Decoding the world of cybersecurity

German experts challenge cyber defence bill

German experts have backed stronger national cyber capabilities while warning parliament that proposed active defence powers need clearer oversight, responsibilities and safeguards against collateral damage.

German experts challenge cyber defence bill
Summary
  • Germany’s Bundestag held a two-hour hearing on legislation intended to strengthen national cyber defence.
  • Experts broadly supported stronger capabilities but questioned oversight, fragmented responsibilities and intrusive measures.
  • Debate centred on active cyber defence, judicial safeguards and the division of authority between federal and state bodies.

German cybersecurity experts have urged lawmakers to tighten safeguards around proposed active cyber defence powers even as witnesses broadly agreed that the country needs stronger capabilities to respond to serious attacks.

The Bundestag Interior Committee held a two-hour public hearing on 5 October on the federal government’s draft legislation to strengthen cybersecurity, bringing together technical experts, legal specialists, civil society representatives and the head of Germany’s Federal Criminal Police Office.

While the need to strengthen cyber defence was largely uncontested, witnesses questioned how intrusive new powers would be authorised, which institutions should use them and how Germany should prevent interventions from affecting unrelated systems or third parties.

Dirk Heckmann of the Technical University of Munich argued that the proposal would close important regulatory gaps and improve the state’s ability to identify and counter attacks earlier. His evidence nevertheless called for stronger constitutional safeguards where measures involve covert intervention, manipulation of information technology or the collection of data.

Sven Herpig of Interface concentrated on the institutional design around those powers, identifying fragmented responsibilities, inconsistent thresholds for intervention and insufficient emphasis on resilience. Where federal and state authorities share or overlap responsibilities, unclear decision making can create delays during incidents while also making accountability harder to establish afterwards.

Cyber operations complicate the division of authority because attackers, infrastructure providers, victims and compromised intermediary systems can sit in different jurisdictions at the same time. An intervention aimed at stopping hostile traffic may therefore affect equipment belonging to an organisation that was itself compromised rather than operated deliberately by the attacker.

Dennis-Kenji Kipker of the Cyberintelligence Institute also questioned whether parts of the proposal contained the legal safeguards required for measures capable of affecting third-party systems. His evidence raised concerns around judicial scrutiny, intervention thresholds and the protection of organisations or individuals who are not responsible for the attack being disrupted.

Those concerns become more acute when cyber defence moves beyond blocking traffic, filtering malicious requests or coordinating the removal of criminal infrastructure. Measures that enter, alter or disable remote systems create different questions around attribution and proportionality, especially when investigators cannot immediately establish who controls the infrastructure involved.

Constanze Kurz of the Chaos Computer Club supported the wider objective of improving cybersecurity but criticised state hacking measures that could themselves create damage. If a compromised server belongs to another victim, an intervention intended to disrupt an attacker can produce consequences for systems whose owners were never part of the hostile operation.

Holger Münch, president of Germany’s Federal Criminal Police Office, gave a more supportive assessment of the operational provisions. He argued that the legislation would address a long-standing deficit by establishing cyber-specific powers for the BKA and improving mechanisms for cooperation with telecommunications and digital service providers.

Haya Schulmann of Goethe University Frankfurt likewise supported creating a clearer legal basis for active cyber defence, including intervention in attacker systems as a last resort. Her evidence also identified gaps in the broader framework, including how information gathered by Germany’s cybersecurity authorities should contribute to a national situational picture.

Taken together, the evidence showed substantial agreement on the need for stronger defensive capability without equivalent agreement on the architecture surrounding it. Expanding technical powers does not resolve which body should make an intervention decision, what evidential threshold should apply or how errors should be reviewed when attribution later proves incomplete.

Germany has been expanding its response to cybercrime, espionage, sabotage and wider hybrid activity directed against government, businesses and critical infrastructure. Those pressures increase the attraction of powers capable of disrupting an operation before damage spreads, while simultaneously increasing the consequences of acting on incomplete information.

The draft legislation remains within the parliamentary process, and the committee hearing does not itself determine the final wording. Evidence submitted on 5 October will now sit alongside the government proposal as lawmakers decide how far German cyber authorities should be permitted to intervene outside infrastructure under their direct control.

The resulting framework will have to reconcile operational speed with legal oversight because the two requirements become hardest to balance precisely when an attack is moving quickly and its origin remains uncertain.

×