AI risks have displaced malware as the primary threat for security leaders in the DACH region, while companies rely on governance and European controls.
The German administration is introducing centrally governed cybersecurity standards, including multi-factor authentication, regular vulnerability assessments, and enhanced monitoring of network activity.
CGI and Heuking combine legal compliance consulting with technical implementation to translate regulatory requirements such as NIS2 into secure, workable systems.
Compliance teams must meet several NIS2 deadlines in the coming summer months to avoid penalties and fulfil the statutory requirement for IT security in critical sectors.
CISOs remain in their positions for an average of only 18–26 months as they face personal liability for security incidents while being isolated from strategic decisions in daily operations — shared responsibility and continuous prevention are proposed solutions.
Two-thirds of companies are currently failing to achieve NIS2 compliance and must carry out extensive measures within the remaining time to avoid fines.