News
Study: The external vulnerabilities of federal ministries' IT systems
What is the size of the attack surface of Germany's federal ministries, and how much of it is visible?
Just how secure are the IT systems of federal ministries? A recent ATHENE study assessed their external attack surface and revealed significant gaps in their current security posture.

A recent ATHENE study examined the IT infrastructure of federal ministries from an external perspective. This differs significantly from the assessment of the Federal Office for Information Security (BSI). A substantial portion of the attack surface lies outside the core government network, in systems operated by third parties, as well as at subordinate agencies and service providers. Instead of a unified federal IT infrastructure, the study reveals 16 very different IT landscapes.
The main problem is not novel zero-day vulnerabilities, but rather long-known issues and old, unpatched security gaps.
The study also explains why the BSI’s assessment fails to capture a large part of this attack surface. It is based on the government-owned address space and .de domains — an approach from the on-premises era that inadequately reflects the IT infrastructure which has become increasingly outsourced and cloud-hosted over the past two decades. Those who base their security measures on an incomplete threat assessment risk overlooking the largest and least controlled part of the attack surface.
Based on this, the study also evaluates current political strategies. According to the study, the 'CyberGovSecure' programme, which was adopted on 22 July 2026, represents an important step forward. However, it lacks binding deadlines, measurable goals and a budget. Furthermore, the understanding of assets underlying the programme does not sufficiently account for the external attack surface. The Germany Stack also relies on reuse and new platforms without adequately considering the mandatory decommissioning of legacy systems and the technically justified heterogeneity of the ministries.
The study's key message is that the security of the federal government's IT infrastructure depends not only on new platforms, but also on consistent basic security practices, binding security requirements in operator contracts and a willingness to decommission outdated systems.
to the situation report on IT in the Federal Ministries (in German)
show all news
