
Sector
Data Centres & Telecommunications
Data centres, networks, and telecommunications services form the foundation on which banks, public authorities, energy suppliers, and healthcare systems operate. NIS2, the amended Telecommunications Act (TKG), and the KRITIS umbrella act (KRITIS-Dachgesetz) unite cybersecurity, network security, and physical resilience into a single obligation — from the control layer down to the fibre in the ground and the submarine cables on the seabed. These requirements are integrated across all levels into a robust security architecture.
Overview
A Sector in Transition
Germany is Europe's largest data centre location. Approximately 2,000 data centres with more than 50 kW of connected capacity are operating in the country, alongside tens of thousands of smaller corporate IT installations.[1] The market is growing, driven by cloud computing and artificial intelligence — installed IT connected capacity rose in 2025 to nearly 3,000 MW, with electricity consumption exceeding 21 billion kilowatt-hours.[2] This infrastructure underpins virtually everything else: payment systems, government portals, clinical IT, and the control of energy and water networks all ultimately run across the same servers, networks, and exchange points.
The degree of concentration is striking. More than one third of Germany's data centre capacity is located in the Frankfurt/Rhein-Main region alone, home to DE-CIX, one of the world's largest internet exchange points.[3] What makes economic sense — short distances, dense interconnection, shared connectivity — represents a concentration risk from a security perspective: where a great deal converges in one place, a single disruption carries significant leverage. Telecommunications forms the second pillar. Fixed-line networks, mobile networks, fibre, and international submarine cables together constitute the nervous system through which these data centres are reachable at all. When connectivity fails, even the most powerful computing capacity is rendered useless.
The Threat Landscape
Incidents over recent years reveal three distinct attack surfaces — and they strike the sector at precisely the points where availability matters most. The first is the conventional cyber layer. In November 2016, a variant of the Mirai botnet exploited a vulnerability in the remote management protocol TR-069 to crash approximately 900,000 Deutsche Telekom routers; hundreds of thousands of customers lost internet, telephone, and television services.[4] In September 2020, NetWalker ransomware struck Equinix, the world's largest colocation operator, encrypting internal systems; customer-facing operations remained stable, but the attackers demanded USD 4.5 million.[5] In January 2024, Akira ransomware paralysed a Swedish data centre operated by Tietoevry, bringing down numerous customers ranging from retailers to universities.[6]
The second attack surface is physical — and it is frequently underestimated. In October 2022, unknown actors severed the fibre cables of the railway radio system GSM-R at two mutually redundant locations, near Herne and in Berlin-Karow. Because both lines were struck simultaneously, rail traffic in northern Germany was completely suspended for nearly three hours.[7] The case is instructive because the attack presupposed insider knowledge of the network's redundancy architecture — redundancy only provides protection when the secondary line does not share the same vulnerability. A further layer down lie the submarine cables. In November 2024, two Baltic Sea data cables were damaged within 24 hours, including C-Lion1 between Finland and Germany; in February 2025, C-Lion1 was damaged again.[8] Federal ministers spoke openly of sabotage and hybrid warfare. Germany's connectivity to the international network is directly affected.
The third attack surface is the supply chain. In May 2023, attackers gained access to the Munich data centre of Bitmarck — a central IT service provider for numerous statutory health insurers — using an employee's credentials; as a result, millions of insured persons were indirectly affected.[9] In July 2024, a defective update to the CrowdStrike security software demonstrated the reach of a single error: Windows systems failed globally; in Germany, those affected included Berlin Brandenburg Airport (BER) and the University Medical Centre Schleswig-Holstein, which cancelled all non-urgent surgical procedures.[10] It was not an attack but a software defect — and that is precisely what makes the case so significant: dependence on a small number of global providers for cloud services and security software is itself a systemic risk.
The sector's susceptibility to outages even without hostile actors is borne out by the data. According to the Uptime Institute, 55 per cent of all organisations reported at least one data centre outage in the preceding three years; approximately 54 per cent of serious outages in 2024 were attributable to power distribution failures.[11] The fire at OVHcloud's Strasbourg data centre SBG2 in March 2021 illustrated this vividly: approximately 14,000 servers were destroyed, around 3.6 million websites went offline — and customers who had stored their backups in the same data centre lost those as well.[12]
The Regulatory Forces Shaping the Sector
Three regulatory frameworks interact here. The NIS2 Implementation Act, adopted by the Bundestag in November 2025 and incorporated into the BSI Act, expressly assigns Digital Infrastructure to the regulated sectors and expands the number of entities subject to the legislation nationwide from a few thousand to approximately 29,500. Data centre and cloud operators are classified, depending on their size, as important or particularly important facilities, with obligations covering risk management, intrusion detection, and incident reporting. Significant incidents must be reported within 24 hours, with a follow-up report due within 72 hours; violations carry fines of up to EUR 10 million or 2 per cent of global annual turnover.[13]
Telecommunications is subject to an additional dedicated framework. Sections 165 et seq. of the Telecommunications Act (TKG) require network and service operators to implement technical protective measures and to submit a security concept to the Federal Network Agency (Bundesnetzagentur); the Agency's security catalogue specifies the required measures and has been more closely aligned with NIS2 since late 2025, including a requirement for intrusion detection systems.[14] The third track is physical. The KRITIS umbrella act (KRITIS-Dachgesetz), in force since March 2026 and transposing the European CER Directive (EU 2022/2557), establishes the physical resilience of critical installations as a standalone obligation for the first time — encompassing risk analysis, a resilience plan, notification requirements for physical disruptions, and personal liability for senior management. Digital infrastructure is expressly included as a covered sector.[15]
Alongside these frameworks, a regulatory regime that does not primarily target security nevertheless shapes operations: the Energy Efficiency Act (EnEfG) requires data centres with a connected capacity of 300 kW or more to meet minimum energy efficiency values (PUE), use electricity from renewable sources, and implement waste heat recovery, among other obligations.[16] The technical framework for availability and security is set by standards. The European EN 50600 and its international successor ISO/IEC 22237 define availability classes ranging from basic configuration to fault-tolerant full redundancy; in the US-derived TIA-942 model, these correspond to the familiar Tier I through Tier IV classifications.[17] For information security, ISO/IEC 27001 provides the management framework to which regulators consistently refer.
Where the Critical Risks Reside
The most intractable risks rarely reside in a single domain. They arise at the interfaces — where cybersecurity, physical security, power supply, and external service providers converge and are, in practice, frequently managed in separate accountability silos. Within the data centre, this is most apparent in power distribution: it is statistically the most common cause of outages, and the OVHcloud fire together with repeated power failures at individual sites demonstrate that even emergency power and redundancy concepts can fail when they are not designed with strict mutual independence. A backup housed in the same fire compartment is no backup at all.
In telecommunications, risk shifts outward — across wide geographic areas and beneath the water's surface. Fibre routes, cable ducts, and submarine cables cannot realistically be protected end-to-end over large distances; the decisive lever therefore lies in genuine, geographically and physically separated redundancy and in the speed with which a severed route can be detected and rerouted. Overarching all of this is concentration: a small number of major cloud providers, a small number of security software vendors, a small number of exchange points and data centre regions carry the bulk of the digital load. This bundling creates efficiency and simultaneously creates systemic dependency — when a central element fails, many are affected at once. The technical countermeasure is Defence in Depth: layered, mutually independent protective strata on the onion-shell principle, rigorous network segmentation, zone-and-conduit models, and the Zero Trust principle — no implicit trust granted automatically, whether to users, connections, or service providers. Standards such as ISO/IEC 27001 and the EN 50600 family set the technical framework; they specify what regulation demands — but they do not substitute for the architecture that holds cyber, physical security, and operations together.
Sources
[1] ~2,000 data centres > 50 kW, tens of thousands of smaller IT installations (Nov. 2025) — Bitkom · BMWK Data Centre Location
[2] IT connected capacity 2025 ~2,980 MW, electricity consumption 21.3 bn kWh — Bitkom
[3] Frankfurt/Rhein-Main >1/3 of German data centre capacity, DE-CIX one of the largest internet exchange points — Borderstep Institut · DE-CIX Annual Report 2024
[4] Telekom Mirai botnet (Nov. 2016): ~900,000 routers offline, TR-069 vulnerability — Süddeutsche Zeitung · Sophos News
[5] Equinix NetWalker ransomware (Sept. 2020): internal systems encrypted, USD 4.5 million demanded, operations stable — SecurityWeek · Equinix SEC 8-K
[6] Tietoevry Akira ransomware (Jan. 2024): Swedish data centre paralysed, numerous customers affected — Borns IT-Blog
[7] German rail GSM-R fibre sabotage (Oct. 2022): two redundant lines severed, ~3 hours standstill, insider knowledge — Wikipedia (DE) · Golem.de
[8] Baltic Sea submarine cables: C-Lion1 (FIN–DEU) + BCS East-West Interlink (Nov. 2024), C-Lion1 again (Feb. 2025) — Wikipedia (EN) · BAKS
[9] Bitmarck (May 2023): health insurer IT service provider compromised via stolen credentials, millions of insured persons indirectly affected — smart-datacenter.de
[10] CrowdStrike defective update (July 2024): global Windows outage, in Germany including BER airport and UKSH, not a cyberattack — Heise Online · Wikipedia
[11] Uptime Institute Global Data Center Survey 2024: 55% at least one outage in 3 years, 54% due to power distribution — Uptime Institute 2024 (PDF) · Computer Weekly DE
[12] OVHcloud Strasbourg fire (March 2021): SBG2 destroyed, ~14,000 servers, ~3.6 million websites offline, backups lost — Golem.de · DataCenter Dynamics
[13] NIS2 Implementation Act (Bundestag Nov. 2025): Digital Infrastructure covered, ~29,500 entities, 24h/72h, fines up to EUR 10 million / 2% — BSI Press Release · openkritis.de
[14] TKG §§ 165 et seq., security concept with BNetzA, security catalogue with intrusion detection, closer NIS2 alignment — BNetzA Security Requirements · openkritis.de
[15] KRITIS umbrella act (KRITIS-Dachgesetz) (in force March 2026), CER Directive (EU) 2022/2557, Digital Infrastructure covered, senior management liability — GÖRG Rechtsanwälte · openkritis.de
[16] Energy Efficiency Act (EnEfG, from Nov. 2023): data centres from 300 kW, PUE limits, renewables, waste heat recovery — TÜV Rheinland Consulting · Germandatacenters.com
[17] Availability classes EN 50600 / ISO/IEC 22237 and TIA-942 (Tier I–IV) — DataCenter-Insider · KI365 (TIA-942)

