Metricstream Logo
×
Blogs

Cyber Risk in the DACH Region: Why It's a Business Issue, Not Just an IT Problem

Cyber Risk in the DACH Region
7 min read

Introduction

A cyber risk may start in the IT environment. But its consequences rarely stay there. Across Germany, Austria, and Switzerland, cyber incidents are now landing on board agendas as top business risks. Two examples from this year illustrate why.

Deutsche Bahn, Germany's national rail operator, was hit by disruptive DDoS attacks that made headlines across European security outlets. Over February 17 and 18, the attack knocked out bahn.de, the DB Navigator app, and ticket-booking systems for hours. Germany's BSI, the federal cybersecurity agency, said the attack generated billions of requests per minute at its worst.

On January 7, 2026, the Buhlmann Group, a Hamburg-based steel distributor with roughly 2,000 employees and €428 million in revenue, lost 55 GB of data in a ransomware attack, including construction plans, personnel files, and financial records. The company reported that only a U.S. subsidiary was affected. The ransomware group Akira has claimed responsibility for the attack. Buhlmann is a mid-market industrial firm, not a multinational, a sign that ransomware crews aren't only chasing the biggest names anymore. Switzerland has seen its own surge in Akira activity: Swiss authorities confirmed around 200 companies hit, at what they called a record pace for the country.

Both incidents illustrate what's at stake when critical infrastructure or an industrial supply chain is targeted, as neither risk remained within IT. Across the DACH region, the same is true for healthcare, water, and other essential sectors. In addition, the regulatory calendar is moving just as fast. DORA (the EU's Digital Operational Resilience Act), NIS2 (the EU's updated cybersecurity directive for critical sectors), and the EU AI Act are all mandatory, with ISO 27001 increasingly expected by customers and regulators alike. Staying ahead requires a continuous, AI-powered approach to cyber GRC.

Why Cyber Risk Is Now a Business Risk in the DACH Region

Five forces explain why cyber risk in the DACH region has moved from an IT line item to a board-level concern. Here's what's driving each one.

1. Geopolitical cyber risks are rising

Cyberattacks across Germany, Austria, and Switzerland surged by 124% in 2025, driven largely by hacktivist campaigns and ransomware operations, according to research from Check Point Software Technologies. Germany alone accounted for more than 80% of all recorded DACH incidents, with Switzerland at 12% and Austria at 8%.

Across Europe, the DACH region accounted for 18% of all tracked cyberattacks, putting Germany ahead of France, Spain, and Italy in terms of individual-country share. Germany is an economic heavyweight and has attracted hacktivist attention for its support for Ukraine.

Overall, geopolitics is now a cyber risk driver on par with financial motives.

2. Ransomware keeps climbing across the region

Ransomware groups claimed responsibility for 4,641 attacks worldwide in the first half of 2026, a modest increase over the 4,381 recorded in the same period a year earlier, according to an analysis by Bitdefender. Within that total, Germany ranked fourth globally by the number of claimed incidents, with 176 attacks in the first half of 2026, trailing only the United States, Canada, and the United Kingdom. Switzerland and Austria also appeared on the global list, with 35 and 29 attacks, respectively.

3. Physical and digital risks are converging

Earlier this year, Berlin suffered the longest power outage the city had seen since 1945, caused by an arson attack on high-voltage cables. It illustrated a pattern that cybersecurity and risk teams are watching closely. Critical infrastructure attacks that blend physical sabotage with digital precursors, and disruptive digital attacks aimed squarely at physical infrastructure operators like Deutsche Bahn.

Germany’s KRITIS-Dachgesetz, a critical infrastructure resilience law that entered into force in March 2026, requires operators to address physical and organizational resilience alongside traditional cybersecurity controls rather than treating them as separate disciplines.

The convergence of IT and OT security is a critical trend for cyber GRC. Risk models built purely around digital attack vectors are already out of date for critical infrastructure operators and their suppliers.

4. AI has become a force multiplier on both sides of cyber risk

Generative and agentic AI have reshaped the threat picture for DACH enterprises. German companies continue to face heavy, sustained attacks, according to Check Point's 2026 Cyber Security Report.

Separately, 87% of organizations worldwide say they've encountered an AI-driven cyber attack in the past year, per SoSafe's 2025 Cybercrime Trends research. Most phishing emails targeting these companies are now AI-generated, making them harder for employees to spot and much faster for attackers to produce.

The threat isn't limited to phishing. State-backed threat actors and cybercriminals are increasingly using advanced AI models to carry out more sophisticated attacks. Trend Micro's H1 2026 APT report found that AI has moved beyond isolated experimentation into active attack cycles for state-affiliated groups. This includes autonomous reconnaissance and lateral movement within target networks. What this means is automated vulnerability scanning and faster attack chains that adapt in real time rather than following fixed scripts.

AI dramatically lowers the barrier to entry for attackers, meaning tasks that once required specialized expertise can increasingly be carried out through prompt engineering alone. Static, point-in-time risk assessments can't keep pace with threats that adapt this quickly.

Given the EU AI Act's governance requirements, DACH enterprises are now facing AI risk from two directions at once. AI as an attack vector, and AI as a regulated system that must be governed.

On the other hand, AI also equips today's IT and cyber risk professionals with tools to counter this shift, including continuous control monitoring, threat scanning, and automatic evidence collection, creating a connected system of decisions and actions to protect the enterprise.

5. The regulatory picture is becoming increasingly complex

DACH enterprises are now navigating overlapping EU and national obligations at the same time:

  • NIS2: The European Union's updated Network and Information Security Directive, designed to strengthen cybersecurity across critical sectors and essential services. It aims to ensure a high common level of cybersecurity by imposing stricter requirements on risk management, incident reporting, supply chain security, and corporate accountability. Roughly 29,500 companies in Germany fall in scope, and the BSI's registration portal has been live since 6 January 2026, with an initial deadline of 6 March 2026 for entities already in scope and a rolling three-month window for new entrants. Non-compliance carries fines of up to €10 million or 2% of global annual turnover.
  • DORA: The Digital Operational Resilience Act has applied directly across the EU, including Germany, since 17 January 2025. German financial institutions now face active BaFin examinations of their third-party registers, incident-reporting workflows, and resilience-testing documentation. This sits on top of existing BAIT rules, BaFin's banking-sector IT-risk circular. As of now, DORA sets no EU-wide cap on penalties, but enforcement and maximum fines are left to each member state's national law, and caps vary widely, from around €100,000 for individuals in Finland to several million euros in Germany. National authorities, including BaFin, can and do impose personal liability on senior managers for serious breaches.
  • EU Cyber Resilience Act: Reporting obligations for manufacturers begin on 11 September 2026, requiring a 24-hour early warning and a 72-hour full report for actively exploited vulnerabilities in connected products.
  • TISAX: TISAX, the Trusted Information Security Assessment Exchange run by the ENX Association on behalf of the Verband der Automobilindustrie (VDA), the German Association of the Automotive Industry, is the automotive industry’s standardized mechanism for assessing and sharing information security status. The VDA ISA 6.0 standard is mandatory for TISAX assessments requested after 1 April 2024 and directly aligns with the core requirements of NIS2. Suppliers are mandated to assess once against the VDA ISA catalog and share the results with business partners, rather than incurring repeat customer audits.

Regulatory challenges are perhaps one of the most important and complex aspects of cyber GRC and resilience. Managing multiple frameworks, regulations, deadlines, and exposures using traditional manual approaches can be challenging, especially when board attestations are required.

Build Cyber Resilience with MetricStream Cyber GRC

MetricStream's Cyber GRC is an interconnected, intuitive, and intelligent GRC product set. It helps organizations operating across Germany, Austria, and Switzerland connect cyber risk data from across the enterprise and a fragmented set of regulations into a single source of truth for board-level decision-making.

MetricStream Cyber GRC helps DACH enterprises manage regulatory complexity and cyber risk by:

  • Mapping obligations across overlapping regimes, harmonizing NIS2/BSIG, DORA, TISAX, and the Cyber Resilience Act requirements so compliance teams aren't managing five spreadsheets for five different regulators 
  • Supporting TISAX compliance with site-level assessments, maturity scales, questions and surveys, radar reporting, and other requirements 
  • Quantifying cyber risk in monetary terms to help boards weigh regulatory exposure across DORA, NIS2, and the Cyber Resilience Act and make better-informed cyber investment decisions 
  • Strengthening third-party and supply chain oversight, addressing the Register of Information requirements under DORA, and vendor risk exposure tied to cyber incidents 
  • Automating incident classification and reporting workflows to help meet the tight reporting timelines introduced by NIS2, DORA, and the Cyber Resilience Act 
  • Keeping pace with AI-accelerated threats and AI Act obligations at once. It continuously monitors emerging AI-enabled attack patterns as part of the risk register while mapping EU AI Act governance requirements alongside existing frameworks, so security and compliance teams aren't treating "AI as attacker" and "AI as regulated system" as two separate problems 
  • Providing real-time dashboards and reports that give executives and boards continuous visibility into risk and compliance posture, not just an annual snapshot

Want to learn more about how MetricStream Cyber GRC can help your organization build cyber resilience across DACH's risk and regulatory environment? Reach out or request a customized demo to see how our platform works.

Asia Anwar Jones Senior Vice President, Sales - UK & Europe

Asia Anwar Jones leads MetricStream’s commercial operations across Europe and the UK, bringing over 15 years of strategic leadership experience across GRC technology, Credit Risk, Financial Services and Pharmaceuticals. 

Throughout her career, Asia has played a transformative role in scaling and exiting high-growth ventures, while also driving commercial success within global publicly listed corporations. 

Her expertise spans enterprise sales, go-to-market strategy, and team leadership—navigating complex markets and regulatory landscapes with a proven track record of delivering sustained growth. 

A dynamic leader, Asia is known for bridging commercial innovation with operational excellence across both startup and corporate environments.