The proposal would move Germany beyond the traditional model in which intelligence agencies collect information, assess threats and warn the government. In certain circumstances, they could instead intervene directly in an adversary’s operation.
The reform remains under development and has not yet been adopted. Nevertheless, it points towards a broader transformation of German security policy, with potentially significant consequences for intelligence oversight, international cyber operations and private-sector cooperation.
From intelligence collection to operational action
According to a draft reviewed by Reuters, Germany intends to rewrite the legal foundations governing its domestic intelligence service and the Bundesnachrichtendienst, or BND, which is responsible for foreign intelligence.
The proposal would introduce different categories of threat, with progressively more intrusive powers becoming available as the assessed severity increases. Under the strongest conditions, intelligence services could access attackers’ systems, copy or delete information and disable tools used in campaigns attributed to foreign states.
The draft also reportedly allows targeted influence and deception measures against foreign actors. This would represent a significant expansion beyond technical cyber-defence activities and into the wider field of active intelligence operations.
Earlier versions of the planned BND reform indicate how substantial this change could become. Reporting by ARD and ZDF described proposals that would allow the foreign intelligence service to redirect malicious data flows, interfere with hostile IT infrastructure, manipulate digital assets and, in exceptional security situations, conduct sabotage against equipment or systems threatening Germany or its allies.
The exact scope may still change. The drafts reported by German media were internal working documents, and the version described in July appears to form part of a broader effort to modernise the legal framework for both domestic and foreign intelligence operations.
Germany is developing two active cyber-defence tracks
The intelligence reform should not be confused with Germany’s separate Law to Strengthen Cybersecurity, which the federal government approved in May and submitted to the Bundestag in June.
That bill focuses primarily on the Federal Office for Information Security, the Federal Criminal Police Office and the Federal Police. It would give federal authorities clearer powers to detect preparations for major attacks, interfere with malicious infrastructure and interrupt ongoing cyber operations.
German Interior Minister Alexander Dobrindt presented the bill as a transition from investigating attacks to actively disrupting the attackers’ servers, software and operational infrastructure.
Germany is therefore developing two parallel models. The first strengthens police and civilian cybersecurity authorities that investigate crime, protect federal systems and respond to major attacks. The second would make the intelligence services more operational when dealing with hostile states, espionage networks, sabotage campaigns and threats originating outside Germany.
This distinction will be important when determining which authority may act, what approval is required and whether an operation is treated as law enforcement, intelligence activity, national defence or a combination of several functions.
Why Berlin is changing its position
Germany’s intelligence services have historically operated under tighter restrictions than many comparable services in Europe and North America. Germany’s post-war security architecture was consequently designed to prevent excessive concentration of surveillance and executive power. Intelligence gathering, policing and military operations were divided among different institutions and subjected to different legal controls.
The government now argues that this model has become increasingly difficult to maintain in an environment where cyberattacks, sabotage, disinformation, espionage and military pressure are frequently combined.
German officials have repeatedly connected the reform effort with escalating hybrid threats, particularly those associated with Russia. Recent cases cited in the German debate include cyberespionage against political and military targets, suspected sabotage operations, disinformation campaigns and more than 1,000 suspicious drone flights recorded during 2025.
The government also wants German intelligence services to contribute more capabilities to international intelligence partnerships. Berlin has traditionally depended heavily on information collected by allies whose services have broader legal and operational powers. Supporters of reform argue that Germany must become a more capable contributor rather than primarily a recipient of intelligence.
Private companies could become part of the operational framework
One of the most important elements for businesses is the proposed authority to issue confidential and binding information orders.
According to the reported draft, telecommunications companies, digital platforms, transport operators and financial intermediaries could be required to provide information to intelligence authorities. Refusal could result in inspections and fines of up to €1 million.
If adopted, these provisions could place companies in a difficult position between regulatory cooperation, customer confidentiality, data-protection requirements and restrictions on disclosing government requests.
Providers of cloud infrastructure, telecommunications, online platforms, payment services and transport systems may need defined internal procedures for receiving classified or confidential orders. They would also require clear executive responsibility for validating requests, limiting access to sensitive information and documenting decisions without compromising an operation.
Cybersecurity teams may find themselves managing incidents in which law enforcement, intelligence services and internal responders have different objectives. A company may want to contain an intrusion immediately, while authorities may want to observe the attacker, collect intelligence or use the compromised environment to support a wider operation.
This creates a need for pre-established government liaison procedures rather than improvised communication during a crisis.
The central problem is attribution
Active disruption is only as reliable as the attribution on which it is based. Attackers routinely use compromised servers, residential routers, cloud services and infrastructure belonging to innocent third parties. Malicious traffic may pass through several countries before reaching its target. A system that appears to be part of a foreign intelligence operation may in fact belong to an unaware business or individual.
Interfering with such infrastructure can therefore damage third-party systems, destroy evidence or interrupt legitimate services. It may also reveal investigative methods and alert the attacker before the wider campaign has been understood.
Policy specialists have warned that active cyber-defence operations create risks of misattribution, collateral damage, overlapping institutional responsibilities and uncontrolled proliferation of offensive tools. They also note that disruption operations often delay or inconvenience sophisticated adversaries rather than permanently stopping them.
The success of Germany’s reform will consequently depend less on whether agencies receive the technical authority to intervene and more on the decision-making structure surrounding each intervention.
Oversight will determine the reform’s credibility
The reported proposal would consolidate important oversight responsibilities under an expanded Independent Control Council. The body could be required to approve the most intrusive intelligence measures in advance and review how they are subsequently implemented.
Earlier reform drafts also connected the most serious operational powers with a specially declared security situation. Under those proposals, the National Security Council would identify the situation and the Bundestag’s Parliamentary Intelligence Oversight Panel would have to approve it by a two-thirds majority.
Independent approval will be especially important because many affected individuals and organisations may never learn that an operation occurred. Traditional legal remedies are difficult when the underlying action, evidence and authorisation remain secret.
Germany’s Federal Constitutional Court has already ruled that the BND remains bound by the fundamental rights contained in the Basic Law when surveilling foreign nationals outside Germany. The court required clear legal limits, proportionality and effective independent oversight of intelligence activities and cooperation with foreign services.
New powers to alter data, disable systems or conduct covert operations will almost certainly face similar constitutional scrutiny. German civil-rights organisations have already indicated that they could challenge the reform if it permits disproportionate mass surveillance or weakens existing safeguards.
A European test case
Germany’s decision could influence the wider European debate over state action in cyberspace. Many European governments accept coordinated takedowns, domain seizures and disruption operations against ransomware groups and botnets. Direct intervention in infrastructure connected to another state is more controversial because it can raise questions of sovereignty, escalation and international responsibility.
Germany’s size, legal tradition and political influence mean that its eventual framework could become an important reference for other European countries considering similar powers.
A narrowly defined system with strong attribution standards, independent authorisation and transparent post-operation review could establish a model for controlled state intervention. A broad framework divided among competing authorities could instead increase uncertainty and operational risk.
What does it mean for business
For cybersecurity managers, the reform is not an invitation to conduct private hack-back operations. The proposed powers would remain governmental and would be exercised through authorised public institutions.
The practical impact on companies would be indirect but significant. Organisations may receive confidential requests, be asked to preserve access to compromised systems or need to coordinate incident response with several government authorities.
Businesses operating critical infrastructure, digital platforms, telecommunications, transport and financial services should therefore review who is authorised to communicate with intelligence and law-enforcement bodies. Incident-response plans should address the handling of confidential government instructions, evidence preservation and situations in which immediate remediation could conflict with an official investigation.
Legal, cybersecurity, privacy and executive teams will need to make these decisions jointly. A request connected with an intelligence operation cannot be treated as an ordinary technical support ticket.
The beginning of a strategic shift
Germany has not yet completed its move from passive cyber defence to active disruption. The intelligence reform remains a proposal, and substantial legal and political debate is likely before its final form becomes clear.
The direction, however, is already visible. Germany no longer considers monitoring, attribution and resilience sufficient responses to every major cyber threat. Its government is building a framework in which state institutions can interfere with an attacker’s systems and operations before the damage is complete.
The unresolved question is not whether Germany possesses the technical capability to act. It is whether the country can create legal thresholds, coordination mechanisms and democratic controls strong enough to ensure that these powers improve security without creating new risks of their own.
