Skip to main content

The cyberattack on Berlin would have gone differently.
Interview on the Berlin cyberattack with Sebastian Struwe

The cyberattack on Berlin's state network shows how vulnerable public infrastructure is. Classic protection alone would not have stopped it. It's about intrusion detection, deception technology, and digital sovereignty.

The Berlin cyberattack: what happened and what it teaches us

The recent cyberattacks in Berlin are yet another example of how vulnerable public and private organizations can be. Could Cybersense's intrusion detection have stopped the attack in its tracks?

The core contribution of our intrusion detection is to identify attackers early, as soon as they move within the network, reconnoiter systems, or attempt to escalate their access rights. Based on the publicly known course of the Berlin attack, our system would have made visible activity indicating spread within the infrastructure. That would have given security teams the chance to intervene earlier, contain the attack, and above all prevent a possible data leak. In that sense, early detection is genuinely an effective form of damage prevention. And the short answer to your question: yes. Berlin would most likely have turned out differently with us.

Are German companies and public institutions today sufficiently protected against cyberattacks?

Existing protection often isn't enough, because attackers keep evolving. New vulnerabilities emerge, attack methods become more professional, and criminal groups increasingly divide labor among themselves.

That doesn't mean established protective measures like firewalls, endpoint protection, or access controls are completely ineffective. They remain essential. What matters is not treating them as a complete security strategy. Organizations additionally need visibility within their network, the ability to recognize what happens after an attacker has already overcome an initial layer of protection. This is where deception technology complements existing security architecture: it creates targeted decoy assets and monitored areas within the network. As soon as an attacker examines or uses them, a highly relevant warning signal is triggered.

Sebastian Struwe, Geschäftsfrüher Cybersense GmbH
Sebastian Struwe, Mitgründer Cybersense GmbH

Late detection and the right response

Why are attacks often only detected once damage has already occurred?

Security doesn't always fail because of missing technology. What's often missing are the resources for continuously analyzing alerts and unusual activity, that applies to staff, time, expertise, and budget alike. In hindsight, it's usually easy to reconstruct how an attack unfolded. The real question is therefore: why wasn't this behavior recognized as an attack in the moment? In practice, security teams are often confronted with a high volume of alerts. Without clear, reliable signals, critical indicators get lost or are prioritized too late.

How should those responsible in Berlin, and other decision-makers across Germany, act now?

For us, Assume Breach applies. We assume that the attacker is already inside the network. Organizations should bring in a competent partner with experience in intrusion detection, incident response, and forensic analysis. We have already worked with organizations in the federal political environment and successfully stopped an attack at an early stage there. What matters is not just cleaning up the specific incident, it's important to close the root causes and blind spots in the security concept. For executives and IT leaders, this comes down to one central question: can we detect attacks before they endanger business-critical systems, sensitive customer or citizen data, and our own reputation?

More on digital sovereignty

The cyberattack on Berlin shows how closely intrusion detection and digital sovereignty are connected. In his interview, Michael Pütz explains which dependencies companies should be aware of, and how much control they really have.

Read the interview with Michael Pütz

Cybersecurity as a leadership issue

Why do decision-makers still not treat cybersecurity as a top business priority?

When security measures work well, they become invisible. That's their success, but also their problem. Money gets invested without it being immediately visible what damage that investment prevented. Manufacturing companies in particular still tend to see IT security as a necessary cost factor. But that thinking is changing. Machinery, supply chains, planning, communication, and administration today all depend deeply on IT systems. If IT fails, operations often can no longer function reliably either. Cybersecurity is therefore a component of operational capability, value creation, and corporate governance.

How high is the economic damage caused by cyberattacks?

Estimates from Germany's Federal Criminal Police Office (BKA) and Bitkom put the figure for Germany in 2025 in the high three-digit billion euro range. It's reasonable to assume this burden will keep rising. Even more costly than business interruption, recovery, forensics, or legal counsel is the intangible damage from reputational loss, and that can't be offset with money in the short term.

Strengthening defense, building sovereignty

Does Germany need more capabilities for digital counterattacks?

The focus should above all be on effective defense. A mutual digital arms race doesn't automatically create more security. For companies, public administrations, and critical infrastructure, the priority is clear: detect attacks early, protect systems, limit impact, and quickly regain the ability to act. A strong, multi-layered defense is more sustainable than hoping to deter attackers through a digital counterattack.

In your view, is digital sovereignty sufficiently prioritized in Germany and Europe?

Germany and Europe need to build and strengthen their own capabilities in cyber defense. The major international providers, particularly from the US and Israel, have deep expertise. At the same time, Germany also has capable companies and skilled professionals, we are one example of that.

Digital sovereignty requires real investment, qualified talent, research, resilient security structures, and contracts awarded to European or national providers.

The most important lesson for decision-makers

What's your most important message to executives and IT leaders?

Don't rely on an attack stopping at the outer wall. Plan for the fact that attackers can overcome individual protective mechanisms, and make sure they become visible within the network once they do. Cyber defense today must consist of prevention, detection, response, and recovery. Anyone who brings these four areas together protects not just systems and data, but their own ability to act and the trust of customers, partners, and employees, and with it, their future.

Michael Pütz, Ansprechpartner Cybersense GmbH

Do you have any questions? Would you like a demo?
We look forward to hearing from you.

Your contact partner
Michael Pütz

Contact us now