The German Cabinet has approved a reform of the German Federal Intelligence Service (BND). The Internet Industry Association (eco) criticizes the planned exploitation of IT vulnerabilities by foreign intelligence and warns against conflicts of interest at the BSI as well as a weakening of independent oversight.

As part of an adapting security landscape, the German government plans to modernize the technical capabilities of the Federal Intelligence Service (BND). However, the plans passed by the cabinet face significant opposition from the digital economy. The industry association eco warns that the proposed legislation could undermine national cybersecurity.

A primary point of criticism centers on the management of newly discovered IT vulnerabilities. Under the proposed rules, state authorities could develop an interest in leaving security gaps unpatched to facilitate intelligence access rather than closing them immediately. eco Board Member Klaus Landefeld highlighted that any vulnerability accessible to the BND can equally be discovered and exploited by cybercriminals or foreign intelligence services. Given that the window between disclosure and potential exploitation often spans only a few hours, government resources must strictly prioritize threat mitigation and rapid patching.

The future role of the German Federal Office for Information Security (BSI) is similarly questioned. The proposed obligation to forward vulnerability data to the BND creates a clear conflict of interest. Businesses must be able to trust that reporting security flaws to the BSI leads directly to system protection rather than feeding intelligence operations.

Furthermore, the reform expands the geographical reach of the BND. Under specific conditions, the foreign intelligence agency would be authorized to intervene in domestic IT systems. Consequently, digital infrastructure operators and businesses within Germany fall within the scope of intelligence measures. eco demands stringent statutory thresholds and effective, independent oversight for any domestic operations.

At the same time, the reform restructures oversight mechanisms. The duties of the former G10 Commission are largely expected to transfer to the Independent Control Council. However, provisions for exigent circumstances permit actions to be executed prior to Council approval. Retrospective reviews cannot replace effective prior authorization. Additionally, the deployment of AI and automated systems in state interventions necessitates clear accountability and complete auditability. eco calls upon the Bundestag to amend the legislation regarding vulnerability handling, BSI neutrality, and prior oversight.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner