Any Questions?

Feel free to reach out if you would like to find out how Athereon GRC can support you with current governance, risk and compliance issues.

21.8.2026
7 minutes

Cybersecurity: Identify Risks and Protect Your Business with Athereon GRC

Germany is among the most frequently attacked countries in the digital space worldwide. The threat landscape remains tense, and attack surfaces are expanding faster than many organizations can secure them. For executives, CISOs, and IT managers, cybersecurity is therefore no longer a purely technical issue, but a strategic and increasingly legal responsibility. This article classifies current risks, highlights effective measures, and explains how you can systematically manage cyber security with Athereon GRC.

What is Cybersecurity?

Cybersecurity encompasses all technical and organizational measures that protect IT systems, networks, applications, and data from digital attacks. The goal is to safeguard the confidentiality, integrity, and availability of information—whether this data is stored, processed, or transmitted.

The broader term cyber protection complements traditional defense with data backup, recovery, and emergency management. An important distinction from pure IT security: Cyber security considers not only technology, but also processes, responsibilities, and employee behavior. An organization only becomes truly resilient when these layers work together. This distinction has practical consequences, as it determines which responsibilities, budgets, and documentation obligations you need to plan for.

The threat landscape: why cybersecurity will be critical in 2026

Risks can only be managed if they are known. The situation report from the German Federal Office for Information Security (BSI) for the period from July 2024 to June 2025 cites concrete figures: an average of 119 new vulnerabilities per day, an increase of roughly 24% compared to the previous year. On top of that, approximately 280,000 new malware variants emerge every day.

Ransomware remains the most consequential threat. During the reporting period, the German Federal Criminal Police Office recorded around 950 reported attacks, about 80% of which targeted small and medium-sized companies. Attackers deliberately choose the least protected targets, not the largest ones. Small and medium-sized companies are hit particularly hard because they often lack the staff and budget for continuous protective measures. In many cases, attackers now combine encryption with data leaks: Even functioning backups offer no protection against the threat of sensitive information being published. At the same time, the trade in stolen credentials is growing, as these can be readily resold on the darknet.

Attack vectors are also shifting. Email-based attacks are noticeably declining, while the exploitation of vulnerabilities in web-based systems is on the rise. Many incidents can be traced back to professionally organized groups operating under the ransomware-as-a-service model, combining encryption with data theft (double extortion). In addition, state-sponsored actors are targeting the IT infrastructures of companies, municipalities, and public administrations to cause disruption and spread disinformation. A single protective measure is not enough to counter this range of threats.

The economic damage is substantial. The German digital association Bitkom estimates the annual total damage from data theft, espionage, and sabotage at €289.2 billion, of which around €202.4 billion are directly attributable to cyberattacks. The BSI identifies inadequately protected attack surfaces as the core problem. Misconfigurations, delayed updates, and publicly accessible systems often provide attackers with the easiest point of entry. Consistently managing these factors is therefore the most important lever for improving security.

Cybersecurity as a regulatory obligation

Cybersecurity is no longer optional. Several sets of regulations require companies to implement specific protective measures, and the requirements often apply simultaneously.

With the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), Germany has transposed the European NIS2 directive into national law. The law was published in the Federal Law Gazette of Germany on December 5, 2025, and entered into force on December 6, 2025, without any transition period. Since then, approximately 29,500 companies fall within its scope and are classified as "essential" or "important entities." Eighteen sectors are covered, ranging from energy, water, and health to transport and logistics, as well as parts of the manufacturing industry and digital services; the decisive factors are sector affiliation and size, typically starting at 50 employees or €10 million in revenue. They must implement risk management measures, report significant security incidents to the BSI, and register via the reporting and notification channel portal. Violations may result in fines of up to €10 million or 2% of global annual turnover, and executive management is held personally liable. The initial registration deadline via the BSI portal, which went live in January 2026, already expired on March 6, 2026, but subsequent registration remains possible and advisable. Since March 17, 2026, the KRITIS Umbrella Act has also imposed additional requirements on the physical resilience of critical facilities. A practical note: The areas of measures required under Section 30 of the BSIG largely correspond to the structure of an ISMS. An established management system based on ISO/IEC 27001 is therefore the fastest way to achieve compliance.

The Cyber Resilience Act (Regulation (EU) 2024/2847) targets the product itself. It obligates manufacturers, importers, and distributors of products with digital elements to implement security by design, vulnerability management, and security updates throughout the entire lifecycle. As of September 11, 2026, reporting obligations apply for actively exploited vulnerabilities and serious incidents, and as of December 11, 2027, the full requirements, including CE marking, take effect. Unlike NIS2, the CRA applies directly as a regulation in all member states, eliminating the need for national implementation. You will find a detailed assessment in our article on the [Cyber Resilience Act] (https://www.athereon.de/en/framework/cra).

Added to this is the General Data Protection Regulation (GDPR), which requires appropriate technical and organizational measures for personal data. If these requirements are handled in separate, isolated projects, it is easy to lose track. An approach that consolidates the requirements works more efficiently and provides greater legal certainty at the same time.

Cybersecurity Measures: How to Successfully Protect Against Cyberattacks

Effective protection against cyberattacks results from the interplay of technical and organizational measures. Individual tools are not sufficient; what matters is a coordinated approach that is continuously reviewed and adjusted. Since not every risk can be handled in the same way, risk-based prioritization helps: What would cause the greatest damage in the event of an incident is secured first.

Technical cybersecurity measures

On the technical level, several building blocks bear the main load. Multi-factor authentication makes it harder to misuse stolen credentials. Consistent patch and vulnerability management closes known gaps before attackers can exploit them. Regular backups kept offline and tested ensure recovery after an incident. Network segmentation limits the spread of malware, while encryption protects data during storage and transmission. Systematic attack surface management reduces the publicly accessible and therefore vulnerable surface, which is the central weakness identified by the BSI. Continuous monitoring and the timely detection of suspicious activity increase the chance of stopping attacks before major damage occurs.

Organizational cybersecurity measures

Technology alone is not enough. Equally important are clear responsibilities, well-regulated access and authorization management, and tested emergency and recovery plans. Because many attacks target people, regular awareness training is one of the most effective investments. The supply chain is also coming into sharper focus: The security level of service providers and partners must be assessed and contractually secured.

Added to this is the ability to respond to incidents in a structured manner. Companies subject to NIS2 or the Cyber Resilience Act must report significant incidents within tight deadlines; the CRA, for example, requires an early warning within 24 hours and a follow-up report within 72 hours. These deadlines can only be met if reporting channels, responsibilities, and escalation levels are defined and practiced in advance. A documented incident response process therefore belongs in every robust cybersecurity strategy.

These building blocks are held together by an information security management system (ISMS), for example in accordance with ISO/IEC 27001. It anchors cybersecurity as an ongoing process: Assess risks, derive measures, verify effectiveness, and make adjustments. This is where a GRC platform comes in, consolidating these steps and documenting them transparently.

From individual measures to a system: cybersecurity with Athereon GRC

Cybersecurity, risk management, and compliance can be managed most effectively when they converge in a single environment. That is precisely what Athereon GRC, as Europe's leading GRC platform, is designed for. It combines the ISMS, ERM, BCM, DPM, and SRM modules, thereby covering information security, enterprise-wide risk management, business continuity, data protection, and supplier risks on a single foundation. For cybersecurity, the modules interlock: The ISMS manages protective measures and evidence, BCM ensures the ability to act following an attack, SRM assesses risks along the supply chain, and DPM links data protection requirements. Instead of numerous isolated solutions, a coherent overall picture emerges.

The platform is framework-agnostic: Whether ISO/IEC 27001, BSI IT-Grundschutz, NIS2, or TISAX®, you work with the standards relevant to your company without introducing a new tool for each set of rules. As a solution that is 100% made in Germany, Athereon GRC meets European companies' expectations regarding data sovereignty and traceability.

Support is provided by the AI agent LAiKA. It is built on a shared foundation as its data base, LAiKA Assist helps with everyday tasks, and specialized agents handle targeted assignments, including the Infrastructure Mapper, the Compliance Assistant, and the Questionnaire Assistant. Throughout, the principle "Nothing without your OK" applies: LAiKA prepares and proposes; you make the decision.

Conclusion: Compliance as an Opportunity

The threat landscape is not getting any easier, and the regulatory framework continues to tighten. When cybersecurity is understood as a structured task rather than a collection of individual measures, it becomes a competitive advantage. A systematically managed security and compliance software protects against attacks and fines while also building trust with customers and partners, embodying the idea of compliance as an opportunity.

With Athereon GRC, you manage risks, measures, and evidence in one place and maintain an overview of your cyber security. Instead of merely reacting to incidents, you act proactively.

Would you like to learn more?

Book a noncommittal demo appointment with our team to analyze your individual use case with us.