Cybercriminals in Germany increasingly use social engineering and impersonation of legitimate processes instead of pure malware techniques, as the Gen Report shows with increases of 134 percent in fake shop fraud and 160 percent in dropper malware.
NIS2 implementation obliges enterprises outside critical infrastructure to adopt strengthened cybersecurity measures from 2026 onwards and threatens substantial fines for non-compliance.
AI-powered attacks will fundamentally transform Germany’s cybersecurity landscape, while the country is already a top target for ransomware operations.
The NIS2 Directive significantly expands the scope of regulated companies and introduces new requirements for cybersecurity governance and risk management systems.
NIS2 requires companies to establish structured governance, implement technical security measures, and maintain demonstrable incident-response processes, for which CISOs must assume full responsibility at board level.