Attack threat in Germany: Why the state warns but withholds crucial information from citizens
Xpert Pre-Release
Available in 27 languages 📢
Prefer Xpert.Digital on GoogleⓘPublished on: August 25, 2026 / Updated on: August 25, 2026 – Author: Konrad Wolfenstein

Attack threat in Germany: Why the state warns but withholds crucial information from citizens – Creative image on the topic, created with AI: Xpert.Digital
Blackout & Sabotage: Experts sound the alarm – How unprepared is Germany for a worst-case scenario?
"Expect attacks at any time": What Interior Minister Dobrindt's new warning level means for you
Electricity, water, internet at risk: The major legal loophole that affects us all
The security situation in Germany has changed – abstract warnings have become a concrete threat. In August 2026, the Federal Ministry of the Interior officially classified the risk of attacks, sabotage, and hybrid attacks on critical infrastructure as "high." However, while the government is rigorously holding companies accountable with the new Critical Infrastructure Protection Act (KRITIS), the general public is largely left to its own devices when it comes to crisis preparedness. Experts from the Competence Center for Critical Infrastructures (KKI) are now sounding the alarm: those who warn people about attacks must also explain how they can prepare for emergencies – such as widespread power or water outages. Read here why absolute security is an illusion in our highly networked country, why important emergency information from the federal government is gathering dust, and why true societal resilience extends far beyond fences and government offices.
When the state warns but does not explain
Germany has changed its security assessment. In August 2026, Federal Interior Minister Alexander Dobrindt reclassified the threat level from abstract to high, citing increased reporting and intelligence gathering, which indicated that the risk of attacks in Germany must be expected at any time. According to him, these attack plans were explicitly directed not only against German infrastructure, but also against individuals and institutions. The minister also spoke of hybrid threats, sabotage, and espionage, and pointed to recurring drone overflights of critical infrastructure, for example in Denmark, as evidence of a worsening security reality. This reassessment is more than just a linguistic nuance. It marks a shift from a diffuse, barely tangible perception of threat to a concrete expectation that attacks are not merely conceivable, but probable. This is precisely the point of criticism raised by the Competence Center for Critical Infrastructures: A government that announces a high threat level cannot simply alarm the public without also providing them with actionable information.
The blind spot of German security architecture
The Competence Center for Critical Infrastructures (KKI) has derived a fundamental demand from the upgrade in the security risk classification, one that goes far beyond symbolic gestures. Anyone who tells people that attacks on infrastructure are possible at any time must also explain how they can prepare for them, says the association's chairman, Martin Debusmann. This is explicitly not about creating fear, but rather, on the contrary, about building security through knowledge. Because those who know what to do in an emergency react more calmly and simultaneously relieve the burden on authorities and emergency services. This argument touches on a sore point in the German security debate. For years, crisis preparedness in Germany has been understood primarily as a state and corporate responsibility, while individual preparation by the population remained a niche topic, associated more with prepper culture than with a serious security strategy. Other European countries, especially the Nordic countries, have communicated much more proactively in recent years and systematically prepared their populations for scenarios such as power outages, cyberattacks, or military threats. Germany is visibly lagging behind in this respect, even though the technical and legal prerequisites for such communication have long been in place.
Nets without fences: Why protection alone is not enough
A central argument of the Critical Infrastructure Crisis Management (KKI) concerns the physical nature of critical infrastructure itself. Despite significant security measures, electricity, water, telecommunications, and transportation networks cannot be completely protected because extensive networks often run across public and private land, making them considerably more difficult to secure than centralized operational sites. This structural vulnerability is not a new insight, but it has gained renewed urgency in light of the current threat landscape. A substation can be fenced in and monitored, but a high-voltage power grid hundreds of kilometers long or a fiber optic cable along a railway line cannot be secured with comparable effort. Precisely for this reason, neither the operators of critical infrastructure nor the police, fire department, or disaster relief services alone can guarantee that the consequences of a targeted attack on the population will be fully mitigated at all times. This economic and technical reality leads to an uncomfortable but crucial conclusion: Absolute security is an illusion in a highly networked industrialized nation, and resilience must therefore begin where prevention ends – namely, with the ability of society and individuals to cope with disruptions.
The forgotten five-point plan
As early as 2025, the KKI (German Crisis Management Institute) called for targeted and transparent public awareness campaigns in a five-point plan for crisis preparedness. Citizens need to know how to prepare for potential disruptions and how to behave appropriately in a crisis situation, emphasizing that personal preparedness is not a substitute for state protection, but rather a necessary component of a resilient society. This wording is deliberate, as it avoids the trap of pitting private preparedness against state responsibility. The public debate sometimes gives the impression that those who call for personal preparedness want to absolve the state of its responsibility. The KKI, however, positions personal preparedness as a complementary element that supplements state protective measures without replacing them. Debusmann succinctly summarizes this idea when he states that while Germany is right to invest in the protection of critical infrastructure and the capabilities of its security authorities, resilience does not end at the factory gate, nor with the police or disaster relief services. A resilient society needs resilient citizens, which includes understandable information, concrete recommendations for action, and crisis communication that takes people seriously.
A good brochure that nobody knows about
What is particularly noteworthy about the KKI's criticism is its reference to a specific communication failure. Last year, the Federal Office of Civil Protection and Disaster Relief updated and republished an information brochure whose content is relevant and clearly presented. However, the relaunch has received little publicity or promotion since then, even though the material is freely available on the Federal Office's website, both as a download and for order in print. This finding is symptomatic of a structural problem in German crisis communication. The issue is not a fundamental lack of content or expertise, but rather a lack of ability to effectively communicate this content to the public. A brochure available on a government website has no societal impact if no one is aware of its existence. From a communication economics perspective, this is a classic distribution problem: the product is available, but demand is not being generated because the necessary visibility is lacking. In a time when attention is the scarcest resource of all, it is not enough to provide relevant information; it must be actively and repeatedly brought to public attention, for example through mass media, social networks, schools or businesses.
Related to this:
What the federal and state governments now need to deliver
From this analysis, the KKI derives a clear political demand. The federal and state governments should use the increased threat level as an opportunity to prepare the population more systematically for potential crisis situations. Existing recommendations for personal preparedness must be communicated much more effectively and presented in an easily understandable way, while authorities, operators of critical infrastructure, and aid organizations should regularly practice joint crisis scenarios and coordinate their communication strategies for emergencies. The core thesis is that a higher threat level not only requires more protective measures but also a society that knows what to do in an emergency. This demand can be interpreted economically as an investment in societal human capital. Prepared knowledge within the population reduces the burden on emergency services in a crisis, minimizes the consequences of misconduct, and accelerates the restoration of normalcy. The costs of such an awareness campaign are comparatively low compared to the economic damage of an uncoordinated crisis, such as widespread power outages or attacks on water supply systems, which makes the KKI's demand understandable from a cost-benefit perspective.
Hub for Security and Defense - Advice and Information
The Security and Defence Hub offers expert advice and up-to-date information to effectively support companies and organizations in strengthening their role in European security and defence policy. Working closely with the SME Connect Defence Working Group, it particularly promotes small and medium-sized enterprises (SMEs) that wish to further develop their innovative capacity and competitiveness in the defence sector. As a central point of contact, the Hub thus creates a crucial bridge between SMEs and European defence strategy.
Related to this:
Gap in the security architecture: Why the KRITIS overarching law is only the beginning
The KRITIS umbrella law as a legal framework
Parallel to the debate on public preparedness, Germany has created a new legal framework for the protection of critical infrastructure with the KRITIS umbrella law. The law was enacted on March 11, 2026, published in the Federal Law Gazette on March 16, 2026, and entered into force on March 17, 2026. It transposes the European Directive 2022/2557 on the resilience of critical installations, also known as the CER Directive, into German law, thus establishing for the first time a uniform federal legal framework for the cross-sectoral physical security of critical infrastructure. Previously, the protection of critical facilities in Germany was regulated inconsistently and with a strong sector-specific focus, which in practice led to significant differences in security levels between individual industries and federal states. The umbrella law ends this fragmented situation by establishing uniform minimum requirements for all relevant sectors, without, however, prescribing in detail which specific measures operators must implement. Instead, the law merely obliges them to take appropriate and proportionate measures, which leaves companies some leeway but also brings with it questions of interpretation and legal uncertainties.
Related to this:
Who is affected and what needs to be done
The KRITIS umbrella law affects operators in a total of ten or eleven strategically important sectors, including energy, transport and traffic, finance and insurance, health, drinking water, wastewater, municipal waste disposal, information technology and telecommunications, food, space, and public administration. Facilities that are essential for the overall supply of services in Germany and serve more than 500,000 people are generally considered critical. According to estimates by industry experts, around 1,300 operators in the affected sectors are required to develop resilience plans, risk analyses, and personnel security concepts. Staggered deadlines apply to implementation: Operators must register with the joint registration platform of the Federal Office of Civil Protection and Disaster Assistance and the Federal Office for Information Security by July 17, 2026, at the latest, although registration was possible from this date onward. Companies are given ten months to develop a comprehensive resilience plan, while regulatory oversight and potential sanctions for violations will only take effect from 2027 onwards. This phased approach demonstrates that the legislator is granting operators a realistic transition period, which seems appropriate given the complexity of the required measures, but also means that the full protective effect of the law will only be realized in the medium term.
Two speeds of resilience
Considering the two levels of action together – statutory operator protection and societal preparedness – reveals a structural imbalance in the German security architecture. While the legislature has created a detailed, enforceable framework with clear deadlines for companies through the KRITIS (Critical Infrastructure Protection Act), no comparable binding mechanism exists for the public. There is no legal obligation to inform citizens about recommended behavior in a crisis, no binding deadlines for public awareness campaigns, and no sanctions for failing to communicate. This asymmetry can be interpreted as a typical pattern of government action: regulation unfolds most effectively where clearly identifiable addressees – i.e., companies – can be subject to legal obligations, while diffuse societal tasks such as raising public awareness are structurally disadvantaged because they lack a clearly defined responsible party and a direct control mechanism. The KKI (Communication and Critical Infrastructure Protection Act) addresses precisely this gap by demanding that the government's responsibility for communication be taken as seriously as the regulatory obligations of operators.
The economic logic of precaution
From an economic perspective, the demand for improved public preparedness can be understood as an investment in resilience capital, which reduces external costs in an emergency. A power outage, a disruption of the drinking water supply, or a breakdown in telecommunications not only causes direct economic damage through production losses and supply shortages, but also indirect costs due to panic, misbehavior, overloaded emergency call systems, and difficulties in coordinating rescue efforts. If a significant portion of the population has basic supplies, functioning emergency communication systems, and appropriate behavior in a crisis, the strain on state systems decreases considerably, resulting in less collateral damage and a faster return to normalcy. This logic is by no means new; it already underlies the civil defense concepts of many neighboring countries, where regular public campaigns, warning apps, and training programs are an integral part of security policy. Germany possesses comparable instruments, both technically and legally, but, as the case of the poorly advertised BBK brochure demonstrates, it has so far only made insufficient use of them.
Risks of a communication strategy lacking sensitivity
At the same time, the call for greater public awareness is not without communicative risks. An imprecise or overdramatized presentation of the threat situation can lead to uncertainty, panic buying, or a general loss of trust in state institutions if citizens get the impression that the state can no longer fulfill its protective function. The Crisis Management Center (KKI) itself therefore explicitly emphasizes that it is not about generating fear, but about providing security through knowledge, which represents a conscious distinction between alarm and information. Successful crisis communication must therefore walk a fine line: it must be concrete enough to guide action, but at the same time be formulated so soberly and objectively that it is not misunderstood as an expression of state helplessness. Experience from other countries shows that continuous, recurring communication integrated into everyday life, for example through fixed annual action days or school curricula, is significantly more effective than one-off campaigns launched immediately after a tightening of security measures, which could therefore be perceived as reactive symbolic politics.
A necessary realignment
The escalation of the threat level by Federal Interior Minister Dobrindt marks a turning point in the German security debate, one that goes beyond the mere assessment of an abstract risk and includes a concrete call to action for society. The KRITIS overarching law demonstrates that the legislature has already created a robust, albeit still in the implementation phase, legal framework at the level of critical infrastructure operators. However, a comparably consistent approach is still lacking at the level of the general public, even though, as the KKI rightly emphasizes, this is precisely where a crucial building block of societal resilience lies. A security strategy that relies solely on technical safeguards and corporate obligations remains incomplete as long as it does not recognize the public as an active participant in the resilience architecture. The coming months will show whether the federal and state governments will heed the KKI's criticism and develop a systematic, comprehensible, and regularly repeated communication strategy from their hitherto rather reserved information policy—a strategy that truly meets the demands of a resilient society.
Consulting - Planning - Implementation
I would be happy to serve as your personal advisor.
Head of Business Development
Chairman SME Connect Defense Working Group
Consulting - Planning - Implementation
I would be happy to serve as your personal advisor.
You can contact me at wolfenstein∂xpert.digital or
Just call me on +49 7348 4088 965 .




















