G DATA study shows: Management rates the IT department most highly, but also sees the greatest need for action
A high-performing IT department forms the basis for effective cyber defence. Seven out of ten employees believe their IT department is well positioned when it comes to IT security. This is shown by the representative study “Cybersecurity in Numbers” by G DATA CyberDefense, Statista and brand eins. One striking finding is that assessments of IT security vary depending on the department.

A comprehensive IT security strategy requires budget, specialised expertise and personnel. Almost two-thirds of employees in Germany believe that their IT department is equipped to meet the current requirements for effective IT security. This is shown by the study “Cybersecurity in Numbers” by G DATA CyberDefense, Statista and brand eins. However, one quarter (23 percent) of employees in Germany also believe that their company is only partially well protected and has vulnerabilities. Only seven percent cite security gaps and inadequate cybersecurity as a high risk. Overall, the results reveal a high level of trust in the IT departments of German companies. Behind this strong trust, however, lies a reality in which IT departments have to cope with increasingly complex security requirements while working with limited resources. Strong IT alone is not enough. There is also a risk that cybersecurity is viewed solely as the responsibility of IT rather than as a company-wide task.
“70 percent of employees trust their IT department – a strong signal, but with NIS 2 the issue has finally become a matter for senior management,” says Andreas Lüning, co-founder and Executive Board member at G DATA CyberDefense AG.
“Effective protection is only possible when management and specialist departments take joint responsibility. Companies should now use this momentum to adapt their strategy to the new regulatory requirements.”Perceptions of cybersecurity depend on the role within the companyOne striking finding is that the assessment of the IT department varies across departments within a company. Trust is particularly high among management and legal departments, at 82 percent. At the same time, management also sees the greatest deficit of all departments in the implementation of effective IT security, at eight percent. This is consistent with the growing responsibility of company management resulting from regulatory requirements such as NIS 2.
The assessment in human resources is considerably more critical (70 percent). One reason is that HR departments are regularly confronted with phishing messages, fake applications or social engineering attacks. IT departments themselves rate the situation as positive overall (81 percent). This provides companies with a good starting point. However, to keep pace with the challenging threat landscape, they should regularly review their IT security strategy. IT security is not a finished process: new technologies, attack methods and regulatory requirements call for the continuous development of protective measures.
Cybersecurity in Numbers“Cybersecurity in Numbers” has now been published for the fifth time and stands out for its high information density and particular methodological depth: More than 5,000 employees in Germany were surveyed as part of a representative online study on cybersecurity in both professional and private contexts. Statista experts closely supported the survey and, thanks to a sample size well above the industry standard, are able to present robust and valid market research results in the “Cybersecurity in Numbers” magazine. In addition, the market researchers have compiled figures, data and facts from more than 300 statistics into a comprehensive reference work on IT security.