Security Gaps Threaten German Medium-Sized Enterprises Amid GDPR Compliance Failures
Most German medium-sized companies struggle with weak IT security and fail to fully comply with GDPR access rights, exposing critical vulnerabilities.
- • Over 80% of medium-sized enterprises in the DACH region have insufficient login security.
- • 66.7% of administrators possess excessive permissions, enabling internal network breaches.
- • 62.1% lack centralized logging or SIEM systems, delaying detection of cyberattacks.
- • 83.5% of GDPR data access requests remain unanswered or incomplete by companies.
Key details
A recent report by Trufflepig IT-Forensics reveals that over 80% of medium-sized enterprises in the DACH region face significant security vulnerabilities due to weak access controls and outdated IT structures. The study, which examined 273 penetration tests, shows that 81.8% of companies lack sufficient authentication security for sensitive systems, primarily relying on traditional passwords. Additionally, 66.7% of administrators have excessive permissions, facilitating lateral movement for attackers within networks. Alarmingly, 62.1% of these firms operate without centralized logging or SIEM systems, causing delayed attack detection.
Furthermore, 56.1% of companies maintain inadequate incident response plans that lack regular testing, and 47% fail to segment their networks properly, risking exposure of critical infrastructure. Christian Müller, CTO at Trufflepig, emphasizes that breaches typically stem from such structural weaknesses rather than advanced "zero-day" exploits.
Compounding these security challenges, a separate analysis by noyb highlights that 83.5% of GDPR data access requests remain unanswered or incomplete by companies, including major platforms like TikTok and Microsoft’s Xandr. While the EU Commission considers limiting access rights in the ongoing Digital Omnibus legislative process, critics argue this undermines transparency and data protection. Over 70% of data protection officers do not view such requests as burdensome, contradicting claims justifying proposed restrictions.
These findings underscore an urgent need for medium-sized German enterprises to strengthen both cybersecurity fundamentals and compliance with data protection regulations. Experts advocate for a proactive approach combining prevention, transparency, and active response readiness to combat escalating ransomware and espionage threats.
This article was translated and synthesized from German sources, providing English-speaking readers with local perspectives.
Source articles (2)
Source comparison
Latest news
Germany Faces Healthcare Accessibility Challenges Amid Budget Cuts and Physician Shortages
Germany and EU Partners Agree on Deportation Centers Outside Europe for 2027
AfD Leads Sachsen-Anhalt State Election Race Amidst Rising Tensions and Media Scrutiny
Hansa Rostock Condemns Hooligan Violence and Extremist Symbols During Watford Friendly
FC St. Pauli's Winless Streak Hits 188 Days After 2-2 Draw with Arminia Bielefeld
AfD's Rising Influence in Sachsen-Anhalt Sparks Public Concern Ahead of 2025 State Election
The top news stories in Germany
Delivered straight to your inbox each morning.