German Audit Office Criticizes Misuse of IT Security Budget
netzpolitik.org
- The German Federal Court of Auditors (Bundesrechnungshof) has sharply criticized the government for the ineffective use of funds designated for IT security.
- At least €1.2 billion in budget exceptions originally intended for hardening IT systems was redirected toward unrelated projects, including AI research and bird-song identification apps.
- The Federal Ministry for Digital and State Modernization (BMDS) has failed to establish clear, mandatory criteria for how these funds should be allocated.
Failures in Cyber Defense Oversight
- The Federal Office for Information Security (BSI) has only audited 15 federal entities over the past four years.
- At this pace, it would take over 20 years to audit all federal agencies, a timeline deemed unacceptable given the current threat environment.
- While the government has launched the "CyberGovSecure" initiative to improve coordination, the court considers the planned 2027 timeline for full implementation to be too slow.
Deficiencies in Data Verification
- The BMDS and BSI currently rely on self-reported data from agencies to monitor the state of IT security, which the audit office considers insufficient.
- The court recommends replacing self-assessments with neutral verification procedures conducted by independent auditors to ensure reliable data.
- The BMDS has largely rejected these audit office recommendations, leaving the government without a valid basis to effectively manage and secure its IT infrastructure.