Cybersecurity: Tackling the Root Causes of Critical Infrastructure Crime

Germany is intensifying its battle against the evolving threat of digital warfare, but the frontline defenders are warning that treating the symptoms of cyberattacks is not enough. The Police Union (Gewerkschaft der Polizei, or GdP) is calling for a fundamental shift in strategy, urging the government to address the root causes of vulnerability rather than merely reacting to breaches.

As digital transformation accelerates across both public and private sectors, the risk profile for the nation has shifted. The GdP emphasizes that cyber resilience is no longer a luxury but a necessity for the survival of critical infrastructure and the maintenance of internal security. This push comes amid a landscape where state-sponsored actors and organized crime syndicates are operating with increasing professionalism and precision in the virtual space.

The urgency of this transition is highlighted by the persistent gaps in national protection standards. According to Alexander Poitz, the GdP’s deputy federal chairman responsible for digitalization and criminal policy, the lack of nationwide, uniform security standards leaves the country vulnerable. Poitz argues that an effective cybersecurity strategy is a decisive key to ensuring Germany’s internal security in an era of rapid digitalization.

At the heart of the debate is the need for a holistic approach that integrates the state, economy, science, and society. The GdP maintains that the resilience of critical infrastructure and the ability of authorities and organizations with security tasks (BOS) to withstand the pressure of disaster and crisis scenarios must be prioritized, regardless of current budgetary constraints.

Addressing the Gaps in National Cyber Defense

The current threat landscape is characterized by a steady increase in attacks from both state and non-state actors. Organized crime, in particular, has moved into the virtual realm, leveraging inadequacies in existing cyber defense structures to launch targeted strikes. This vulnerability is further exacerbated by a lack of digital competence and risk awareness among the general population, which often provides an easy entry point for criminals.

Addressing the Gaps in National Cyber Defense

To combat this, the GdP has advocated for the implementation of nationwide protection standards. The union points to the Federal Ministry of the Interior’s (BMI) cybersecurity strategy, which views the challenge as a collective responsibility. However, the transition from strategy to operational reality remains a point of contention. Poitz has explicitly warned that “security has no maximum price,” suggesting that financial constraints should not dictate the level of preparation for catastrophic cyber scenarios according to a June 2024 report from the GdP.

The focus is not only on preventing attacks but on ensuring that when they do occur, the systems can recover quickly and the state can continue to function. This concept of resilience is critical for the “Behörden und Organisationen mit Sicherheitsaufgaben” (BOS), who must remain operational even under the massive pressure of a crisis.

The Push for Digital Sovereignty and New Legal Powers

Beyond technical defenses, the GdP is concerned about the strategic dependence of the public sector on external digital technology providers. In a formal statement regarding the NIS 2 Directive, the union cautioned that increasing reliance on third-party providers must not lead to a reduction in the operational capacity of public services as detailed in their submission to the Bundestag. The union has called on the German government to take serious steps to ensure “digital sovereignty,” ensuring that the state maintains control over its critical digital infrastructure.

Parallel to these strategic concerns, there is a push for updated legal toolkits. The GdP has expressed a positive evaluation of a draft law aimed at strengthening cybersecurity, specifically noting the introduction of specific intervention powers to repel cyberattacks per a 2026 statement. These powers are seen as essential since they provide security agencies with instruments tailored to the unique technical characteristics of cyberattacks, allowing for a more proactive defense rather than a purely reactive one.

Key Challenges in the Cyber Landscape

  • Professionalized Crime: Organized criminal structures are increasingly using targeted virtual attacks to exploit weak defense systems.
  • Public Awareness: A general lack of risk awareness and digital literacy in the population creates vulnerabilities that criminals can exploit.
  • Budgetary Pressures: The GdP warns against allowing budget limitations to compromise the preparation for crisis scenarios.
  • Vendor Dependency: The risk that reliance on global tech providers could undermine the operational independence of the public sector.

What This Means for Critical Infrastructure

Critical infrastructure—ranging from energy grids to healthcare systems—represents the highest stakes in the fight for cyber resilience. The GdP argues that these systems require the “best possible resilience” because the consequences of a failure in these sectors could be catastrophic for the nation.

The shift toward “combating causes, not symptoms” implies a move away from simply patching software after a breach is discovered. Instead, it suggests a systemic overhaul that includes:

  1. Establishing mandatory, nationwide security standards for all critical operators.
  2. Investing in the digital education of the workforce and the general public to reduce the success rate of social engineering attacks.
  3. Developing sovereign technology stacks to reduce dependency on foreign providers.
  4. Granting law enforcement the technical and legal authority to intercept and neutralize threats before they reach their targets.

By focusing on these structural improvements, the GdP believes Germany can move from a state of vulnerability to a state of resilience, where the infrastructure is designed to withstand and recover from attacks by default.

Summary of GdP’s Strategic Priorities

GdP Cybersecurity Priorities
Area of Concern Proposed Solution Expected Outcome
Critical Infrastructure Maximum resilience and standardized protection Ability to withstand disaster/crisis scenarios
Public Sector Digital Sovereignty Prevention of operational restrictions by tech providers
Police Capabilities Specific intervention powers Technical ability to repel active cyberattacks
General Population Increased digital competence Reduction in successful criminal exploits

The ongoing dialogue between the Police Union and the Federal Ministry of the Interior will likely center on how these requirements are funded and implemented. As the draft law for strengthening cybersecurity moves forward, the focus will remain on whether the provided tools are sufficient to meet the sophistication of modern digital threats.

The next critical checkpoint will be the further legislative processing of the draft law to strengthen cybersecurity, which aims to provide the aforementioned intervention powers to security authorities.

Do you believe the government is doing enough to protect critical infrastructure from digital threats? Share your thoughts in the comments below or share this article with your network.

Leave a Comment