Knowledge

Cybersecurity in Transition: Why Companies Face Unprecedented Challenges Today

Professional cybercriminals and AI-powered attacks are pushing the threat landscape to unprecedented levels. With annual damages reaching €202.4 billion, risks are now evolving faster than defences can keep up.

Kassandra Büttner

VP Growth & Marketing

·

·

5 minsReading time

According to a study by Bitkom, most cyberattacks worldwide originate in Russia, China, and the USA. These are carried out by professional, organised cybercriminals, state actors, and increasingly by AI-powered attacks. The facts speak for themselves: cyberattacks cause €202.4 billion in damage in Germany every year (Bitkom, 2025a). More than half of all businesses feel their existence is threatened. Despite this, risks are evolving faster than security measures.

The World Economic Forum reports that 72% of all organisations worldwide have experienced rising cyber risks in the last year (World Economic Forum, 2025a). What is particularly insidious is that attackers have long been using artificial intelligence to operate more quickly, purposefully, and professionally. In many companies, however, AI is used in an uncontrolled manner or without security checks, creating an ideal entry point for data theft and sabotage. This is a new reality for businesses of all sizes.

Cybersecurity in Germany: growing risks meet improvable security concepts

German firms are investing more than ever in IT security. In 2025, spending will rise to €11.1 billion, an increase of 10.1%. The share of the IT security budget has doubled from 9% to 18% within three years. Yet the number of incidents also shows this trend (Bitkom, 2025b).

35% of companies expect a sharp increase in attacks, with another 47% expecting a clear rise. Not a single company expects a decline (Bitkom, 2025a). The problem is therefore not money, it is speed. Attackers are evolving faster than many security departments can keep up with.

At the same time, cybercrime is professionalising at a rapid pace. The World Economic Forum warns that "cybercrime-as-a-service" platforms enable even less technically savvy perpetrators to carry out highly complex attacks (World Economic Forum, 2025). This makes every firm, no matter how large, a potential target.

"The more we use AI in everyday life, the more vulnerable systems become to manipulation, abuse, and data leakage if security is not integrated from the very start," said Prof. Dr Dennis-Kenji Kipker in an interview with CYBERsicher in June, adding: "In order to raise awareness of cybersecurity issues among employees, we need management that leads by example." (Kipker, cited after Baldus, 2025).

The global situation: more complex, faster, more challenging

The global cybersecurity situation is becoming more demanding. According to the "Global Cybersecurity Outlook 2025", 60% of organisations view geopolitical tensions as a direct factor influencing their cyber strategy (World Economic Forum, 2025). Attacks are becoming a tool of international conflict, targeting German companies as well.

Particularly worrying is that 35% of small organisations consider their cyber resilience to be insufficient, seven times as many as in 2022 (World Economic Forum, 2025). Small and medium-sized enterprises are therefore the weakest link in the digital chain and thus a preferred target.

Supply chains increase the risk further. 54% of large companies name vulnerabilities in partners and service providers as the greatest obstacle to effective protection (World Economic Forum, 2025). A single compromised software update or an external service provider with poor protection can be enough to compromise an entire corporate ecosystem.


The AI game changer: both a saviour and a risk

Artificial intelligence is revolutionising cybersecurity and, at the same time, cybercrime. 66% of companies expect AI to have the greatest impact on the overall cybersecurity situation in the coming twelve months (World Economic Forum, 2025).

But this is where the core problem arises: while attackers use AI to make phishing emails more flawless, to scan systems, or to improve malware, only 37% of companies actually have a process in place to check the security of new AI tools before deployment (World Economic Forum, 2025). Many firms deploy models or tools they do not understand, thereby unintentionally opening new backdoors.

Deloitte sums up the threat clearly: with every AI system in a company, the attack surface grows because data, models, interfaces, and infrastructures must be protected (Deloitte, 2025a).

At the same time, AI can also massively strengthen defences. Modern systems detect anomalies in real time, classify vulnerabilities, accelerate security analyses, and can even give strategic recommendations as an "AI-CISO" (World Economic Forum, 2025). Those who use AI wisely and securely can overtake attackers for the first time, instead of just chasing after them.

The invisible vulnerability within the company: Shadow AI

Shadow AI refers to artificial intelligence applications that employees use without the knowledge of the IT or security departments. This can be harmless ChatGPT usage, or it can mean that sensitive customer data, confidential documents, or internal strategies are carelessly copied into external models.

According to KPMG, 48 to 49% of respondents admitted to uploading sensitive company data into public AI systems, including financial figures, sales and customer data, or even copyrighted material. Particularly concerning is that such breaches occur most frequently in companies that have actually introduced rules. 67% of employees in firms with an AI ban and 56% in companies with an AI policy nevertheless upload sensitive data to public digital tools. In organisations without a policy (33%) or with unclear regulations (38%), this happens much less frequently (KPMG & University of Melbourne, 2025).

The numbers clearly show that bans do not work, and policies alone do not ensure security. Without practical guidance, clear processes, and real training on responsible AI use, shadow AI risks emerge regardless of what is officially permitted or forbidden.

Studies show that companies do not have a complete overview of where AI is being used. The attack surface is growing faster through AI systems than governance structures can keep up with (Deloitte, 2025a). There is a lack of security reviews before the deployment of new AI tools (World Economic Forum, 2025).

In this combination, shadow AI arises almost automatically and quickly becomes a problem: data leakage, model manipulation, compliance violations, and massive liability risks can be the consequence. Companies are thus unintentionally creating their own vulnerability.

While professional cybercriminals have long been using AI for deepfakes, phishing, or automated malware, companies often use untested services and thus increase their own attack surface, for example, through prompt leaks or unwanted data loss.

The way forward: security must be considered from the start

The solution lies in a consistent "Secure-by-Design" approach. Deloitte describes a model for this in which security is not patched on at the end of a project, but is integrated right from the beginning (Deloitte, 2025b).

This means security is considered throughout the entire development process. Standards such as NIST, ISO 27001, and the NIST AI Risk Management Framework are embedded. AI systems, data, and applications are continuously tested, classified, and monitored. The entire company gains transparency over which assets actually exist, which is the basic requirement for preventing shadow AI.

Only when companies know exactly which AI is running where and what data it processes can they maintain control instead of being caught by surprise.

What this means for businesses

The message is clear: cyberattacks are no longer a niche phenomenon. They are one of the greatest threats to the economy, and they are becoming even more powerful through artificial intelligence. Companies of all sizes must therefore modernise their security strategies, protect their data, and actively prevent shadow AI.

Those who do not act now risk not only millions in losses but also their very existence. However, those who have started early or are working as quickly as possible on deploying AI securely can gain a decisive advantage and, in the long run, belong to the winners of the digital future.


Sources:

Bitkom. (2025a). Cybercrime und der Markt für IT-Sicherheit 2025. https://www.bitkom.org/sites/main/files/2025-10/bitkom-charts-cybercrime-und-der-markt-fuer-it-sicherheit-2025.pdf

World Economic Forum. (2025). Global Cybersecurity Outlook 2025. https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2025.pdf

Bitkom. (2025b). Deutscher Markt für IT-Sicherheit wächst zweistellig. https://www.bitkom.org/Presse/Presseinformation/Deutscher-Markt-IT-Sicherheit-waechst-zweistellig

Baldus, J. (2025, 26 June). Digitale Resilienz: Cybersicherheit ganzheitlich gedacht. Transferstelle Cybersicherheit im Mittelstand. CYBERsicher. https://transferstelle-cybersicherheit.de/digitale-resilienz-cybersicherheit-ganzheitlich-gedacht/

Deloitte. (2025a). Cyber Security – Cybersecurity trifft KI und Generative KI. https://www.deloitte.com/de/de/services/consulting/perspectives/cybersecurity-meets-ai-genai.html

Deloitte. (2025b). Secure by Design – A CISO’s Guide to a Practical Approach. https://www.deloitte.com/us/en/services/consulting/articles/secure-by-design-ciso-guide.html

KPMG International & University of Melbourne. (2025). Trust, attitudes and use of AI: A global study 2025. https://kpmg.com/xx/en/our-insights/ai-and-technology/trust-attitudes-and-use-of-ai.html