In brief: The reform of intelligence services law threatens to turn the BSI from an independent security provider into a supplier for the BND, industry associations warn.
The planned reform of intelligence services law provides that the BSI will in future pass on knowledge of security vulnerabilities to the BND. Bitkom, Eco and VATM criticize that the state is thereby knowingly keeping vulnerabilities open instead of having them closed.
The German federal government is planning a reform of intelligence services law that would impose new obligations on the Federal Office for Information Security (BSI): if the agency detects vulnerabilities in IT systems, it will in future have to pass this information on to the Federal Intelligence Service (BND). The industry associations Bitkom, Eco and VATM are up in arms against the draft law. They accuse the state of knowingly keeping known security vulnerabilities open instead of having them closed promptly.
For CISOs and security officers at companies, the new regulation is of immediate importance. Until now, the BSI has been regarded as a trustworthy, primarily defensively oriented authority that reports vulnerabilities to manufacturers and issues warnings. If findings additionally flow to an intelligence service that can also use vulnerabilities offensively for its own purposes, the BSI’s role changes fundamentally. The associations fear that vulnerabilities will remain open longer because intelligence interests could stand in the way of prompt closure – with corresponding risks for the IT security of companies and critical infrastructure that depend on timely patches.
For security planning within organizations, this means reassessing the basis of trust in state reporting channels. Should the reform be implemented in its intended form, it is advisable not to rely solely on BSI notifications for one’s own vulnerability management processes, but to draw more heavily on additional independent sources and in-house threat intelligence capabilities. The further legislative process remains to be observed, particularly with regard to whether and in what form security authorities will in future be subject to a disclosure obligation toward manufacturers, or whether exceptions for intelligence use will be provided for.
Source: www.golem.de · Published August 12, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.