09/30/2026 | Press release | Archived content
Companies are making progress in dealing with cyber incidents but remain under considerable pressure to adapt. This is shown by the 2026 IT Security Survey conducted by eco - Association of the Internet Industry, which is being published to coincide with European Cybersecurity Month. Just under a third of the 100 IT decision-makers surveyed report security-related incidents with tangible impacts over the past twelve months. For 42%, relevant cybersecurity incidents have increased significantly or somewhat compared with the previous year. From the respondents' perspective, the greatest threat continues to come from cybercriminals.
"The survey makes it clear that many companies have become more professional in their handling of cyber incidents. At the same time, traditional prevention alone is no longer sufficient. Cyber resilience means detecting attacks early, limiting their impact and quickly restoring business operations in the event of a crisis," says Norbert Pohlmann, Board Member for IT Security at eco.
New attack patterns and higher volumes increase the pressure
According to the survey, companies must not only adapt to new attack methods. Familiar patterns are also occurring more frequently or on a larger scale. 28% of respondents report novel attack patterns, while 29% report identical attack patterns occurring at a higher volume. Cyber resilience must therefore achieve both: detecting new threats and ensuring that existing protective mechanisms remain stable even under increased strain.
At the same time, progress is being made. Almost half of respondents see significant improvements in the handling of security-related incidents compared with one to two years ago. Respondents cite staff training and awareness-raising, technical modernisation of security infrastructure, Security Operations Centres, clear responsibilities and incident response plans as particularly effective measures.
Regulation makes cybersecurity an organisational responsibility
NIS2, the KRITIS umbrella law and other IT security requirements are increasing the pressure on companies to embed cybersecurity more firmly within their organisations. Respondents regard documentation requirements, audits, reporting processes and risk management as particularly challenging. Implementation remains particularly demanding for SMEs: just under half of respondents believe that NIS2 implementation among SMEs is only feasible with external support.
"SMEs in particular often have neither the budget nor the human resources to keep pace with growing regulatory and technical requirements," says Pohlmann.
In an emergency, recovery capability is crucial
Just under a third of the companies surveyed report security-related incidents with tangible impacts over the past twelve months. These include business interruptions, production stoppages, data breaches, manipulation of processes or products and extortion attempts.
What matters, therefore, is how long companies can tolerate the downtime of business-critical systems and whether they have suitable contingency and recovery plans in place. Cyber insurance can provide additional protection against financial risks, but it is no substitute for preventive measures, contingency planning or robust recovery capabilities.
Government support remains important
From the respondents' perspective, government bodies also have a role to play. Companies expect the German Federal Office for Information Security (BSI), above all, to provide guidance, practical standards, centralised threat intelligence and reliable information-sharing formats. Many companies believe that a purely supervisory or punitive role is insufficient to address the practical need for support.
"The figures show that companies are taking their responsibilities seriously and becoming better equipped to take action. However, to ensure that this progress also reaches SMEs, closer cooperation between government and industry is needed - with practical standards and concrete guidance rather than additional complexity," says Pohlmann.
About the study
The 2026 IT Security Survey was conducted by the Security Competence Group of eco - Association of the Internet Industry. Data was collected from September to December 2025. A total of 100 IT security experts were surveyed through online formats and at live events.