Why security in critical infrastructure is a people question
Substations, airports, power cables: in the first nine months of 2026 the threat to Germany’s critical infrastructure has moved from specialist topic to headline. We have seen the pattern for years: outcry, activism, silence. This article shows why resilience does not fail on technology but on missing decision-makers, missing budgets and missing people.
“It cannot be that a plane has to explode first before the last sleepyheads wake up.” The sentence comes from Albrecht Broemme, for 14 years Berlin’s chief fire officer and for 13 years president of the Federal Agency for Technical Relief (THW). He said it in an interview with the Frankfurter Allgemeine Zeitung on 4 September 2026. Broemme is certainly no alarmist. He knows where Germany is vulnerable – and, by his own account, could take the capital off the grid for four weeks with a handful of sawn-through pylons.
You do not have to follow him on every point to see that he is right about the pattern.
Chronicle of a wake-up call foretold
The tally of the past months alone reads like a situation report that would have been dismissed as exaggerated two years ago. On 3 January 2026 an arson attack on a cable bridge in Berlin-Lichterfelde destroyed five 110 kV and ten 10 kV cables. Around 40,000 households, more than 2,000 businesses, care homes, hospitals and schools were without electricity and heating until 7 January – the longest power outage in the city since 1945. Broemme does the maths: two per cent of Berliners were affected. Twenty per cent of the police and fifty per cent of the fire service were deployed.
In early August 2026 a drone fitted with explosives was discovered at Leipzig/Halle airport near Ukrainian cargo aircraft. On 2 September the Federal Government officially held Russia responsible; Interior Minister Dobrindt spoke of “low-level agents” acting on Moscow’s behalf. On 1 September a double-digit number of home-made explosive and incendiary devices was found at the Turnow-Preilack substation near Jänschwalde. At least one of them detonated. Brandenburg’s Interior Minister Redmann: “Those were most certainly not New Year’s Eve rockets.” The same day: Bergheim near Cologne. On 2 September: an attempted sabotage at the Dormagen-Gohr substation – discovered by a passer-by out for a walk.
A passer-by. Not a sensor, not a patrol, not a security concept. Anyone who still believes after this year that Germany prevented worse thanks to good preparation has not read the news. We were lucky – or, as Broemme puts it, the perpetrators were “often too stupid to do more damage”. Nobody should build a security architecture on either.
Since 2023 the Federal Office for the Protection of the Constitution has described a new quality: sabotage on behalf of foreign intelligence services, carried out by disposable agents recruited at little cost via messenger apps. Their aim is not only physical damage but also insecurity and the overloading of the security authorities. As of 1 March 2026 the Federal Public Prosecutor was conducting twenty proceedings against 23 suspects in the field of espionage and sabotage.
The reflex we know
As an executive search firm we have been working intensively on security functions in critical infrastructure for years. And we know the cycle. When it became known in July 2024 that Western services had foiled Russian plans to attack Rheinmetall CEO Armin Papperger, something moved. Suddenly boards were talking about security – not about the man at the factory gate, but about networked corporate security: executive protection, travel security, site security, IT, crisis communication, public perception and an exchange on equal terms with the authorities that work openly and covertly in this field. A few months later the interest had ebbed away. The job market for these profiles had relaxed. So had the enquiries.
It will be interesting to see how long the current wake-up call lasts.
Bigger than the headlines
The circle of those affected is far larger than the news suggests. Energy suppliers, airports and railways are only the visible tip. Critical infrastructure also includes hospitals, drinking-water suppliers, telecommunications networks, remote energy parks, data centres, logistics hubs and waste-disposal operators. Many of them are publicly or municipally owned – and financially anything but comfortable. According to the 2026 municipal utilities study by EY and BDEW, only 47 per cent of municipal utilities still rate their business performance as good or very good; four years ago it was 75 per cent. Ninety per cent expect significantly higher investment, a quarter an increase of more than 200 per cent. Security rarely ranks high in these calculations.
The KRITIS Umbrella Act, in force since 17 March 2026, points in the right direction: mandatory registration since 17 July, risk analyses, resilience plans, a 24-hour reporting obligation, fines of up to one million euros. But the standard threshold of 500,000 people supplied leaves a substantial share of operators outside its scope. The Bundesrat had recommended 150,000. The Federal Government declined. Broemme’s verdict: “not consistent enough”. Ours: whoever lies below the threshold is not less vulnerable for it – only less obliged.
The anecdote that explains everything
Some time ago we sat down with a public-sector institution. The subject was a security-critical key position. In the first meeting it quickly became clear that nobody at the table could put a figure on the budget. Instead, we were facing three representatives of the staff council. Nothing against co-determination – it belongs at the table. But not alone and not first. Anyone who wants to build a security function strategically needs someone in the very first conversation who can decide. The management. Otherwise a positioning turns into a set of minutes.
This is exactly the problem that no law solves.
They exist – the people
The good news: Germany has a remarkable number of very well-trained people in this field. They come from the Bundeswehr, the police, the intelligence services, the THW, the fire services, corporate security departments and the security industry. Some are looking for their next step. They want to contribute their expertise not only operationally but strategically: designing security architectures, building situational awareness, maintaining contacts with the authorities, preparing decisions and standing behind them. Broemme calls for “Chief Resilience Officers” at state-secretary level in the federal and state governments. We call for the counterpart in companies, associations and public institutions: security and resilience leaders with a mandate, a budget and a direct line to the top.
That costs money. Yes. Broemme on this: “Power outages cost much, much more. And human lives are priceless.” Four days without electricity in south-west Berlin have done the maths.
What needs to happen now
First: make security a matter for the top, not a staff position with official channels. Second: think in networks – sites, people, travel, IT, communication, authorities. Third: budget before the first tender is written. Fourth: bring the right people on board while they are available – and not only when the next passer-by finds something.
We help with that. Personally, confidentially, with an eye for values and fit. Because the question is not whether the next attack comes, but who prevents it.
Talk to us. connect@focus-defence.de · +49 30 5444 5899
Sources
F.A.Z., interview with Albrecht Broemme (4 Sept 2026) · tagesschau.de / NDR / WDR on Leipzig and Jänschwalde · ZDFheute on Dormagen and Jänschwalde · Wikipedia “Brandanschlag auf das Berliner Stromnetz 2026” · Federal Office for the Protection of the Constitution, situation report on Russian sabotage · Tagesspiegel on Federal Public Prosecutor proceedings · KRITIS Umbrella Act (Federal Law Gazette, 16 March 2026) · Municipal utilities study 2026 (EY/BDEW) · CNN/ZDF on the Papperger plot 2024
