The evolution of threats in the digital environment is profoundly changing the way in which States understand national security. For years, the main concerns of governments were focused on international terrorism, traditional espionage and conventional military conflicts. However, the growing dependence on information technologies has opened a new scenario in which cyberattacks can cause damage comparable to that of a physical crisis, affecting essential services, critical infrastructures and even the economic stability of a country.
Germany is one of the European countries paying the greatest attention to this transformation of the security landscape. As Europe’s largest economy and one of the world’s main industrial centers, the country depends heavily on digital systems for the functioning of its public administration, its companies and its strategic infrastructures. This dependence also makes it an attractive target for groups of cybercriminals, organizations dedicated to industrial espionage and state actors interested in obtaining political, economic or military advantages.
Given this scenario, the German government is studying a reform that would allow the capabilities of its intelligence services to be strengthened in order to respond more effectively to cyberattacks. The proposal seeks to grant new tools to certain agencies to intervene when a digital threat compromises national security, always within a legal framework subject to institutional oversight. The debate has generated broad interest both in the political sphere and among cybersecurity experts and organizations defending civil rights.
An international context marked by the increase in cyberattacks
Cyberattacks have become one of the main risks for governments and companies around the world. In recent years, an increase has been observed both in the number of cyberattacks and in the level of sophistication of the techniques used by attackers to carry out each cyberattack. These cyberattack campaigns no longer seek only to obtain confidential information, but also to disrupt essential services, financially extort the organizations affected by a cyberattack or weaken the public’s trust in public institutions through cyberattack actions.

The conflict between Russia and Ukraine has contributed to accelerating this trend related to the cyberattack. The war has shown that current military operations combine conventional actions with disinformation campaigns, sabotage of critical infrastructures and cyberattacks directed against communication networks or government systems. For many analysts, cyberspace has become consolidated as a new scenario of confrontation in which States attempt to obtain strategic advantages through cyberattacks, without needing to directly resort to an armed confrontation, which has increased concern about the use of the cyberattack as a tool of pressure.
Europe has responded by strengthening its cooperation mechanisms in cybersecurity matters to prevent and respond to any cyberattack, although each country maintains its own competencies in developing its national capabilities against this type of cyberattacks. Germany considers that the increase in geopolitical tension requires reviewing the available tools to prevent, detect and respond more effectively to a cyberattack. The intention is not only to improve the protection of computer systems against a possible cyberattack, but also to adapt legislation to a technological environment that evolves very rapidly and in which the risk of suffering a cyberattack is increasingly greater.
Why does Germany consider a reform necessary?
German authorities maintain that current legal instruments were designed for a context very different from the one that exists today. When many of the regulations governing the activity of intelligence services were approved, the internet still did not have the central role it plays today and most critical infrastructures did not depend on digital networks as complex as those currently existing. This difference has generated a gap between existing threats, especially those related to cyberattacks, and the tools that institutions can use to prevent, contain and respond to a cyberattack of great magnitude.
Security officials consider that limiting themselves to detecting a cyberattack or collecting information about its perpetrators may be insufficient when a cyber aggression or cyberattack is underway. In certain cases, a cyberattack can spread within minutes and simultaneously affect multiple public agencies or private companies, causing significant interruptions in services. This speed makes it necessary to have mechanisms that allow action before the damage caused by a cyberattack becomes irreversible and before the cyberattack spreads to other critical infrastructures.
The debate does not revolve solely around the possibility of strengthening the State’s technical capabilities to respond to a cyberattack. It also focuses on precisely defining what the limits of these new powers would be, which agencies could exercise them and under what mechanisms of judicial and parliamentary control they should be developed in order to intervene against a cyberattack without violating fundamental rights. The intention is to prevent the strengthening of national security in the face of the growing risk of cyberattacks from implying an unjustified reduction of citizens’ constitutional guarantees.
The difficulty of identifying those responsible for a cyberattack
One of the greatest challenges faced by investigators is determining who is truly behind a cyberattack or a malicious computer operation. Unlike other types of aggression, in cyberspace it is relatively easy to conceal the origin of a cyberattack by using servers located in different countries, compromised networks or previously infected systems. This means that the address from which a cyberattack or intrusion apparently originates rarely coincides with the identity of those responsible, which makes the attribution of the cyberattack extremely difficult.
Specialized groups usually employ advanced techniques to hinder investigations into a cyberattack. Among them are the use of virtual private networks, infrastructures distributed across multiple jurisdictions and programs specifically designed to eliminate traces of activity once the cyberattack operation has been completed. In some cases, they even reuse tools developed by other groups with the aim of diverting investigators’ attention and making the attribution process of the cyberattack even more complicated.
This reality makes intelligence gathering an especially complex task when investigating a cyberattack. Before adopting any response measure against a cyberattack, authorities need to gather enough technical evidence that allows them to establish a high degree of certainty regarding the authorship of the cyberattack. An incorrect attribution of a cyberattack could not only affect third parties unrelated to the events, but could also generate diplomatic tensions with other countries or trigger disproportionate responses.
Precisely for this reason, Germany maintains close cooperation with European partners and international allies regarding information exchange to detect and analyze each cyberattack. Sharing indicators of compromise, behavior patterns and technical data makes it possible to accelerate investigations and increase the ability to identify coordinated cyberattack campaigns that simultaneously affect several States. This collaboration has become one of the fundamental pillars of European digital security and of the joint response to the growing number of cyberattacks.
International cooperation in the face of borderless threats
Cyber threats rarely respect national borders. A cyberattack can be planned from one continent, carried out through servers distributed across several countries and simultaneously affect organizations located in different regions of the world. This global dimension of the cyberattack means that no State can face all the risks associated with the digital environment on its own or respond effectively to an international-scale cyberattack campaign.
Germany actively participates in numerous international mechanisms aimed at strengthening cybersecurity cooperation in response to the growing number of cyberattacks. Within the European Union, there are initiatives focused on the exchange of information about incidents and cyberattacks, the development of common protection standards and the coordination of responses when a cyberattack affects several member states. These tools make it possible to share technical knowledge and improve the capacity to react to particularly sophisticated cyberattack campaigns.
The North Atlantic Treaty Organization has also increased its attention to the cyber domain during the last decade. The Alliance considers that a cyberattack or a cyberattack campaign can have consequences comparable to those of other forms of aggression and, for this reason, it has developed specific structures to strengthen cooperation among its members. Germany plays a relevant role within these initiatives due to its technological capacity and the strategic importance of its infrastructures in the face of the risk of suffering a cyberattack.
In addition to institutional cooperation, the private sector plays an increasingly important role in preventing any cyberattack. A significant part of critical infrastructures belongs to companies that manage essential services for the population and that can become targets of a cyberattack. For this reason, collaboration between public bodies, technology companies and infrastructure operators is indispensable to quickly detect a cyberattack and coordinate an effective response when an incident of this type occurs.

The balance between security and fundamental rights
Although the need to strengthen protection against cyberattacks has broad political support, the debate intensifies when reforms affect the powers of intelligence services to prevent or respond to a cyberattack. Germany has one of the most demanding legislations in Europe regarding data protection and fundamental rights, a reality that conditions any proposal related to state surveillance or the collection of information linked to a cyberattack.
Various civil rights organizations have recalled that the new powers must be subject to clearly defined limits and effective oversight mechanisms. From this perspective, any expansion of powers to combat a cyberattack must comply with criteria of necessity, proportionality and democratic control, preventing tools designed to deal with an exceptional cyberattack from being used indiscriminately. The objective is to guarantee that the protection of national security in the face of the increase in cyberattacks does not translate into unjustified restrictions on individual freedoms.
Supporters of the reform argue, for their part, that the evolution of threats requires adapting the existing legal framework. They argue that cybercriminals and state-sponsored actors precisely take advantage of the legal limitations of democratic countries to develop increasingly sophisticated cyberattacks. Consequently, they consider that providing intelligence services with appropriate tools to prevent and respond to a cyberattack constitutes a necessary measure to protect both institutions and citizens.
This exchange of arguments reflects a recurring issue in contemporary democracies: how to find a balance between the effectiveness of security policies against a cyberattack and respect for fundamental rights. The answer is not usually found in extreme positions, but rather in the design of control systems that allow action against a cyberattack or any other real threat without weakening the principles on which the rule of law is based.
The role of artificial intelligence in the new cybersecurity strategy
Artificial intelligence has become one of the tools with the greatest potential to transform cybersecurity and improve the response to a cyberattack. Machine learning algorithms are capable of analyzing millions of events per second, detecting anomalous behaviors associated with a possible cyberattack and generating alerts long before a human analyst could identify a threat. This capability is especially useful in a context in which the volume of information generated by networks, devices and applications continues to grow exponentially.
Intelligence agencies and organizations specialized in security consider that these technologies can significantly improve the early detection of espionage campaigns, intrusion attempts and coordinated cyberattacks against critical infrastructures. Thanks to the automation of certain tasks related to the detection of a cyberattack, analysts can focus their efforts on the strategic evaluation of the most complex incidents and on decision-making. However, the incorporation of these tools also raises questions about algorithm transparency, data protection and the need to always maintain human supervision in the most sensitive processes.
At the same time, attackers are also taking advantage of advances in artificial intelligence to perfect their cyberattack techniques. Fraudulent emails are becoming increasingly convincing, malicious programs can automatically adapt to different computer environments and disinformation campaigns can produce large amounts of false content with an increasingly realistic appearance. This technological race forces governments to constantly invest in research and development to prevent their defensive capabilities against cyberattacks from falling behind the evolution of threats.
The challenges of attribution in a hybrid warfare scenario
One of the factors that most complicates the response of States to cyberattacks is the difficulty of attributing with certainty the authorship of a cyberattack or a malicious computer operation. Unlike a conventional military attack, where it is normally possible to identify the responsible party relatively quickly, a cyberattack in cyberspace is usually designed precisely to conceal its origin. Those responsible for a cyberattack use networks distributed across different countries, previously compromised equipment and multiple layers of anonymization that make any investigation aimed at identifying the authors of the cyberattack extremely difficult.
This reality means that a government’s response to a cyberattack cannot be based solely on preliminary indications. Before adopting any measure that could have diplomatic or security consequences following a cyberattack, it is essential to gather technical evidence, contextual intelligence and information from different national and international organizations. The attribution of a cyberattack is, in most cases, a complex process that can last for weeks or even months, especially when there are actors behind the cyberattack with extensive technical resources and the ability to conceal their identity.
The situation becomes even more delicate when groups with indirect links to certain States are involved behind a cyberattack. On many occasions, governments resort to hacker organizations that, at least formally, act independently to carry out a cyberattack. This strategy makes it difficult to prove official involvement in the cyberattack and provides a certain degree of deniability, which complicates the adoption of retaliatory measures within the framework of international law and the coordinated response to future cyberattacks.

The growing sophistication of cyberattacks has forced governments to rethink the way in which they protect their national interests against each cyberattack. Germany, aware of its economic, technological and industrial relevance, considers that the current legal framework must evolve in order to respond more effectively to an environment where cyberattacks and other digital threats are part of everyday geopolitical competition. The proposal to expand certain capabilities of intelligence services represents an attempt to adapt institutions to a reality marked by interconnection, automation and the constant emergence of new risks associated with cyberattacks.
At the same time, the intense political debate demonstrates that any reform related to security against a cyberattack must be developed within the limits established by the rule of law. The protection of privacy, parliamentary control, judicial oversight and respect for fundamental rights continue to be essential pillars of the German democratic system. Finding a balance between these guarantees and the need to respond quickly to a cyberattack or increasingly complex cyberattack campaigns will be one of the greatest challenges for political decision-makers in the coming years.
Beyond the German case, this discussion reflects a global trend. Twenty-first century national security no longer depends solely on the military capacity or economic strength of a country, but also on its preparation to prevent, detect and respond to a cyberattack that may compromise the functioning of its institutions, companies and essential services. The evolution of cybersecurity and the constant increase in cyberattacks will continue to shape the international agenda in the coming years, and the decisions adopted by the main European democracies will contribute to defining the protection model that will prevail in an increasingly connected society.
In a scenario where the risk of suffering a cyberattack is increasingly greater, having the support of cybersecurity specialists is essential to protect the operational continuity of any organization. At ITD Consulting, we offer comprehensive solutions to prevent, detect and respond to cyberattacks, strengthening the security of companies and institutions through advanced technologies and specialized advice. If you wish to learn how to reduce the impact of a cyberattack and strengthen the protection of your digital infrastructure, you can contact our team by writing to [email protected], where we will be happy to help you develop a cybersecurity strategy adapted to the needs of your organization.