Artificial intelligence has drastically worsened the threat landscape in cyberspace, but German companies are reacting far too slowly. While attackers use AI for automated scripts, deepfakes, and phishing, most companies lack emergency procedures and organizational protection concepts.
Keyfacts AI attacks at a glance:
- High level of concern: Every sixth German company (17 %) has already reported confirmed incidents or suspected cases regarding AI-based cyberattacks.
- Popular methods: Deceptive real phishing emails lead with 90 % ahead of automated attack scripts (40) % and deepfakes (11). %.
- Poor preparation: Only 11 % of the companies with AI-related activities have established specific processes for AI-related security incidents.
- Lack of protection: Just under a third (29 %) of AI users completely forgo training, risk assessments or provider audits.
- Call for testing standards: Around 70 % of the companies are demanding independent certifications for reliable AI systems.
A frightening number of attacks, a frighteningly little amount of preparation
A look at the threat landscape shows how massively artificial intelligence is increasing the risk to the economy. According to the press release, every sixth company in Germany has already recorded AI-based cyberattacks or corresponding suspicious cases. At the top of the list are deceptively real phishing emails that are hardly noticeable thanks to AI. But self-learning attack scripts and fake audio and video recordings – so-called deepfakes – are also causing problems for companies. However, while criminals have long since taken advantage of the technology, the defense lags behind. According to the study by the TÜV Association and BSI, only eleven percent of companies with AI connections have special procedures for such security incidents.
Between touch fears and security gaps
Behind the numbers lies a twofold task for businesses: they must arm themselves against attacks from the outside and, of course, also secure their own use of AI. So far, for example, about half of all businesses use artificial intelligence. It is understandable that more than half of the skeptics cite privacy and security concerns as the main reason. However, it is remarkable how laxly many of those companies that already use the technology act. Although many resort to basic technical measures such as access rights, just under a third completely forgo training, risk assessments, or approval processes at the organizational level.
Trust is no longer enough: What the protection should look like
The crucial question is: How can security be ensured in the future? According to TÜV President Dr. Dirk Stenkamp, pure trust in manufacturers’ self-declarations is no longer sufficient. According to the press release, around 70 percent of companies expect significantly more reliability through independent certifications. At the same time, BSI Vice President Thomas Caspers emphasizes that companies without their own AI strategy are also in sight and that AI should urgently be used to defend themselves. For small and medium-sized businesses, the Alliance for Cyber Security has therefore issued recommendations for action, while the federal government is building a new AI security institute.