Digital Security in the Public Sector: Greater Resilience against Hybrid Attacks
How can attacks on critical infrastructure be countered? We’ll be demonstrating this at our Resilience Day and in the *Behörden Spiegel* special publication on #SCCON26.

The public sector needs to be more resilient to hybrid attacks. Source: Unsplash
With Russia’s war of aggression against Ukraine and growing geopolitical tensions, the security situation in Europe has changed fundamentally. Alongside traditional cybercrime, hybrid attacks are becoming increasingly significant. They combine, for example, cyberattacks, disinformation, espionage and sabotage with economic or military pressure. The public sector, in particular, is a strategic target. Attacks on local government, public authorities or municipal IT systems can disrupt services, jeopardise sensitive data and undermine trust in state institutions.
The public sector must prepare for crises
Even today, a successful cyberattack can significantly hamper both the public sector and the private sector. In a major crisis, several challenges could arise simultaneously: IT systems could fail, communication channels could be disrupted, supply chains could be interrupted, or staff might be temporarily unavailable. At the same time, disinformation campaigns could be used to deliberately create uncertainty.
Public authorities, local authorities and businesses should therefore not limit their contingency planning to individual cyber incidents. The crucial question is: Which public services must be delivered reliably even under difficult conditions?
Three steps towards greater resilience
• Identify critical services: Public authorities, local authorities and businesses should determine which services and processes must be prioritised in the event of a crisis, and on which IT systems, data, service providers and specialist staff they depend.
• Ensure digital operational capability: Tested backups, multi-factor authentication, up-to-date authorisation policies and recovery plans for critical systems form the basis for remaining operational even after an attack.
• Strengthen crisis management and communication: Responsibilities and line-ups must be clarified in advance, alternative communication channels tested, and contact information made available offline. Clear processes are also needed to identify disinformation and keep citizens informed.
Resilience can only be achieved through collaboration
Hybrid threats do not stop at jurisdictional or administrative boundaries. The federal government, the Länder and local authorities must therefore work together just as closely as public authorities, the business sector and operators of critical infrastructure. Shared situational awareness, practical security standards, reliable information channels and regular exercises can help ensure a faster and more coordinated response in the event of an emergency. Digital resilience thus becomes a key prerequisite for a state capable of effective action.
Resilience Day at #SCCON26 on 15 October
On the third day of the Smart Country Convention 2026, the focus will therefore be on how we can protect our economy and make it more resilient. On the Plaza Stage, representatives from industry, security authorities and the field will discuss how companies can strengthen their resilience and responsiveness and better prepare for current and future threats.
Click here for the day’s programme.
Would you like to find out more about digital security? In the special edition of *Behörden Spiegel*’s “NEUE HORIZONTE” dedicated to the Smart Country Convention, you’ll find the full article by Nemo Buschmann, as well as contributions from the Minister for Digital Affairs, Dr Karsten Wildberger, our partner country Portugal, and many other partners of the Smart Country Convention 2026.
You can register here free of charge for the pre-event magazine for #SCCON26.