A cyber risk may start in the IT environment. But its consequences rarely stay there. Across Germany, Austria, and Switzerland, cyber incidents are now landing on board agendas as top business risks. Two examples from this year illustrate why.
Deutsche Bahn, Germany's national rail operator, was hit by disruptive DDoS attacks that made headlines across European security outlets. Over February 17 and 18, the attack knocked out bahn.de, the DB Navigator app, and ticket-booking systems for hours. Germany's BSI, the federal cybersecurity agency, said the attack generated billions of requests per minute at its worst.
On January 7, 2026, the Buhlmann Group, a Hamburg-based steel distributor with roughly 2,000 employees and €428 million in revenue, lost 55 GB of data in a ransomware attack, including construction plans, personnel files, and financial records. The company reported that only a U.S. subsidiary was affected. The ransomware group Akira has claimed responsibility for the attack. Buhlmann is a mid-market industrial firm, not a multinational, a sign that ransomware crews aren't only chasing the biggest names anymore. Switzerland has seen its own surge in Akira activity: Swiss authorities confirmed around 200 companies hit, at what they called a record pace for the country.
Both incidents illustrate what's at stake when critical infrastructure or an industrial supply chain is targeted, as neither risk remained within IT. Across the DACH region, the same is true for healthcare, water, and other essential sectors. In addition, the regulatory calendar is moving just as fast. DORA (the EU's Digital Operational Resilience Act), NIS2 (the EU's updated cybersecurity directive for critical sectors), and the EU AI Act are all mandatory, with ISO 27001 increasingly expected by customers and regulators alike. Staying ahead requires a continuous, AI-powered approach to cyber GRC.
Five forces explain why cyber risk in the DACH region has moved from an IT line item to a board-level concern. Here's what's driving each one.
1. Geopolitical cyber risks are rising
Cyberattacks across Germany, Austria, and Switzerland surged by 124% in 2025, driven largely by hacktivist campaigns and ransomware operations, according to research from Check Point Software Technologies. Germany alone accounted for more than 80% of all recorded DACH incidents, with Switzerland at 12% and Austria at 8%.
Across Europe, the DACH region accounted for 18% of all tracked cyberattacks, putting Germany ahead of France, Spain, and Italy in terms of individual-country share. Germany is an economic heavyweight and has attracted hacktivist attention for its support for Ukraine.
Overall, geopolitics is now a cyber risk driver on par with financial motives.
2. Ransomware keeps climbing across the region
Ransomware groups claimed responsibility for 4,641 attacks worldwide in the first half of 2026, a modest increase over the 4,381 recorded in the same period a year earlier, according to an analysis by Bitdefender. Within that total, Germany ranked fourth globally by the number of claimed incidents, with 176 attacks in the first half of 2026, trailing only the United States, Canada, and the United Kingdom. Switzerland and Austria also appeared on the global list, with 35 and 29 attacks, respectively.
3. Physical and digital risks are converging
Earlier this year, Berlin suffered the longest power outage the city had seen since 1945, caused by an arson attack on high-voltage cables. It illustrated a pattern that cybersecurity and risk teams are watching closely. Critical infrastructure attacks that blend physical sabotage with digital precursors, and disruptive digital attacks aimed squarely at physical infrastructure operators like Deutsche Bahn.
Germany’s KRITIS-Dachgesetz, a critical infrastructure resilience law that entered into force in March 2026, requires operators to address physical and organizational resilience alongside traditional cybersecurity controls rather than treating them as separate disciplines.
The convergence of IT and OT security is a critical trend for cyber GRC. Risk models built purely around digital attack vectors are already out of date for critical infrastructure operators and their suppliers.
4. AI has become a force multiplier on both sides of cyber risk
Generative and agentic AI have reshaped the threat picture for DACH enterprises. German companies continue to face heavy, sustained attacks, according to Check Point's 2026 Cyber Security Report.
Separately, 87% of organizations worldwide say they've encountered an AI-driven cyber attack in the past year, per SoSafe's 2025 Cybercrime Trends research. Most phishing emails targeting these companies are now AI-generated, making them harder for employees to spot and much faster for attackers to produce.
The threat isn't limited to phishing. State-backed threat actors and cybercriminals are increasingly using advanced AI models to carry out more sophisticated attacks. Trend Micro's H1 2026 APT report found that AI has moved beyond isolated experimentation into active attack cycles for state-affiliated groups. This includes autonomous reconnaissance and lateral movement within target networks. What this means is automated vulnerability scanning and faster attack chains that adapt in real time rather than following fixed scripts.
AI dramatically lowers the barrier to entry for attackers, meaning tasks that once required specialized expertise can increasingly be carried out through prompt engineering alone. Static, point-in-time risk assessments can't keep pace with threats that adapt this quickly.
Given the EU AI Act's governance requirements, DACH enterprises are now facing AI risk from two directions at once. AI as an attack vector, and AI as a regulated system that must be governed.
On the other hand, AI also equips today's IT and cyber risk professionals with tools to counter this shift, including continuous control monitoring, threat scanning, and automatic evidence collection, creating a connected system of decisions and actions to protect the enterprise.
5. The regulatory picture is becoming increasingly complex
DACH enterprises are now navigating overlapping EU and national obligations at the same time:
Regulatory challenges are perhaps one of the most important and complex aspects of cyber GRC and resilience. Managing multiple frameworks, regulations, deadlines, and exposures using traditional manual approaches can be challenging, especially when board attestations are required.
MetricStream's Cyber GRC is an interconnected, intuitive, and intelligent GRC product set. It helps organizations operating across Germany, Austria, and Switzerland connect cyber risk data from across the enterprise and a fragmented set of regulations into a single source of truth for board-level decision-making.
MetricStream Cyber GRC helps DACH enterprises manage regulatory complexity and cyber risk by:
Want to learn more about how MetricStream Cyber GRC can help your organization build cyber resilience across DACH's risk and regulatory environment? Reach out or request a customized demo to see how our platform works.
Subscribe for Latest Updates
Subscribe Now