NKCS Thematic Workshop: “A New Era — Strengthening the Cyber Defense Industry”

11 July 2025

Following this year’s CODE Annual Conference, the NKCS thematic workshop “A New Era—Strengthening the Cyber Defense Industry” took place on July 10, 2025, at the University of the German Armed Forces in Munich, organized by the DLR Project Management Agency and the CODE Research Institute.

The geopolitical situation is becoming increasingly threatening; former trading partners are attacking our democracy, and allies are severing ties with us. Germany and the European Union have recognized the signs of the times and are increasing their investment in security, defense, and, above all, sovereignty. For this reason, the National Coordination Center for Cybersecurity Germany (NCC-DE) organized this thematic workshop to discuss with experts how we can better position Germany and Europe in the field of cyber defense and establish them as serious players. The key questions centered on how cyber defense should evolve in light of the geopolitical situation, what it would take for Germany and Europe to assume leading roles, and where the experts foresee our situation in 2030.

Brigadier General Dr. Volker Pötzsch provided insights into the current situation from the Bundeswehr’s perspective in his keynote address on “Threats and Challenges Facing the Bundeswehr in the International Arena.” He emphasized that we find ourselves in a rapidly changing security (and insecurity) environment and that we must shift as quickly as possible from a purely “reactive” mode to a “proactive” one. This becomes particularly essential when we address the topic of critical infrastructure, in which a multitude of sectors (including government & administration, transportation & traffic, health, finance, information technology & telecommunications, and media & culture) are interconnected, much like an orchestra that is meant to play a harmonious score. If all the instruments are well-tuned and the participants work well together — or coordinate through the exchange of information and knowledge — we can also collectively address the threats in cyberspace and the information domain (including cognitive warfare and digital footprints). We can only actively shape this score together!

Heinz-Georg Schmitz (Bosch Engineering GmbH) provided insights from the industry in his presentation titled “Cybersecurity — Status and Solutions in the Automotive World.” It became clear that security in this field encompasses a wide variety of aspects: (1) Security can be a showstopper, particularly when it comes to compliance with non-negotiable regulations (e.g., UN R155, ISO/SAE 21434); (2) However, security can also be an enabler when it comes to expanding vehicle functions (including driver assistance and comfort); (3) Safety can also entail risks, given how interconnected the systems are and how this makes the vehicle an increasingly attractive target for cyberattacks, and (4) Safety is and remains a brand promise. In summary, safety in the automotive industry must be viewed holistically — as a regulatory necessity, as a driver of innovation, as protection against emerging risks, and as a core element of brand trust.

With these two keynote presentations, the approximately 40 participants from industry and research kicked off the active portion of the thematic workshop. In the first round of the World Café-style session, a wide variety of questions regarding the status quo in the German cyber defense sector were discussed, including the strengths and weaknesses of the German industry and research community, as well as how we stack up in European and global comparisons. In the first step, topics and aspects were collected; these were then sorted and grouped in the next step before the participants prioritized them. Variety and a change of perspective were achieved by rotating participants among the different tables after each step. This ensured that all participants were confronted with the questions, could learn about others’ lines of thought, and could then prioritize the issues from their own perspective.

Specifically, the following points among others were identified in Round 1 as areas where there is an urgent need for improvement: (1) Increasing risk tolerance — it is better to try than to overthink; let’s see what happens instead of focusing on the drawbacks; (2) Minimizing regulatory fragmentation, bureaucracy, and dependencies (including on electronics, software, and hyperscalers); (3) Strengthening small and medium-sized enterprises, innovation transfer, and support during TRL transitions; (4) Fostering an understanding of cyber defense at all levels.

In Round 2, the groups were reorganized, and — as before, in three steps — questions regarding the industry’s future-oriented development were addressed: Where do you see the industry in 2040? What can the government and the Bundeswehr do to strengthen the industry? What opportunities do European partners offer? Regardless of the sectors the participants in the groups represented, it became clear that everyone was considering the same issues, facing similar risks, and that the exchange of information and experience is essential to counter threats — and that the cyber defense industry can only be strengthened through collaboration. Using the guiding questions and insights from Round 1, Round 2 produced concrete proposals for ushering in a new era, which were intended to cover the following aspects, among others: (1) closer cooperation between the government, the private sector, and research institutions; (2) minimizing dependencies; (3) Consolidation of common requirements and standards; (4) A national alliance to serve as a global counterweight; (5) Establishment of a professional career path for cyber defense with close collaboration between civilian and military sectors; (6) Creation of transparency and a central, shared interest in cyber security.

All in all, the issues of security and defense are and will remain inextricably linked, and are becoming increasingly multifaceted. Only by working in harmony and engaging in continuous dialogue can we play a well-orchestrated score that can cope with the many short-term disruptions and/or failures that arise in this complex environment. Only together are we strong and can we strengthen the cyber defense industry!

This realization also led to “exchanging business cards,” the continuation of many discussions, and the discovery of numerous commonalities. All of this will be carried forward in the coming months through additional workshops of this kind. After all, a network must and can grow, and it can also exert influence at higher levels (e.g., committees or the EU), thereby transforming the research and development landscape in the field of cyber defense!

 

Photos: © SeCoSys/Schmitt