12.08.2026

BND Reform: Vulnerabilities Must Not Become a Tool for Intelligence Service Access

Commenting on the BND reform approved by the Federal Cabinet, Klaus Landefeld, Member of the Board of eco – Association of the Internet Industry, said:

“In light of the changing security landscape, intelligence services need modern technical capabilities. But the line is crossed when the state develops an interest in keeping vulnerabilities open for its own access purposes. Vulnerabilities must be closed and must not become a tool for intelligence service access.”

eco is particularly critical of the role envisaged for the BSI. Companies must be able to trust that information about vulnerabilities reported to the BSI is used first and foremost to close them as quickly as possible and secure the affected systems. A general obligation to pass information on to the BND creates a problematic conflict of objectives.

“The BSI must not become a supplier of vulnerabilities that can be exploited by intelligence services. Anyone reporting a vulnerability must be able to trust that the state will do everything in its power to close it, rather than first assessing how it might still be used for its own access purposes.”

In eco’s view, the short time window when newly discovered vulnerabilities emerge shows exactly where the priority must lie. When there are sometimes only a few hours between a vulnerability becoming known and being fixed, state resources must be focused on securing systems and applying patches quickly.

“If there are only a few hours, the state’s response must be: patch, don’t access. Because any vulnerability that can be exploited by the BND can, in principle, also be discovered and exploited by cybercriminals or foreign intelligence services.”

The new powers to intervene also fundamentally alter the role of the BND. From eco’s perspective, it is particularly critical that the foreign intelligence service will in future also be able to operate domestically in certain circumstances. This means that companies and operators of digital infrastructures in Germany could also fall directly within the scope of intelligence service measures.

“A foreign intelligence service must not be allowed to become a domestic actor through the back door. If the BND is to be able to intervene in IT systems in Germany in future, there must be particularly high thresholds for doing so and effective independent oversight. This directly affects the Internet industry.”

This makes it all the more problematic that the reform is simultaneously restructuring the oversight mechanisms. The responsibilities of the existing G10 Commission are to be largely transferred to the Independent Oversight Council. Furthermore, in cases of imminent danger, measures that are generally subject to prior oversight may already be carried out before the Oversight Council has reviewed them.

“Greater powers to intervene must not go hand in hand with less oversight. With such far-reaching measures, it is not sufficient for the intelligence service to act first and for independent oversight to take place only afterwards. A retrospective review cannot replace effective oversight before an intervention takes place.”

The use of AI and automated systems further exacerbates this issue. If technical systems can prepare or even trigger state interventions, responsibilities must remain clear and decisions must be traceable at all times.

eco therefore calls on the German Bundestag to significantly strengthen the reform, particularly with regard to the handling of vulnerabilities, the role of the BSI, BND measures within Germany, as well as independent prior oversight and limits on the new powers.

eco Board Member Klaus Landefeld on the German Coalition Agreement: “A surveillance overview bill must not just be lip service”