
Public authorities, municipalities, and their municipal enterprises are among the most attractive targets for cyberattacks because they manage sensitive data and provide critical services for citizens. The report of the Federal Office for Information Security (BSI) on the state of IT security in Germany 2025 paints a tense picture: In the reporting period, the BSI registered an average of around 119 new software vulnerabilities per day (recorded worldwide), an increase of about 24 percent over the previous year. The Federal Criminal Police Office registered around 950 reported ransomware cases for 2024, around 80 percent of which affected small and medium-sized enterprises.
The crucial insight for public authorities: Most successful attacks do not begin with highly complex technology but with an email, a call, or a message that leads a person into a thoughtless action. The EU cybersecurity agency ENISA also confirms this picture: In its Threat Landscape 2025, social engineering – above all phishing – is the most common initial attack vector, at around 60 percent of the cases examined. Technical protective measures such as spam filters and firewalls are necessary but fall short if employees do not recognize the scam. This is exactly where security awareness comes in: It enables employees to recognize attack attempts, classify them, and respond correctly, thus turning the supposedly weakest link into an effective line of defense.
Phishing refers to the attempt to obtain login credentials or to induce people to execute malware via fake messages. In public administration, such messages are often disguised as letters from supervisors, other authorities, ministries, or IT service providers. These warning signs help to recognize a suspicious message:
No single characteristic is definitive proof. What matters is the overall picture and, if in doubt, checking back via a known, independent channel, i.e., via a telephone number you have looked up yourself and not via the contact details from the suspicious message itself.
For a long time, a classic piece of advice was to recognize phishing by spelling mistakes and clumsy German. This tip is losing value. The BSI's 2025 report on the state of IT security points out that attackers are increasingly using AI-supported tools to create convincing, error-free, and individually tailored messages. Deceptively genuine voice and video imitations are also becoming easier. In practice, this means: Linguistic perfection is no longer an all-clear signal. The content-related check questions become all the more important, such as whether a request is plausible, whether the method of contact is customary, and whether independent verification is possible if in doubt.
Phishing is only one variant of social engineering, i.e., the targeted manipulation of people. In public authorities, a few patterns in particular occur again and again. In CEO or boss fraud, attackers pose as the head of the authority and push for an urgent, confidential bank transfer or data release. In vishing, the attack takes place by phone, for example by an alleged IT support team that wants to get people to hand over login credentials. In pretexting, attackers build up a credible cover story over several contacts to gain trust before making their actual demand.
What all these scams have in common is that they work with the same psychological levers: authority, time pressure, helpfulness, fear, or curiosity. Anyone who knows these levers will recognize the manipulation attempt more easily, even if the specific story sounds new and plausible. Healthy skepticism toward unusual requests, especially when they are combined with pressure, is the most effective countermeasure.
In public administration, security awareness is not only a question of good practice but is also embedded in several sets of rules. With the NIS-2 implementation act (NIS2UmsuCG, BGBl. 2025 I no. 301), which amended the BSI Act (BSIG) and has been in force since December 6, 2025, entities of the federal administration are subject for the first time to uniform minimum requirements for information security management. The catalog of measures under Section 30 BSIG expressly mentions basic cyber hygiene and training in IT security; the management level is obliged to participate in training courses (Section 38 BSIG). For federal states and municipalities, implementation is governed by state law: The federal states decide under their own responsibility which parts of their administration are covered – the BSI provides its own information on this for states and municipalities.
Irrespective of NIS-2, data protection law requires appropriate technical and organisational measures: Under Article 32 GDPR, controllers must ensure a level of protection appropriate to the risk; raising awareness among and training employees is one of the recognized organizational measures. For data processing in the area of criminal prosecution, Section 64 of the Federal Data Protection Act (BDSG) makes a corresponding provision and expressly refers to the Technical Guidelines and recommendations of the BSI. In public administration, the methodological basis is provided by the IT-Grundschutz of the BSI, which takes a holistic view of information security and, in addition to technical aspects, also includes organizational and personnel aspects – i.e., raising employee awareness.
Limitation/context: Whether and to what extent a specific authority is covered depends on its level, tasks, and size and can only be assessed bindingly on a case-by-case basis. What is certain, however, is this: Awareness raising is not merely an optional extra but runs through the relevant requirements as an organizational protective measure.
For emergencies, simple rules of conduct that are known in advance are needed. The basic rule is: In case of suspicion, do not click on links, do not open attachments, and do not enter login credentials. Instead of replying to the message itself, it is advisable to check back via a known, independent route. Above all, however, the message should be reported to the responsible IT security team. Even if someone has already reacted, for example by clicking a link or entering data, reporting immediately is the most important step to limit damage.
These rules are deliberately kept general. Each authority defines the specific reporting and emergency channels in its own requirements and security policies; they should be known to all employees and easy to find.
In addition to recognizing attacks, handling login credentials securely is one of the most effective protective measures. Long passwords that are different for each service and not easy to guess are recommended; a password manager helps to manage them without reusing them. Login credentials do not belong on sticky notes and are not passed on by email or telephone.
Wherever possible, multi-factor authentication should also be activated: In addition to the password, it requires a second proof, such as a code from an app, and thus prevents a single stolen password from being enough to take over an account. Especially in public authorities, where many employees access shared specialized applications, this additional step noticeably reduces the risk. The specific requirements are defined by the respective authority in its security policies.
Nobody recognizes every attack. That is why a functioning reporting culture is often more important than the expectation that nobody will ever fall for a scam. A simple reporting channel, such as a report button in the email program or a clear point of contact, ensures that suspicious messages quickly reach IT security. The earlier an incident is reported, the sooner damage can be limited and the better others can be warned.
What is crucial is a climate without blame: Anyone who reports a mistake must not fear any sanction. Otherwise, incidents are concealed, and a small incident turns into major damage. Reporting must become a natural part of everyday work, not an admission of failure.
A one-off training course fizzles out. Awareness only develops when awareness raising takes place regularly and is anchored in everyday work. Recurring, short learning units have proven effective, supplemented by voluntary phishing simulations in which employees practice recognizing suspicious messages without risk. It is important to design such simulations as a learning opportunity and not as a trap, so that they strengthen trust rather than damage it.
Security culture means that information security is understood as a shared task, from management to case workers. Visible support from the head of the authority, clear responsibilities, and open communication about incidents contribute significantly to turning individual measures into a lasting attitude.
Whether awareness raising works cannot be read from gut feeling. More meaningful are a few metrics tracked over time: the participation and completion rate of the training courses, the reporting rate of suspicious messages – i.e., how many are actually reported – and, in the case of voluntary phishing simulations, the development of the click and reporting rates over several runs. The perspective is important: A rising reporting rate is a good sign because it shows that employees are attentive and use the reporting channel. A falling click rate alone says little if nobody reports.
Metrics are used for management, not for sanctioning individuals. If simulation results are used to expose employees, the reporting culture suffers – and with it precisely the ability that is actually meant to be strengthened. It makes sense to evaluate results anonymously at team or authority level and to derive from them which topics should have priority in the next learning impulse.
For public authorities and municipalities, this means: Awareness is not a one-off project but an ongoing process with fixed intervals, comprehensible content, and robust proof of participation. Especially in public administration, where obligations to provide evidence and the later auditability of the documentation play a major role, documented delivery is just as important as the content. A standardized, digitally rolled-out security awareness training course that can be distributed centrally to all employees and generates comprehensible proof of participation for each person provides a practicable framework for this – provided the records are maintained and retained. A note on our own behalf: Bridgly provides such ready-made security awareness training courses for public administration. Anyone who would first like to assess whether they are affected by current security requirements will find a good introduction in the article on NIS-2 applicability. Further articles for public authorities and municipalities are collected in the Public Sector and Administration topic area.
This article provides general awareness raising and does not replace individual security-related advice. Specific protective measures and reporting and emergency processes are based on the requirements of your authority, the recommendations of the BSI and, where applicable, the applicable legal requirements. The figures cited come from the BSI's 2025 report on the state of IT security (reporting period July 2024 to June 2025), the BKA's Federal Situation Report Cybercrime 2024, and the ENISA Threat Landscape 2025; the legal classifications are based on the NIS-2 implementation act (BSIG), the GDPR, and the BDSG as well as publications by the BSI. As of May 2026.
What is the difference between phishing and social engineering?
Social engineering is the umbrella term for the targeted manipulation of people. Phishing is its most common variant and works via fake messages. Other forms include telephone attacks (vishing) and CEO fraud.
How do I recognize a phishing email?
Typical warning signs are an unexpected sender, time pressure, a request to disclose login credentials, mismatched links, and unexpected attachments. Since modern attacks are often worded without errors, what counts above all is the overall picture and, if in doubt, checking back via an independent channel.
How often should public authorities conduct awareness training?
One-off training courses have little lasting effect. Regular, short refreshers, supplemented by phishing simulations, are effective. Documented proof of participation and an established reporting culture are also important so that knowledge remains anchored in everyday work.
Are public authorities legally obliged to offer security awareness training?
There is no uniform obligation for all public authorities. For entities of the federal administration, however, awareness raising is part of the mandatory catalog of measures via the NIS-2 implementation act and Section 30 BSIG; for federal states and municipalities, state law applies. In addition, Article 32 GDPR requires appropriate organizational measures; raising awareness among and training employees is one of the recognized measures.
Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.
Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.