Summary
- Germany is preparing measures covering cyberattacks, drone activity, and physical sabotage against critical infrastructure.
- Reported plans include a national sensor-based “cyberdome” intended to strengthen cyber defence.
- The full package has not yet been published, leaving its legal, technical, and procurement details unresolved.
Germany is preparing a broader national framework for protecting critical infrastructure against cyber intrusion, drone activity, and physical sabotage, bringing several forms of hybrid threat into the same resilience programme.
Plans attributed to the Federal Ministry of the Interior include expanded mobile counter-drone capabilities and a national cyber-defence network described as a “cyberdome”. The measures follow heightened concern over attempted sabotage and suspicious activity around strategic German infrastructure.
The complete package had not been published at the time of writing, leaving important details unresolved, including the cyberdome’s technical architecture, legal basis, procurement model, operational authority, and deployment timetable.
Interior Minister Alexander Dobrindt said hybrid attacks had become part of Germany’s daily security environment and were expected to increase, according to reporting on the planned measures.
The cyberdome is expected to use a network of digital sensors to improve detection of cyberattacks. Germany is already expanding federal cyber-defence capabilities and strengthening protection around strategic government and private-sector infrastructure.
The proposal sits alongside planned counter-drone measures following an August incident at Leipzig/Halle Airport, where a drone was found close to a runway. German authorities have also dealt with a wider pattern of concern over sabotage, espionage, and interference involving transport, defence, communications, and energy infrastructure.
Attribution remains sensitive. Russia has denied involvement in sabotage operations attributed or linked to Moscow by European governments and has rejected allegations connected with the German airport incident.
The policy direction nevertheless reflects a change in how infrastructure risk is being organised. Cyberattacks, physical interference, and drone activity can affect the same operational assets and may support one another during reconnaissance or disruption.
An adversary examining an airport, power network, defence manufacturer, or telecommunications operator does not need to remain within a single domain. Digital access can reveal operational information, while physical surveillance or drone activity can expose site layouts, communications equipment, or other infrastructure relevant to later interference.
That overlap complicates responsibility. Critical services are frequently operated by commercial companies, while government retains national-security, law-enforcement, intelligence, and civil-protection responsibilities around them.
A national sensor network would therefore need rules governing what information is collected, which organisations can access it, how warnings are distributed, and who is authorised to respond. Those questions are more difficult where private infrastructure operators and federal authorities share responsibility for protecting the same systems.
The same problem applies to physical countermeasures. Allowing infrastructure operators or authorities to take action against drones creates legal and safety questions that differ from conventional monitoring, particularly near populated areas or transport infrastructure.
Germany’s broader critical-infrastructure policy is already moving towards stronger resilience obligations and greater coordination between operators and government. The proposed anti-sabotage package would extend that direction by treating cyber defence as one component of a larger protective system rather than a separate IT discipline.
Its practical effect will depend on the detail that follows. A cyberdome based mainly on shared threat telemetry would create different operational and governance consequences from one involving centralised interception or active defensive measures.
The current proposal therefore establishes a direction rather than a finished architecture. Germany is preparing to join cyber intrusion, drone threats, and physical sabotage within the same national critical-infrastructure response, while the boundaries between state capability and operator responsibility remain to be defined.





