Compliant on paper, exposed in practice?
21st January 2027 • Crowne Plaza Congress Hotel, Frankfurt
Germany's industrial core is engineered for efficiency and regulated harder than ever. But is it secure, or just rarely breached? And does Al change the answer?
Regulated, integrated — and exposed?
Germany's strengths are also its fault lines: deep integration between IT and OT, long supplier chains, an engineering culture that prizes stability over change, and a skills shortage that leaves security teams thin.
These teams are not only wrestling with security. They have a compliance problem too. The regulatory picture has changed more in twelve months than in the previous decade.
The NIS2 Implementation Act took effect in December 2025 with no transition period, taking the organisations supervised by the BSI from around 4,500 to almost 30,000 and making management personally accountable.
DORA governs finance and The EU Cyber Resilience Act's main obligations apply from 11 December 2027, making product security, vulnerability handling and supplier assurance immediate considerations for technology investment and procurement.
Yet when the registration window closed in March, only about four in ten in-scope organisations had registered and the B51 had to set a second deadline. The long tail of the Mittelstand — the family-owned exporters that hold much of Germany's most valuable intellectual property — was not ready.
Meanwhile the threat has become explicitly geopolitical. German industry, infrastructure and public bodies sit at the intersection of state-directed espionage and sabotage, criminal ransomware and hacktivism, at a moment when Europe is rearming and rail, energy, ports and defence supply chains are strategic targets.
This is the tipping point: cyber risk is moving from whether individual companies can prevent attacks to whether Europe's industrial core can sustain trust and operations under permanent pressure.
Al sharpens that challenge. Defenders must modernise detection, response and prioritisation just to keep pace - while securing their own use of Al agents.
Regulation adds urgency, but compliance is not resilience. NIS2 and DORA are a floor, not a strategy, and digital sovereignty - who runs the cloud, where the data sits, which suppliers can be trusted - is now a board-level security question rather than a procurement preference.
German firms may be well positioned by European standards, yet the strategic question is no longer whether they are "more mature than peers". It is whether their operating models are fit for the next phase of cyber risk.
CISOs therefore face an external challenge (a state-grade threatscape) and an internal problem: how to argue for preventive resourcing in a cost-conscious economy before attackers prove how damaging a breach can be.
Cyber incidents ranked as Germany's leading business risk in the Allianz Risk Barometer 2026, reflecting the close connection between digital security, operational continuity and corporate reputation.
So, where do German cyber leaders see genuine resilience, where is compliance masking hidden exposure, and what should organisations do before the storm becomes visible? If Germany is Europe's industrial core, is it also becoming one of its most exposed?
The e-Crime & Cybersecurity Congress Germany will look at how at how security teams and the business must respond to a new era in cybersecurity. Join our real-life case studies and in-depth technical sessions from the most sophisticated teams in the market.
Key Themes: AI and Quantum
Identity, authority, and control for non-human actors
CISOs must rethink core identity and governance frameworks, including the adoption of robust agent identity models (spanning machine, service, and workload identities), and clearly defined delegation structures that determine what authority an agent holds and who grants it. What technologies can help them maintain visibility and control?
Data protection and leakage risks
What does "insider threat" mean when the actor is non-human? For CISOs, the focus shifts to monitoring the behaviour of agents as well as users, developing capabilities to detect anomalous machine activity, and establishing effective controls that balance guardrails, detection, and containment. Do you need Al defences to do that?
Al anti-phishing and social engineering defences
Al is shifting defence from static filtering to behavioural detection at scale, flagging anomalies that rules/ signatures miss. It can also enable pre-emptive defence against social engineering, identifying manipulation cues. The result is a move from reactive blocking to adaptive defence reducing both successful attacks and analyst workload. Can you help?
Who needs to be quantum-ready?
Anyone responsible for long-lived sensitive data or critical infrastructure has a quantum problem. That means banks, governments, telecoms, energy, healthcare whose datasets need to last decades. If your encryption protects value over time, you need crypto-agility and a migration path now, not when quantum arrives. How does this work in the real world?
Al social engineering: the language barrier is gone
Flawless German phishing, cloned executive voices and "fake president" fraud are now cheap and scalable. Defence is shifting from static filtering to behavioural detection at scale, spotting manipulation cues and anomalies that rules miss, and from awareness training to realtime intervention. Do you have solutions?
Intelligent Threat Detection
CISOs now must build a single coherent security program that simultaneously satisfies divergent regulatory demands; they must interpret vague legal standards into technical architectures, and they risk non-compliance if auditors, regulators, or courts interpret differently later; they face unrealistic expectations around incident reporting; and they face personal liability. Can RegTech help?
Key Themes: Building Better Security
NIS2 in practice: from registration to resilience
Almost 30,000 German organisations are now supervised by the BSI, with personal liability for management, 24-hour reporting and evidence obligations to come. Registration was the easy part. How do CISOs turn a compliance programme into measurable resilience - and prove it to auditors and the board?
Ransomware and the Mittelstand
Extortion groups target the hidden champions precisely because they are rich in intellectual property and thin in security staff. Firms must go back to basics but also invest in immutable backups, tested recovery and early-stage infiltration detection. What else can CISOs do to better defend against ransomware?
Improving continuous attack surface discovery
You need to know what attackers can see and what they can actually attack - and you need it on a continuous basis, not in some static inventory. Ideally you also need assets ranked by risk priority and put into the current threat and vulnerability context. Is this feasible and is it cost effective?
Automation, MOR and the skills gap
The Fachkraftemangel means most German security teams cannot scale headcount. SOAR, Al-assisted triage and managed detection promise to pull data across SIEMs, EDRs, cloud APls and ticketing systems and coordinate response through playbooks. Well, that's the theory. How does it work in the real world?
The Cyber Resilience Act: security by design for producers
Germany makes the machines, components and connected products the CRA regulates. Reporting duties are here; full obligations follow. Manufacturers need vulnerability handling across product lifetimes measured in decades. How do engineering-led companies get there?
Digital sovereignty: cloud, data, control
Who runs the cloud, where data sits and which suppliers can be trusted have become board-level security questions. This is especially true around Al. EU providers, hyperscaler enclaves and an on-premise revival all compete for the same workloads.
But what does sovereignty mean in practice, and what does it cost in security terms?
