Hero section background image

Bitkom Economic Security Study 2026: Why Cyberattacks Have Become an Existential Risk for Companies

Content

According to Bitkom’s latest “Wirtschaftsschutz 2026” study, cyberattacks on companies have reached a new record level. Ninety-six percent of the surveyed companies were affected by data theft, industrial espionage, or sabotage over the past year, or suspect that they were. The resulting damage to the German economy is estimated to range between 211 and 270.8 billion euros. Three-quarters of that amount is attributable to cyberattacks.

These numbers are not an abstract problem for security departments. They affect every company that has an online presence. We break down the study’s key findings and explain what they mean for your security strategy.

The Bitkom 2026 Numbers at a Glance

The representative survey of over 1,000 companies with at least ten employees paints a clear picture. Cyberattacks account for 76 percent of total damages, and this figure is rising. Sixty-three percent of companies reported more attacks in the past twelve months than in the previous year. Two-thirds also expect an increase in the next twelve months.

Notably, the percentage of attackers belonging to foreign intelligence services has increased from 7 percent in 2023 to 37 percent today. This aligns with the assessment of Bitkom President Dr. Ralf Wintergerst and BfV President Sinan Selen, who presented the study together. Organized crime remains the largest group of perpetrators, but the lines between the two are increasingly blurred. At the same time, fewer companies can confirm whether an attack actually took place. Only 67 percent could confirm an incident, down from 87 percent the previous year.

Artificial Intelligence Is Changing the Attacker’s Playbook

According to Bitkom, 82 percent of companies believe that attackers are increasingly using artificial intelligence. Bitkom’s own figures support this trend. Damage from automated robocalls increased from 3 to 14 percent, while damage from deepfakes rose from 4 to 8 percent. Attackers are adapting their methods, personalizing content, and producing deceptively realistic audio and video.

This means that attacks are not only becoming more frequent, but also harder to detect. Classic detection patterns are often no longer sufficient. We show just how automated and precise these attacks have become using a real-world case in our article “Green Light, Red Alarm: What a Bot Attack on a Payment API Reveals About Modern Attack Methods.”

DDoS Attacks Keep Growing, and the Study Confirms What We See Firsthand

The Bitkom study shows a clear increase in damage caused by ransomware, phishing, and DDoS attacks. This trend is evident in our own network operations at Link11 every day. Botnets are growing quickly and increasingly exploiting poorly secured IoT devices to reach attack sizes that would have been unthinkable just a few years ago. Attacks exceeding 2 Tbit/s and more than 200 million packets per second are no longer the exception, as we have directly observed in our network.

These attack waves often deliberately shift between thousands of target systems and use random port combinations to evade defenses. Those who rely solely on static thresholds stand little chance against this kind of attack. Effective protection requires capacity, global distribution, and automated response times measured in milliseconds—exactly what our Network DDoS Protection delivers.

Learn how the new Network DDoS Protection protects you even more effectively

Faster mitigation, IPv6 parity, greater transparency, and significantly less manual effort.

Learn more

Why Traditional Protection Is Reaching Its Limits

The study also identifies the primary causes of damage to companies: inadequate detection of security incidents is the most common cause, followed by misconfigurations and weak identity and access management. All three factors have one thing in common. They tend to arise when security tools operate in isolation without capturing the full context of an attack.

Today’s modern web applications consist of a mesh of APIs, mobile clients, and automated integrations. Classic web application firewalls often cannot distinguish between legitimate API requests and those that are part of an automated attack. Web Application and API Protection (WAAP) provides additional protection through behavioral analysis, bot management, and application-layer defense.

The Domain Name System (DNS) itself is also increasingly targeted by attackers, though it rarely receives attention. DNSSEC validation and active, DNS-level monitoring address a gap that many security strategies still overlook.

Digital Sovereignty Is Becoming a Competitive Factor

Another finding from the study should catch the attention of IT leaders. Fifty-nine percent of companies see themselves as dependent on security solutions from the U.S. At the same time, 70 percent believe that German and European solutions are more reliable for authorities and companies in Germany. This sentiment aligns with an ongoing regulatory development. With the C3A criteria catalogue, Germany’s BSI defined concrete criteria for digital sovereignty in the cloud for the first time in early 2026. We break down what that actually means for IT leaders in our article “BSI C3A Criteria Catalog: What IT Leaders Need to Know.”

Sovereignty means more than just where a company is headquartered. It encompasses jurisdiction, operations, and demonstrable control over one’s own security infrastructure. For companies looking to work with European providers, this question is quickly becoming a genuine selection criterion.

What Companies Could Do Right Now

The Bitkom study provides more than just numbers. It also provides clear starting points for your own security strategy:

  • Prioritize attack detection, since inadequate detection remains the most common cause of damage.
  • Review configurations regularly, as misconfigurations lead to damage almost as often.
  • Implement identity and access management consistently to reduce the attack surface.
  • Treat DDoS protection, WAAP, and DNS security as one connected line of defense rather than separate measures. We show what that can look like in practice in our article “By the Time the Attack Hits, It’s Too Late: How to Build DDoS-Resilient Infrastructure Now.”
  • Factor demonstrable digital sovereignty into your choice of provider.

According to the study, the percentage of IT budgets allocated to security has stalled at 18 percent, despite the BSI and Bitkom’s recommendation of 20 percent. Given rising damage totals, this shortfall in investment is something few companies can afford.

Conclusion: Security Needs a Connected Approach

The Bitkom 2026 study makes it clear that cyberattacks are no longer a niche concern. Rather, they are a critical business reality for nearly every company. Companies that close security gaps individually are at a disadvantage against increasingly automated, AI-driven, and international attackers.

At Link11, we address this reality with an integrated protection approach based on Network DDoS Protection, WAAP, Secure CDN, and Secure DNS. This approach is developed in Germany. If you’d like to review your current security architecture with us, please get in touch.

Contact us now >>

Author

Link11 press spokesperson Lisa Fröhlich is the hub for all official corporate communications. When Lisa isn't attending one of the numerous IT events held throughout Germany, she works on new content with a focus on analyses and statistics. After graduating from Johannes Gutenberg University Mainz, she worked for almost a decade in public relations as a PR manager and press spokesperson for various companies before finding her way into the complex world of IT security.