Cybersecurity in finance in Germany

Banks, insurers and payment firms in Germany reported 525 serious ICT incidents to BaFin in the first three quarters after DORA took effect, about 70 percent of them from credit institutions. Their security rules come from DORA, while the BSI keeps a role through the German NIS2 law. Dated events are in the calendar below.

Finance side event of AI Week Frankfurt, presented by Finance Loop

What cybersecurity in finance means in Germany

Cybersecurity in finance is the protection of the systems that hold accounts, move payments and run trading: core banking, card processing, online banking, market access and the cloud services behind them. An attack on these systems can stop payments for millions of customers, so financial firms carry duties that most other companies do not. In Germany two authorities are involved. BaFin supervises how banks, insurers and other financial firms manage IT and cyber risk, and the Federal Office for Information Security (BSI) is the national cybersecurity authority for the country as a whole.

BaFin names cyber incidents with severe impact as one of its risks in focus (in German). It points to geopolitical tension, more complex IT systems and the use of artificial intelligence as reasons, and it counted 525 serious ICT incidents reported in the first three quarters of DORA's first year, about 70 percent of them from credit institutions.

The threat picture: ransomware, data leaks and weak spots

The BSI's annual report on the state of IT security in Germany gives the wider picture. It counts on average 119 new security vulnerabilities a day, 24 percent more than a year earlier. The number of ransomware attacks recorded by the Federal Criminal Police Office stayed at about 950, and the greatest damage came from ransomware combined with data leaks, where attackers encrypt systems and threaten to publish stolen data. About 80 percent of the registered incidents hit small and medium-sized companies, a group that includes many of the IT suppliers banks depend on.

For a financial firm, a ransomware case raises questions beyond IT: whether to pay, whom to report to and whether the attackers' wallet is on a sanctions list. The page on ransomware payments goes through those layers. Social engineering is the second route in: attackers use cloned voices and video of executives to push staff into urgent transfers, which is why deepfake awareness training has reached bank security teams.

NIS2, the BSI Act and DORA: which rules apply to whom

The EU's NIS2 Directive raised the cybersecurity duties for companies in critical and important sectors, and Germany put it into national law by amending the BSI Act (BSIG). Banking and financial market infrastructure are among the sectors NIS2 lists. For financial firms, though, the EU made DORA the more specific law. The BSI states that DORA takes precedence (in German) over the BSI Act on cybersecurity risk management and on reporting significant incidents, and that BaFin is the competent authority for DORA.

In practice a German bank builds its security program on DORA and reports major ICT incidents to BaFin. The BSI Act still reaches it in other ways, for example where the BSI Act's own registration duties apply, and many of the bank's IT suppliers fall under NIS2 in full. A payment processor or a cloud provider can therefore answer to the BSI for its own security and to its bank customers for DORA contract terms at the same time. The detail of DORA itself, from the register of information to threat-led penetration tests, is on the DORA in Germany page.

What security teams at German financial firms work on

Identity and access come first. Most successful attacks start with stolen credentials, so banks roll out phishing-resistant multi-factor authentication for staff and customers, and they watch privileged accounts in the cloud closely. The second topic is the supply chain: a bank's security depends on software vendors, cloud platforms and payment processors, and a weak spot at one supplier can reach many banks at once.

Artificial intelligence works on both sides. Attackers use it for phishing and deepfakes, and security teams use it to sort alerts and detect fraud. A bank that runs AI systems also has to secure them, and BaFin has published guidance on ICT risks from AI under DORA, covered on the page on AI compliance in Germany. The longest-running task is cryptography: a future quantum computer could break the public-key methods that protect bank traffic today, so security teams have started to list where they use them. The page on quantum computing in Frankfurt explains the timeline.

IT risk and cyber risk

IT risk is the wider term: any loss from failing technology, including a bad software update, a data center outage or an overloaded system. Cyber risk is the part caused by an attacker. Under DORA both fall into ICT risk, and a bank's risk management covers them in the same framework as credit and market risk. Someone new to the field should learn the incident classification criteria and the bank's own reporting chain first, because the first hours of an incident decide whether the reporting deadlines hold.

Upcoming events on risk and compliance in Germany

Cybersecurity in finance at Finance Loop

Finance Loop is the meeting place for information security officers, IT risk managers and the vendors who protect banks, insurers and payment firms. It connects the finance, IT and AI communities in Frankfurt and holds events in Munich, Berlin and Hamburg as well.

At the AI Week Frankfurt side event, presented by Finance Loop with Frankfurt Main Finance and Sopra Financial Technology, revel8 spoke on deepfake awareness. Finance Loop highlighted fAInance, a conference by Sopra Steria and Fraunhofer IAIS with deep dives on AI security. Finance Loop announced KI Exchange 2026 in Hamburg, where DORA compliance and fraud detection were on the program, and co-organized the Frankfurt Quantum Finance Forum, where quantum risk to cryptography was a topic.

What is cybersecurity in banking?

It is the protection of a bank's systems, data and customer accounts against attacks. In Germany it is part of the ICT risk management that DORA requires, supervised by BaFin, and it covers access control, network security, incident response, backups and the security of IT suppliers.

Does NIS2 apply to banks in Germany?

Banking is a NIS2 sector, but for cybersecurity risk management and incident reporting DORA takes precedence, as the BSI explains (in German). A bank reports major ICT incidents to BaFin under DORA. Parts of the BSI Act outside those two areas can still apply.

What is the difference between IT risk and cyber risk?

IT risk covers every loss from failing technology, whether a faulty update or a power cut in a data center. Cyber risk is the share caused on purpose by attackers. Banks manage both as ICT risk under DORA.

Is there a cybersecurity meetup for finance in Frankfurt?

Finance Loop runs evenings in Frankfurt, often at TechQuartier, where security, risk and compliance people from banks and fintechs meet, and it supports conferences on AI security and DORA. Dates are in the calendar on this page.

Cybersecurity in finance and Finance Loop

Cybersecurity sits in the Risk & Compliance track of Finance Loop. Talks on deepfake awareness at the AI Week Frankfurt side event and on quantum risk at the Frankfurt Quantum Finance Forum brought the topic to Finance Loop audiences, and security people meet at Finance Loop events across Germany, Austria and Switzerland.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.