Mark and Focus analysis
Germany’s Infrastructure Security Test Is Dependency Reduction
Read the analysis
Germany’s National Security Council has ordered further action against espionage and sabotage while linking critical-infrastructure protection to investment screening, raw-material resilience and artificial-intelligence security. The test is whether cross-sector dependencies become visible and governed.
Germany’s National Security Council has agreed further measures against espionage and sabotage following the August hybrid attack in Leipzig. Its September decisions connect protection of critical infrastructure with tighter investment screening, more resilient critical-raw-material supply and security work around artificial intelligence. That combination treats national infrastructure as a network of dependencies rather than a collection of guarded facilities.
Germany critical infrastructure security is increasingly shaped by systems that cross ownership and sector boundaries. Electricity supports telecommunications, water, transport and data centers. Digital platforms coordinate maintenance and logistics. Equipment manufacturers depend on specialist components and raw materials. A disruption in one layer can spread even when the directly affected asset has met its own security standard.
Dependency maps must drive priorities
The first task is to identify services whose failure would create cascading effects. Asset lists are not enough. Operators and government need a shared view of essential functions, upstream suppliers, digital connections, substitute capacity and the time within which service must be restored.
That work should distinguish common dependencies. Several operators may each have backup arrangements that rely on the same telecom provider, fuel distributor, software vendor or overseas component. On paper the assets appear resilient; in practice they can fail together. Procurement and oversight should require disclosure of concentrated dependencies without publishing operational details that would create new vulnerabilities.
The National Security Council’s reference to reducing strategic dependencies makes this a question of economic security as well as physical protection. Diversification can reduce exposure, but it has costs and cannot mean domestic production of everything. Germany needs criteria for deciding where redundancy, stockpiles, alternative suppliers or public support are justified by the consequence and replaceability of a failure.
Investment screening needs a service-risk lens
The government plans rapid amendment of investment-screening law. Ownership matters when an acquisition could expose sensitive information, operational control or supply. Screening will be strongest if it evaluates the service and dependency created by a transaction rather than relying only on a company’s sector label.
Reviews should consider access to operational technology, data, maintenance rights and critical intellectual property. They also need consistent time limits and clear remedies. Conditions on governance, data separation, supply assurance or security clearance may protect a service without blocking beneficial capital. Where a transaction is restricted, authorities should explain the security logic at a level that preserves necessary confidentiality while maintaining confidence in the process.
Critical raw materials create a related challenge. The council identifies Germany’s Raw Materials Fund as a central instrument for diversified, resilient supply. Financial support should be tied to measurable resilience outcomes: additional sources, processing capacity, recycling, verified stock or reduced single-supplier exposure. Otherwise public finance may subsidise a project without changing the dependency that justified intervention.
Response and recovery belong in the same system
Measures against sabotage must extend from detection to continuity and learning. Operators need routes for reporting suspicious activity and technical anomalies, while agencies need protocols for combining information across sectors. Exercises should test who coordinates when evidence is uncertain and several services are affected.
Artificial intelligence can assist detection and analysis, but it also introduces model, data and supplier risks. Security controls should cover the full operating chain: training and input data, access privileges, updates, human review and fallback when automated systems are unavailable or wrong. An AI tool used in a critical process must not become an unexamined common dependency.
Public accountability can coexist with operational secrecy. Germany can report preparedness measures, exercise completion, restoration performance and progress in reducing concentrated dependencies without disclosing exploitable configurations. Independent scrutiny should test whether requirements are producing real capability rather than compliance documents.
The council’s decisions establish the right breadth. The harder work is to translate national-security categories into asset, supplier and service decisions across thousands of organizations. Progress will be demonstrated not by the number of protected sites, but by fewer single points of failure, credible alternatives and faster restoration when prevention does not hold.
Take-Out
Protecting critical infrastructure requires more than hardening individual sites; Germany must identify the suppliers, digital systems, energy links and strategic dependencies that can disable several services at once.
Questions and answers
What readers should know
- What prompted the latest decisions?
- The National Security Council met after an August hybrid attack in Leipzig and agreed additional action against espionage and sabotage.
- Which policy areas are linked?
- Critical-infrastructure protection, investment screening, critical raw materials, military and civil defense, and artificial-intelligence security.
- Why are dependencies central?
- Different operators can rely on the same supplier, digital platform, energy source or component, allowing one failure to disrupt several services.
- What is the Raw Materials Fund expected to support?
- Projects that strengthen diversified and resilient access to strategically important raw materials.
- What would show practical improvement?
- Reduced single points of failure, exercised continuity arrangements, effective cross-sector reporting and faster restoration after disruption.