A Mittelstand Security Lead Budgets for an Old Threat

A security lead at a mid-sized German machine-tool maker sits down in September to build next year's cyber budget. He puts a small line item under 'nation-state risk' because that's what the line item said the last three years running: a rare, remote threat, worth a modest insurance-style allowance and not much else. On August 26, 2026, Bitkom, Germany's digital industry association, and the BfV, the country's domestic intelligence agency, published a study that makes that budget line look badly out of date.

The study, called Wirtschaftsschutz 2026, surveyed German companies about data theft, industrial espionage, and sabotage over the preceding 12 months. Among companies that reported being hit by at least one such attack, 37% could trace at least one incident to a foreign intelligence service. A year earlier, the same question produced 28%. In 2023, it produced 7%. The security lead's mental model of espionage as a tail risk has not been updated to match the data his own trade association just published.

The Numbers, Three Years Apart

Bitkom and the BfV presented the figures at a joint briefing in Berlin. Overall, 96% of the companies surveyed said they had been hit by some kind of attack or attempted attack in the past 12 months, ranging from data theft to sabotage to industrial espionage. Total damage to the German economy from these attacks is estimated at between EUR 211 billion and EUR 270.8 billion, with roughly three-quarters of that figure attributed to cyberattacks specifically.

The trend inside that headline number is what makes this a decision problem rather than just a bad-news statistic. Attribution to a foreign intelligence service, among companies that were hit at all, has moved with every edition of the study:

Study yearShare of hit companies attributing an attack to a foreign intelligence service
20237%
2025 (one year earlier)28%
2026 (Wirtschaftsschutz 2026)37%

That is roughly a fivefold increase in three years, and the single-year jump from 28% to 37% is itself larger than the entire 2023 baseline.

The Trap: Budgeting Against an Old Base Rate

The base-rate mismatch described above is the same decision-making trap that shows up whenever a company sizes risk once and then stops updating it. A base rate is not a fact you learn and file away; it is a number that moves, and a risk model built on a three-year-old base rate will misallocate every euro that follows it. Treating nation-state espionage as an exotic, low-probability event was a defensible read of the evidence in 2023, when 7% of hit companies traced an attack to a foreign intelligence service. It is not a defensible read of the evidence in 2026, when that figure is 37%.

The comparison worth making internally is the same one used for vendor risk: a company would not keep buying from a supplier whose defect rate had quintupled in three years just because the original contract assumed a low defect rate. A security budget built on a stale base rate is the same error, applied to a bigger number.

Where AI Fits Into the Rising Numbers

Bitkom and the BfV named artificial intelligence as one driver behind both the volume and the sophistication of the attacks logged in the study. AI tools lower the cost of researching a target, drafting a convincing phishing approach in fluent German, or automating reconnaissance that used to take a human analyst days. None of that changes what a company should do differently, but it does explain part of why the curve from 7% to 37% has bent upward so quickly.

For a security lead building next year's budget, the practical read is that the tools available to an attacker are improving faster than most internal risk models are being revised. A budget line written in 2023 assumed a 2023 attacker.

What to Change Before the Next Budget Cycle

The Bitkom and BfV figures are specific to Germany, and the study should be read that way: it says nothing directly about attribution rates in France, the Netherlands, or the United Kingdom. But the decision problem it illustrates is not German-specific. Any EU or UK owner-operator who last sized nation-state risk against a pre-2023 assumption is working from a base rate that Germany's own data suggests is out of date.

The concrete fix is not a bigger budget on faith; it is a scheduled recalibration. Pull the current threat-attribution figures for your own sector and country once a year, compare them to the assumption baked into your last budget cycle, and adjust the allocation between generic cyber hygiene and targeted counter-espionage measures accordingly. A company that has not re-run that comparison since 2023 is, by definition, planning against a threat level that Germany's own intelligence agency says no longer holds.

Servola Journal

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.