Cyber security is becoming a management responsibility
Cyber security has long since ceased to be purely an IT issue. With NIS-2, DORA and other regulatory requirements, the demands on governance, risk management and compliance are increasing. Security issues are therefore increasingly becoming the responsibility of senior management, heads of public authorities and supervisory bodies.
At the same time, organisations today expect security strategies that integrate technical, organisational and regulatory requirements and strengthen digital resilience in the long term.
AI is changing the threat landscape
One of the most significant trends is the increasing use of artificial intelligence. According to ISG, AI-enabled attacks are among the greatest cyber security challenges of the coming years. Attackers are using AI to automate phishing campaigns, create deepfakes or identify vulnerabilities more quickly.
The Federal Criminal Police Office (BKA) has also observed that AI lowers the technical barriers to entry for cybercrime and makes attacks more efficient and harder to detect. At the same time, security managers are relying on AI-based analytics and automation to detect threats more quickly and respond to them.
Skills shortages and rising attacks are driving demand for security services
Whilst the threat landscape is growing, many organisations lack the necessary specialist staff. Small and medium-sized enterprises and public sector organisations, in particular, face the challenge of meeting increasing security requirements with limited resources.
Consequently, demand is rising for Security Operations Centres (SOCs), Managed Detection & Response (MDR) and other managed security services. ISG is once again forecasting growth of over 15 per cent in this sector for the German market.
Greater focus on public authorities and critical infrastructure
The growing threat is by no means confined to the private sector. The BKA reports attacks on local authorities, municipal utilities and other organisations providing essential public services. At the same time, federal authorities and public administrations are among the most frequently targeted victims of hacktivist DDoS attacks.
Geopolitical tensions are also having an increasing impact on cyberspace. The number of hacktivist attack announcements and reports targeting German entities rose significantly in 2025.
Digital sovereignty is gaining in importance
Alongside security, the issue of control and data sovereignty is coming more to the fore. Companies and public authorities are paying increasing attention to where data is processed and the legal framework governing security services. As a result, solutions and operating models from Germany or the EU are becoming increasingly important.
The quantum age is already casting its shadow
Just a few years ago, quantum computing was regarded as a topic of the future. Today, the first organisations are already addressing the risks of so-called ‘Harvest Now, Decrypt Later’ attacks, in which encrypted data is collected so that it can be decrypted later using powerful quantum computers.
Consequently, there is a growing need for strategies and consultancy services relating to post-quantum cryptography and long-term data security.
What does this mean for organisations?
The study’s findings show that cyber security today extends far beyond the protection of individual systems. What is needed are holistic approaches that bring together technology, processes, compliance and digital sovereignty. For businesses, public authorities and operators of critical infrastructure in particular, cyber resilience is becoming an ongoing management task.
It is precisely at this interface that consultancy and security service providers such as Materna support organisations in further developing their security strategies, implementing regulatory requirements and sustainably strengthening their resilience against new threats. The latest ISG study also demonstrates that this demand for consultancy is continuing to grow: in 2026, Materna is listed for the first time as a leader in the Strategic Security Services quadrant, making it one of the leading providers of cyber security consultancy in Germany.
Conclusion
ISG and the Federal Criminal Police Office paint a similar picture: the threat level remains high and is being further exacerbated by AI, geopolitical conflicts and professional criminal networks. At the same time, the demands regarding compliance, digital sovereignty and cyber resilience are increasing. For businesses, public authorities and public administrations, cyber security is therefore increasingly becoming a strategic cross-cutting task that encompasses technology, organisation and governance in equal measure.
Further information
ISG Provider Lens 2026: Materna named a leader in Strategic Security Services
Cyber Resilience Management