[{"data":1,"prerenderedAt":30},["ShallowReactive",2],{"nr-en-bsi-studie-deutsche-unternehmen-ki-angriffe-unvorbereitet":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":22,"trackerLabel":23,"headlineStat":24,"image":25,"ogImage":26,"imageAlt":5,"csv":10,"minutes":27,"words":28,"html":29},"bsi-studie-deutsche-unternehmen-ki-angriffe-unvorbereitet","BSI Study: Only One in Ten German Companies Prepared for AI-Powered Attacks","A joint investigation by the BSI and TÜV Association reveals a troubling picture: while one in six companies has already experienced AI-driven cyberattacks, most have failed to establish protective measures.","2026-10-07","09:38","2026-10-07T09:38:00+02:00","","October 7, 2026","daten","standard","ideal-syka","Ideal Syka",[17,18,19,20,21],"Cybersecurity","Artificial Intelligence","Enterprise Risk","BSI","Phishing","\u002Feu-digitalrecht-ticker","Cybersecurity & AI Risks","Only 10% of companies prepared for AI attacks, yet 17% already affected","\u002Fnewsroom\u002Fimg\u002Fbsi-studie-deutsche-unternehmen-ki-angriffe-unvorbereitet.webp","\u002Fog-nr\u002Fbsi-studie-deutsche-unternehmen-ki-angriffe-unvorbereitet.en.png",3,544,"\u003Cp>German companies are drastically underprepared in the fight against AI-powered cyberattacks. That&#39;s the central finding of a new study by the \u003Cstrong>Federal Office for Information Security (BSI)\u003C\u002Fstrong> and the \u003Cstrong>TÜV Association\u003C\u002Fstrong>, which surveyed more than 500 companies with at least 20 employees. The verdict is alarming: only \u003Cstrong>10 percent\u003C\u002Fstrong> of businesses have established protective measures and processes against such attacks – while simultaneously \u003Cstrong>17 percent\u003C\u002Fstrong> have already reported confirmed incidents, suspected cases, or both.\u003C\u002Fp>\n\u003Ch2>Key Facts\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>17 percent\u003C\u002Fstrong> of companies reported AI-powered cyberattacks or fraud attempts in the past 12 months (\u003Cstrong>4 percent\u003C\u002Fstrong> confirmed, \u003Cstrong>11 percent\u003C\u002Fstrong> suspected)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>90 percent\u003C\u002Fstrong> of affected companies cite convincing phishing emails as the most common attack vector\u003C\u002Fli>\n\u003Cli>Only \u003Cstrong>31 percent\u003C\u002Fstrong> of AI-using companies deploy AI to improve their own IT security\u003C\u002Fli>\n\u003Cli>\u003Cstrong>11 percent\u003C\u002Fstrong> have specialized processes for handling AI-related security incidents\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Attack Methods: From Phishing to Deepfakes\u003C\u002Fh2>\n\u003Cp>The range of AI-powered attacks is impressive – and frightening. \u003Cstrong>Phishing emails\u003C\u002Fstrong> dominate at 90 percent: AI enables attackers to craft highly convincing messages tailored to specific individuals or companies. \u003Cstrong>40 percent\u003C\u002Fstrong> of affected firms report \u003Cstrong>automated attack scripts\u003C\u002Fstrong> that independently search for IT security vulnerabilities and adapt dynamically. An especially insidious variant involves \u003Cstrong>deepfakes\u003C\u002Fstrong>: \u003Cstrong>11 percent\u003C\u002Fstrong> of companies encountered fabricated audio or video recordings – for example, mimicking executive voices to trick employees into making transfers (so-called CEO fraud).\u003C\u002Fp>\n\u003Ch2>Protective Measures: Major Gaps Among AI Users\u003C\u002Fh2>\n\u003Cp>The situation is particularly troubling among companies already using or planning to use AI: \u003Cstrong>49 percent\u003C\u002Fstrong> already deploy AI, with another \u003Cstrong>9 percent\u003C\u002Fstrong> planning to do so within the next twelve months. Yet their defensive readiness falls short.\u003C\u002Fp>\n\u003Cdiv class=\"tbl-scroll\">\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Measure\u003C\u002Fth>\n\u003Cth>Share\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>Specialized processes for AI security incidents\u003C\u002Ftd>\n\u003Ctd>\u003Cstrong>11 %\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>General IT processes (without AI-specific additions)\u003C\u002Ftd>\n\u003Ctd>\u003Cstrong>43 %\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Currently under development\u003C\u002Ftd>\n\u003Ctd>\u003Cstrong>20 %\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>No regulations in place\u003C\u002Ftd>\n\u003Ctd>\u003Cstrong>25 %\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>To protect their own AI operations, companies employ various measures: \u003Cstrong>56 percent\u003C\u002Fstrong> offer training, while \u003Cstrong>45 percent\u003C\u002Fstrong> each conduct risk assessments or have established approval processes. However, \u003Cstrong>29 percent\u003C\u002Fstrong> have implemented none of these measures.\u003C\u002Fp>\n\u003Ch2>Why AI Adoption Stalls: Security Concerns as a Brake\u003C\u002Fh2>\n\u003Cp>Fear of AI-powered attacks is a genuine obstacle: \u003Cstrong>42 percent\u003C\u002Fstrong> of companies currently don&#39;t use AI and have no plans to do so. More than half of them (\u003Cstrong>53 percent\u003C\u002Fstrong>) cite \u003Cstrong>data protection or security concerns\u003C\u002Fstrong> as the reason – only lack of perceived benefit ranks higher (\u003Cstrong>58 percent\u003C\u002Fstrong>). Other barriers include high integration effort (\u003Cstrong>44 percent\u003C\u002Fstrong>), legal uncertainty (\u003Cstrong>43 percent\u003C\u002Fstrong>), lack of expertise (\u003Cstrong>39 percent\u003C\u002Fstrong>), and expected high costs (\u003Cstrong>36 percent\u003C\u002Fstrong>).\u003C\u002Fp>\n\u003Ch2>What This Means for You\u003C\u002Fh2>\n\u003Cp>The study paints a picture of widespread unpreparedness: German companies are falling significantly behind in securing AI-related risks. If you want to use AI or already do, don&#39;t wait for an attack to happen – specialized processes, training, and risk assessments are not a luxury but a necessity. At the same time, the data shows that security concerns are a legitimate reason to pause AI projects. The question isn&#39;t whether AI-powered attacks will come, but when – and whether you&#39;ll be ready.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.bsi.bund.de\u002FDE\u002FService-Navi\u002FPresse\u002FPressemitteilungen\u002FPresse2026\u002F261007_KI-Sicherheitsstudie_TUEV_BSI.html\">BSI\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1791361750051]