08.09.2026

eco Board Member on the Cyberattack Against Berlin: “The State Must Not Exempt Itself from Cybersecurity Requirements”

The August cyberattack on parts of Berlin’s state administration network and the publication of the stolen data on 4 September demonstrate, in the view of eco – Association of the Internet Industry, how dangerous differing security standards for the public and private sectors can be.

In addition to personal data, apparently sensitive documents concerning emergency plans for the water supply and the extension of the Federal Chancellery were also published. This confirms the criticism already voiced by eco in 2024: state and municipal authorities also need binding, verifiable cybersecurity standards.

“The state must not exempt itself from cybersecurity requirements. Under NIS2, companies have to make considerable efforts to protect their systems and data. At the same time, comparable binding requirements do not apply directly to state and municipal administrations. The attack on Berlin shows that this gap is not merely a theoretical problem,” says Prof. Dr Norbert Pohlmann, a member of the eco Board.

In its statement of 28 May 2024 on the draft NIS2 Implementation and Cybersecurity Strengthening Act, eco had already explicitly criticised the exemption for federal-state bodies. In the Association’s view, action must now follow.

“Anyone who requires companies to ensure cybersecurity must apply at least the same standard to their own public authorities. Sensitive administrative data must not receive less protection than data held by a company simply because it sits on a different desk,” says Pohlmann.

This is particularly evident when it comes to protecting critical infrastructure. A water utility may comprehensively secure its own systems, yet sensitive information about its infrastructure held by a public authority can still be compromised.

“Cybersecurity does not end at organisational boundaries. Where public authorities manage information about critical infrastructure, appropriate security standards must also apply and be implemented there,” says Pohlmann.

Companies subject to the NIS2 Implementation Act must systematically assess cyber risks, implement protective measures and document compliance. These measures include backups, arrangements for recovery following security incidents, access controls and regular training. Significant security incidents must be reported within clearly defined time limits. Managing boards are also responsible for implementing and monitoring the security measures.

No comparable catalogue of obligations under federal law currently applies directly to state and municipal administrations. Responsibility for implementing the European requirements in critical areas of state administrations therefore rests with the federal states.

“Berlin is a wake-up call: cybersecurity must not become lost in a maze of responsibilities within Germany’s federal system. Attackers do not care whether a vulnerability lies with the German federal government, a federal state or a municipality. All that matters is whether it exists and can be exploited,” says Pohlmann.

eco is therefore calling for a joint emergency plan involving the German federal government, the federal states and municipalities. It must specify how vulnerable systems are to be checked at short notice, compromised access credentials blocked and affected authorities and organisations notified. Clear reporting channels, defined responsibilities and regularly tested procedures are needed for future attacks.

In addition, eco is calling for consistently high security standards for state and municipal authorities, binding implementation deadlines and independent audits. The necessary funding must be provided for specialist staff, secure technology and mandatory training.

eco also sees a need for action in day-to-day operations. Effective cybersecurity does not begin with the next attack, but with routine administrative processes.

“Employees need secure, workable procedures for handling confidential documents and access credentials in their day-to-day work. The heads of public authorities must provide these procedures, train employees in their use and monitor compliance. Responsibility for the security of administrative data cannot be shifted onto individual employees,” says Pohlmann.

eco Board Member Norbert Pohlmann on Log4J Security Vulnerability: Cyber crime hits new level – German federal government must continue to promote trust and security on the Internet