Overestimated Cybersecurity Capabilities: A False Sense of Security Among German Small and Medium-Sized Businesses


Benchmarks from PwC analyses show that the actual maturity levels of security are significantly lower than companies’ self-assessments. At the same time, IT security budgets often fail to address the current threat landscape and are frequently insufficient to meet rising demands. Furthermore, attackers are increasingly focusing on the supply chain, as vulnerabilities among service providers and partners offer attractive targets.
The use of artificial intelligence is fundamentally changing the threat landscape by providing both attackers and defenders with new capabilities. In addition, external service providers are increasingly becoming an integral part of modern security architectures and are taking on important roles in protecting IT infrastructure.
Sharp Increase in Data Breaches
The discrepancy between people’s subjective sense of security and the lower level of protection—as evidenced by maturity analyses—is particularly critical given the current threat landscape. For example, the recently published PwC study „Threat Dynamics“ shows that there has been a massive increase in data breaches and ransomware activity in Germany. According to the study, small and medium-sized enterprises (SMEs) are particularly vulnerable because many companies are still in the process of transitioning to zero-trust architectures, and user accounts without consistent access controls across all network boundaries remain a critical vulnerability.

„As the driving force behind the German economy, small and medium-sized businesses are
”Unfortunately, it's a highly lucrative target for attackers."
Uwe Rittmann,
Head of Family-Owned Businesses and Small and Medium-Sized Enterprises,
PwC Germany
The threat to small and medium-sized enterprises (SMEs) is also confirmed by the BKA’s 2025 Situation Report, which states that 90 percent of digital extortion victims are SMEs. „As the engine of the German economy, SMEs are unfortunately a highly lucrative target for attackers. The dilemma is that while we see significant progress in digitalization at many companies, this not only increases their potential for innovation but also expands their attack surface,“ said Uwe Rittmann, Head of Family Businesses and SMEs at PwC Germany.
While the majority rate their own maturity level as advanced, the benchmarks used for comparison paint a different picture. Self-assessments are consistently one to two maturity levels higher than the benchmarks. The latter are based on actual analyses that include, among other things, technical inspections of the IT infrastructure, reviews of existing security documentation, and interviews with the responsible departments.
Investment volumes are too low
„Companies systematically overestimate their own cyber defense capabilities. This is also reflected in security budgets that are, in some cases, disproportionately low,“ says PwC IT security expert Nial Moore. While an annual budget of 50,000 euros may still be appropriate for small businesses with fewer than 200 employees, it is not sufficient to adequately address the risks in larger organizations. Nevertheless, even many significantly larger companies invest less than 50,000 euros in their IT security—which the expert considers a high risk: „Such budgets are not sufficient for professional monitoring or tested emergency procedures. This is cutting corners in the wrong place, because the potential damage from even supposedly minor incidents generally far exceeds the investment required for adequate protection.“ (Source: PwC)



