12.08.2026 | 1 Image

Risk, Budget, Compliance: How Companies Prioritize Their IT Security Measures

Current study by G DATA shows: companies rely more on business relevance than on short-term threat trends when protecting their IT
G_DATA_CiZ-25-26_Visual_Motiv_09 © G DATA CyberDefense AG

"Cybersecurity in Numbers" has now been published for the fifth time and stands out for its high information density and particular methodological depth: more than 5,000 employees in Germany were surveyed as part of a representative online study on cybersecurity in both a professional and private context. Statista's experts closely accompanied the survey and, thanks to a sample size far exceeding the industry standard, are able to present robust and valid market research findings in the "Cybersecurity in Numbers" magazine. In addition, the market researchers have compiled figures, data, and facts from more than 300 statistics into a comprehensive IT security reference work.

This press release has:
Which IT security measures companies implement first depends above all on their specific needs. The protection of business-critical systems and processes plays the biggest role here. This is shown by a current study, "Cybersecurity in Numbers," from G DATA CyberDefense, Statista, and brand eins. Next in line are the potential risk of damage and the available budget for IT security. Experience from previous security incidents or expectations from customers and partners, by contrast, are of secondary importance.

Press release Plain text



Companies prioritize IT security decisions primarily around the question of which systems are especially worth protecting. But the consequences of an incident and the available budget also factor into these decisions. This is the finding of the current study "Cybersecurity in Numbers" by G DATA CyberDefense, Statista, and brand eins. Companies cannot implement all relevant IT security measures at the same time. Those responsible must therefore set priorities. The protection of business-critical systems and processes is the most important factor in prioritizing IT security measures. On average, it achieves the best score, at 2.72; companies thus direct their investments primarily toward those areas whose failure would immediately impair business operations. Almost as important are the risk and potential damage to the company. This factor achieves an average rank of 2.75. In third place is the available budget for IT security, with a score of 2.78. The lower the score, the higher the priority.

"A resilient security strategy is not built from isolated measures. Companies need a clear picture of their critical processes, well-thought-out priorities, and a realistic plan for implementation", says Andreas Lüning, co-founder and Executive Board member of G DATA CyberDefense. "What matters now is consistently aligning security measures with the greatest business risks and developing them further strategically."

Compliance and Security Strategy Shape Planning
Legal requirements and long-term security objectives also remain among the central decision-making criteria. IT security is no longer viewed solely as a technical task, but is increasingly integrated into strategic, organizational, and regulatory processes.

Experience with previous security incidents ranks at the bottom of the list. The influence of expectations from customers, partners, or regulatory authorities is even slightly lower. Yet past incidents in particular can provide important clues about vulnerabilities, unclear responsibilities, and missing processes. Companies should therefore systematically evaluate the lessons learned from security incidents and incorporate them into their security strategy. This not only helps close technical gaps but also improves reporting channels, decision-making processes, and collaboration in an emergency.

"Cybersecurity in Numbers" Available for Download
"Cybersecurity in Numbers" has now been published for the fifth time and stands out for its high information density and particular methodological depth: more than 5,000 employees in Germany were surveyed as part of a representative online study on cybersecurity in both a professional and private context. Statista's experts closely accompanied the survey and, thanks to a sample size far exceeding the industry standard, are able to present robust and valid market research findings in the "Cybersecurity in Numbers" magazine. In addition, the market researchers have compiled figures, data, and facts from more than 300 statistics into a comprehensive IT security reference work.

Click here to download "Cybersecurity in Numbers." (only in German available)

G DATA CyberDefense AG is a leading German company in the field of IT security. Since 1985, the company based in Bochum has stood for digital security “Made in Germany”.

More than 500 experts protect businesses, public authorities, and private users every day with modular solutions that seamlessly combine software and services:

  • Managed Extended Detection and Response (MXDR)
  • Endpoint Security for Businesses
  • Security Awareness Training
  • IT security services such as penetration testing, incident response, and forensic analysis

Transparency, data protection, and digital sovereignty are the cornerstones of the company’s security strategy. For this reason, G DATA develops and operates its solutions in Germany. With its no-backdoor guarantee and ISO 27001 certification, the company helps businesses and organizations meet regulatory requirements. In doing so, G DATA lays the foundation for CyberVertrauen and a secure, resilient future.

G DATA. Trust in German Sicherheit.

All contents of this press release as .zip:

Direct download

Release text 3378 Characters

Plain text Copy release text

Images (1)

G_DATA_CiZ-25-26_Visual_Motiv_09
8 390 x 6 061 © G DATA CyberDefense AG


Contact

(3) Stefan Karpenstein
Stefan Karpenstein
Public Relations Manager

+49 234 9762 - 517
stefan.karpenstein@gdata.de