DataCybersecurityArtificial IntelligenceEnterprise Risk

BSI Study: Only One in Ten German Companies Prepared for AI-Powered Attacks

A joint investigation by the BSI and TÜV Association reveals a troubling picture: while one in six companies has already experienced AI-driven cyberattacks, most have failed to establish protective measures.

Only 10% of companies prepared for AI attacks, yet 17% already affected

BSI Study: Only One in Ten German Companies Prepared for AI-Powered Attacks

German companies are drastically underprepared in the fight against AI-powered cyberattacks. That's the central finding of a new study by the Federal Office for Information Security (BSI) and the TÜV Association, which surveyed more than 500 companies with at least 20 employees. The verdict is alarming: only 10 percent of businesses have established protective measures and processes against such attacks – while simultaneously 17 percent have already reported confirmed incidents, suspected cases, or both.

Key Facts

  • 17 percent of companies reported AI-powered cyberattacks or fraud attempts in the past 12 months (4 percent confirmed, 11 percent suspected)
  • 90 percent of affected companies cite convincing phishing emails as the most common attack vector
  • Only 31 percent of AI-using companies deploy AI to improve their own IT security
  • 11 percent have specialized processes for handling AI-related security incidents

Attack Methods: From Phishing to Deepfakes

The range of AI-powered attacks is impressive – and frightening. Phishing emails dominate at 90 percent: AI enables attackers to craft highly convincing messages tailored to specific individuals or companies. 40 percent of affected firms report automated attack scripts that independently search for IT security vulnerabilities and adapt dynamically. An especially insidious variant involves deepfakes: 11 percent of companies encountered fabricated audio or video recordings – for example, mimicking executive voices to trick employees into making transfers (so-called CEO fraud).

Protective Measures: Major Gaps Among AI Users

The situation is particularly troubling among companies already using or planning to use AI: 49 percent already deploy AI, with another 9 percent planning to do so within the next twelve months. Yet their defensive readiness falls short.

Measure Share
Specialized processes for AI security incidents 11 %
General IT processes (without AI-specific additions) 43 %
Currently under development 20 %
No regulations in place 25 %

To protect their own AI operations, companies employ various measures: 56 percent offer training, while 45 percent each conduct risk assessments or have established approval processes. However, 29 percent have implemented none of these measures.

Why AI Adoption Stalls: Security Concerns as a Brake

Fear of AI-powered attacks is a genuine obstacle: 42 percent of companies currently don't use AI and have no plans to do so. More than half of them (53 percent) cite data protection or security concerns as the reason – only lack of perceived benefit ranks higher (58 percent). Other barriers include high integration effort (44 percent), legal uncertainty (43 percent), lack of expertise (39 percent), and expected high costs (36 percent).

What This Means for You

The study paints a picture of widespread unpreparedness: German companies are falling significantly behind in securing AI-related risks. If you want to use AI or already do, don't wait for an attack to happen – specialized processes, training, and risk assessments are not a luxury but a necessity. At the same time, the data shows that security concerns are a legitimate reason to pause AI projects. The question isn't whether AI-powered attacks will come, but when – and whether you'll be ready.

Sources

Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.

Share
← All articles

All analyses are based on i6eal's own measurements or on clearly labelled sources. Figures are snapshots and may change; corrections are disclosed transparently.