When it came to concerns about specific kinds of security breaches, German responses showed a more equal weight placed across the different kinds of categories than global responses and US firms. The survey asked respondents to pick their top two concerns, and whereas 72% of US respondents named data breaches in those top picks, just 37% of German companies reported the same. We speculate that this is likely due to the investment that German companies have had to make around privacy controls in the wake of GDPR.
For German firms, the number one incident they are worried about is ransomware, which was named by 39% of respondents. Number two was breaches, followed by Distributed Denial-of-Service (DDoS) (32%) and supply chain attacks (28%).
A look at German cyber risk maturity
German respondents were more self-critical about the maturity level of their cyber risk management practices than US companies, but they led global responses. Some 71% of German respondents reported that they’re at least moderately mature, which was a few points above the global benchmark of 67%. However, only 17% report themselves very mature. This trails behind the US levels of very mature firms, which stood at 28%. The good news is that a scant 1% of German firms admit that they’re very immature and only 11% said they’re moderately immature. This is far better than the global rate of immaturity, which stands at 20%.
Nevertheless, there’s still a lot of work to be done for many firms in Germany to institute a programmatic approach to risk management that’s well-aligned to the business. Only 81% of companies have a formal cyber risk management program in place, lagging behind the US rate of 92% and the UK rate of 87%. What’s more, just 26% of German firms say that they have a program that is well-aligned with the business. This also lags behind US and UK firms:
| Does your organization have a formal cyber risk management program that monitors, prioritizes, and manages cyber risk in the context of business risk? |
| |
Germany |
US |
UK |
| Yes, we have a formal program, but we’re still working on managing cyber risk in the context of business priorities |
55% |
58% |
54% |
| Yes, and it is well-aligned with the business |
26% |
34% |
32% |
Visibility benchmarks
That lack of visibility that German firms were concerned about is likely interconnected with this lack of having a formal program. Formal programs are fed by continuous monitoring, and they also drive it. The survey showed that German firms are still figuring out how to implement and get the most out of continuous monitoring of assets and third-party relationships. The study showed that only 40% of German organizations continuously monitor their assets, and just 17% continuously monitor and are also able to regularly map threats across their environment and contextualize that data with risk factors to help them prioritize exposure management. That’s in contrast to 54% of US firms that continuously monitor and 22% that also contextualize that monitoring data.
Drilling specifically into exposure management tooling and practices, a solid 81% of German firms say they have an exposure management program in place and have started to deploy attack surface management tools to run it. However, only 29% of German firms believe that they have mature processes in place to run their exposure management programs.
German firms aren’t just struggling to implement and use continuous monitoring on their own internal assets. They’re also lagging behind global firms when it comes to third-party risk management and monitoring. Fewer than a third of German companies (26%) report that they continuously monitor all of their third-party relationships for cyber risk. That lags behind counterparts globally and specifically in UK and US firms:
| We continuously monitor all of our third-party relationships for cyber risk |
| Germany |
Global |
UK |
US |
| 26% |
33% |
43% |
38% |
The lack of visibility hurts companies in a lot of different ways, and also takes a toll on the mental health of cybersecurity staffers. The global results showed that companies that use asset monitoring to discover and prioritize exposure mitigation are 30% less likely to have staff suffering from burnout. According to our study some 49% of German firms report their staff is experiencing some level of burnout.
Continuous monitoring is a top spending priority
The good news is that German companies have deemed continuous monitoring as a top spending priority for the next year. Almost a third of firms voted this the number one spending initiative, ahead of IAM, vulnerability management, endpoint management, and security training:
| Which security and risk initiatives do you consider most urgent for the next year (2025)? Select top three |
Germany |
Total |
| Continuous monitoring |
31% |
31% |
| Identity and access management |
29% |
29% |
| Vulnerability management |
27% |
29% |
| Endpoint management / endpoint detection and response |
26% |
25% |
| Security training |
26% |
22% |
| Software supply chain security |
25% |
24% |
The 2025 State of Cyber Risk and Exposure report shows that German organizations and their peers still have significant work to do if they want to both identify and understand the business risk around cyber exposures that threaten their digital ecosystems. Simply identifying exposures isn’t enough: security teams and business stakeholders alike need to contextualize risk data with business priorities and actionable threat intelligence to drive meaningful mitigation efforts. To dive more fully into these trends and read our analysis of what the survey means for enterprises, check out the full State of Cyber Risk Intelligence 2025 report here.