eco - Verband der deutschen Internetwirtschaft e.V.

10/06/2026 | Press release | Distributed by Public on 10/06/2026 06:57

eco on the Hearing on the Cybersecurity Act

Berlin, 5 October 2026 - Following today's hearing of the Committee on Internal Affairs on the Act to Strengthen Cybersecurity, eco - Association of the Internet Industry continues to see a considerable need for improvements. The planned interventions in IT systems and data traffic raise fundamental questions regarding proportionality, technical feasibility and oversight under the rule of law. Among other things, public authorities are to be able to redirect or record data traffic, delete or alter data in IT systems and intervene in domain name resolution.

The hearing also confirmed the need for improvements to the new cyber defence powers. The more intrusive a measure is, the more clearly the thresholds for intervention must be defined and the more firmly oversight under the rule of law and safeguards must be enshrined.

Germany must be able to defend itself effectively against serious cyberattacks. However, particularly in the case of such intrusive powers, exceptionally high standards of proportionality, technical safeguards and oversight under the rule of law are essential. The legislature must therefore impose strict limits on such powers.

Cyberattacks are frequently carried out via compromised systems belonging to uninvolved third parties. If, for example, a compromised server is used as an intermediary for an attack, a shutdown or redirection of data traffic by public authorities may also affect uninvolved users and companies that use the same infrastructure. Identifying attack infrastructure therefore does not automatically mean that the actual attacker has been identified. Before far-reaching measures are taken, the technical attribution of a source of threat must therefore be sufficiently reliable. Uninvolved third parties must be effectively protected against misattribution and collateral interference.

eco Association also takes a critical view of potential interference with data flows and obligations on telecommunications companies and digital service providers to cooperate. Measures at the DNS or traffic level may also affect uninvolved services and users. If, for example, a compromised domain is redirected or rendered inaccessible, legitimate services operating under the same domain may also be affected. State intervention in data traffic must not gradually become a standard tool of the security authorities.

eco Association therefore calls for priority to be given to defensive and, where possible, minimally invasive measures. Where attacks can be stopped through takedowns, the isolation of compromised systems or other targeted measures, far-reaching interventions must not become the norm. Vulnerabilities should, as a matter of principle, be closed and responsibly disclosed rather than being left open for operational purposes. Cybersecurity is achieved primarily through secure and resilient infrastructures - not through the broadest possible scope for state intervention.

For the further parliamentary proceedings, eco Association therefore calls for stronger safeguards under the rule of law and stronger technical safeguards. In the case of particularly intrusive measures, the requirement for judicial authorisation must not be restricted solely to IT systems used for private purposes. At the same time, the thresholds for intervention must be differentiated more clearly according to the severity of the measure in question and its relevance to fundamental rights. State cyber defence must remain targeted, verifiable and limited to what is strictly necessary.

(German-language) eco Association statement on the draft Act

eco Association statement on the Cabinet's consideration of the bill

eco - Verband der deutschen Internetwirtschaft e.V. published this content on October 06, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on October 06, 2026 at 12:57 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]