and companies have had to deal with cyber threats since 2005. That was the year the Federal Office for Information Security (BSI) first published its report on the state of IT security in Germany and has been monitoring the threat landscape ever since.
Initially, the report was published every two years, but the frequency has increased since 2013. This is because concerns about cybersecurity are growing alongside increasing digitalization. The current report for 2023 shows that these concerns are justified: the situation remains tense to critical, and the threat in cyberspace is “higher than ever before”. What does this mean in concrete terms?
Learn more about cybersecurity in our concise NIS2 blog post.
Ransomware is the biggest threat – and it no longer just affects large corporations
Attacks involving malicious software (ransomware), which are often financially motivated, have been the greatest threat to cybersecurity for years. From June 1, 2022, to June 30, 2023, an average of 250,000 new malware variants were discovered – every single day.
While attackers previously targeted primarily multi-million dollar corporations, they now target increasingly often small and medium-sized enterprises (SMEs) as well as municipalities and research institutions. Many of these organizations often have a backlog in terms of IT security and are therefore "easy prey" for attackers.
Cybercrime-as-a-Service: Hackers are becoming increasingly professional
Cybercrime has become a lucrative business for attackers, one that is performing so well that hackers are collaborating across borders and industries and outsourcing specific tasks. Individual steps of cyberattacks are being offered as services – the BSI therefore refers to this as "Cybercrime-as-a-Service".
The 2023 Federal Cybercrime Situation Report shows that an increasing number of cybercrimes in Germany are being committed from abroad. Compared to 2022, the number of crimes committed from abroad rose by 28 percent in 2023, while domestic crimes fell by 1.8 percent, though they remain stagnant at a high level with 134,407 cases.
Software vulnerabilities are reaching a worrying level
While hacker software is constantly improving, the BSI identified an increasing number of vulnerabilities in corporate software in 2023. These are used by attackers as entry points. Within just one year, around 27,000 new vulnerabilities were discovered in specialized applications, server infrastructures, and even smartphone apps. It is particularly concerning that not only is the number of security gaps rising, but more and more of them are being classified as critical.
Increased risks due to technological progress
Artificial intelligence became accessible to the masses with the launch of ChatGPT and can be used from almost any computer or smartphone. While generative AI models offer many advantages, in the wrong hands they become a threat to personal data, for example when cybercriminals use them to make spam and phishing emails appear even more authentic. Companies that use AI software could also inadvertently increase their attack surface for hackers.
Companies must become more resilient
The threat landscape in cyberspace remains tense as technological progress continues unabated. Companies and individuals who want to benefit from the advantages of digitalization and artificial intelligence while still protecting themselves from cyberattacks must strengthen their cyber resilience.
This means they must be aware of the dangers of the cyber world, make their IT systems resilient, and prepare for the worst-case scenario. Some of the most important measures for greater cyber resilience include, among others,
- security updates
- backups
- data backups
- emergency plans for successful attacks
- Employee training
The federal government defines IT security as an essential service for businesses and a protective measure for citizens. To strengthen cybersecurity in this country, it has transposed the EU Directive on Security of Network and Information Systems (NIS2) into national law. As of October 2024, this establishes clear requirements for many companies regarding how they must protect their IT systems.
Do you need an IT and data security strategy? We are here to help
We would be happy to discuss whether you are affected and what specific steps your company can take to protect its data in a no-obligation consultation.
Would you like to learn more about IT security and secure your company for the long term?
Get in touch for a no-obligation consultation. We will support you in implementing the requirements and avoiding penalties.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.












