Skip to content

16 June 2026 | 12 min

Cyber Europe 2026: Why Cyber Resilience Is Becoming a Management Priority

Cyber Europe 2026 was the eighth major European cyber crisis exercise organised by the European Union Agency for Cybersecurity, ENISA. The exercise took place on 10 and 11 June 2026 and tested how well Europe can respond in a coordinated way to large-scale cyber incidents.

The focus was on the railway and maritime sectors. The exercise simulated the handling of parallel cyber incidents affecting critical transport and logistics infrastructure. It was not only about technical defence, but also about crisis coordination, business continuity, communication with authorities, situational awareness, decision-making processes and the continuity of essential services.

Participants included European authorities, national cybersecurity bodies, operators of critical infrastructure and other organisations from the European cyber ecosystem. Switzerland also took part. Under the lead of the Federal Office for Cybersecurity, BACS, various national and cantonal authorities as well as operators of critical infrastructure participated in the exercise.

For companies, Cyber Europe 2026 sends an important signal: cyber resilience is no longer measured only by the existence of security policies. What matters is whether organisations can remain operational during an incident, make clear decisions, coordinate their response and document their actions in a reliable way.

Cyber Europe 2026 was a Europe-wide cyber crisis exercise organised by ENISA, with a focus on railway and maritime transport.

The exercise tested responses to parallel cyber incidents, coordination between authorities and operators, and the ability to maintain essential services.

Switzerland participated under the lead of BACS. National and cantonal authorities as well as operators of critical infrastructure were involved.

For companies, the exercise shows that cyber resilience goes far beyond IT security. Incident response, business continuity management, crisis communication, vendor management and management responsibility must work together.

In the context of NIS2, critical infrastructure and rising cyber risks, operational evidence is becoming increasingly important. Companies must not only plan, but also exercise, document and improve.

What Is Cyber Europe 2026?

Cyber Europe is a regular European cyber crisis exercise organised by ENISA. It brings together authorities, critical sectors and cybersecurity organisations. The goal is to simulate realistic cyber crises and test how well collaboration, escalation and crisis response work in practice.

Cyber Europe 2026 focused on transport networks, especially rail and maritime infrastructure. Both sectors are highly connected, internationally dependent and essential for the economy, supply chains and mobility. A cyberattack on such infrastructure can have consequences far beyond a single company.

For this reason, the exercise was not designed as an isolated technical test. It aimed to show how organisations work together under pressure, exchange information, make decisions and keep operations as stable as possible.

What Was Tested During Cyber Europe 2026?

The exercise centred on several parallel cyber incidents. Such scenarios are particularly demanding because they put organisations under pressure at the technical, operational and strategic levels at the same time.

The exercise tested, among other things, how quickly incidents are detected and assessed, how information flows between the parties involved, how crisis teams make decisions and how essential services can be maintained despite cyberattacks.

Business continuity was also a key element. A cyber incident is not just an IT problem when timetables, logistics processes, port operations, communication systems or safety-related operational processes are affected. Companies need to know which processes are critical, which dependencies exist and which alternatives are available in an emergency.

Another focus was coordination. Cyber crises can quickly cross organisational and national boundaries. Operators, service providers, authorities, regulators, crisis teams and communication teams must work together under time pressure. In real crises, these interfaces are often the biggest weakness.

Why the Railway and Maritime Sectors Were in Focus

Railway and maritime transport are central components of European mobility and supply chains. They connect passenger transport, goods flows, ports, industry, energy supply and international trade routes.

At the same time, these sectors are becoming increasingly digital. Operational control systems, communication networks, booking platforms, port management, logistics data, sensors and automated processes increase efficiency, but also create new attack surfaces.

A successful cyberattack can therefore have far-reaching consequences. It can delay supply chains, disrupt passenger transport, increase safety risks and damage public trust.

Cyber Europe 2026 therefore illustrates a challenge that applies to many critical sectors: the more connected organisations become, the more important robust cyber resilience, clear responsibilities and tested crisis processes become.

Why Switzerland’s Participation Matters

Switzerland participated in Cyber Europe 2026 and tested its cyber resilience in the railway and maritime sectors. The exercise was led in Switzerland by the Federal Office for Cybersecurity, BACS. National and cantonal authorities as well as operators of critical infrastructure were involved.

This is relevant for two reasons. First, cyber risks are cross-border by nature. Even though Switzerland is not a member of the EU, it is closely connected to European transport, energy, financial and supply chains. An incident in a neighbouring country can affect Swiss organisations, and vice versa.

Second, Switzerland’s participation shows that cyber resilience is not only a matter for national authorities. It is created through cooperation between the state, the private sector, critical operators and specialised service providers. In major incidents, it matters whether this cooperation has already been tested.

For Swiss companies, the message is clear: cyber crises must not only be prepared for technically. They require crisis leadership, reporting channels, roles, supplier contacts, recovery plans and documented decision-making processes.

Cyber Europe 2026 and NIS2: What Companies Should Take Away

Cyber Europe 2026 fits directly into current developments around NIS2. The directive strengthens requirements for cybersecurity, risk management, incident reporting and management responsibility in important and essential entities.

The exercise shows what matters in practice. Companies must not only meet requirements, but also demonstrate that their processes work during an actual incident. This is especially relevant for incident response, business continuity management, crisis communication and the management of external dependencies.

NIS2 is becoming increasingly operational. A policy alone is not enough. A company must know who makes decisions during an incident, which systems are critical, which service providers need to be involved, which reporting deadlines apply and which evidence must be available afterwards.

Cyber Europe 2026 makes one thing clear: cybersecurity readiness must be exercised. Only then can companies see whether roles are clear, escalation paths work and measures are effective in practice.

Why Cyber Resilience Is More Than IT Security

Cyber resilience describes an organisation’s ability to prevent, detect, manage and recover from cyber incidents. This goes far beyond traditional IT security.

Technical protection measures remain important. But during a crisis, organisational factors are just as decisive. These include clear responsibilities, fast decision-making, crisis communication, emergency processes, supplier coordination and the ability to continue critical business processes.

A company can be technically well positioned and still fail during a crisis if it is unclear who decides, who communicates or which systems need to be restored first.

Conversely, an organisation with strong governance can respond faster, limit damage and learn from incidents. Cyber resilience is therefore a management topic and a central part of modern GRC structures.

The Role of Business Continuity Management

Business continuity management, or BCM, plays a central role in cyber crises. It answers the question of how critical processes can continue when systems, service providers or locations fail.

Cyber Europe 2026 shows that BCM should not be viewed separately from cybersecurity. A cyber incident can disrupt business processes just as severely as a natural disaster, power outage or supply chain disruption.

Companies should therefore review whether their BCM plans are realistic from a cyber perspective. Are recovery priorities defined? Are critical processes known? Are dependencies on service providers documented? Are alternative communication channels available? Have crisis roles been tested?

BCM proves its value not on paper, but in exercises. Companies that regularly simulate cyber crises identify weaknesses before a real incident exposes them.

Incident Response: From Plan to Tested Reaction

Many companies have incident response plans. The decisive question is whether these plans work under pressure.

Cyber Europe 2026 shows that incident response is dynamic. Information is incomplete, decisions must be made quickly and multiple stakeholders are involved at the same time. This is why a static process document is not enough.

Effective incident response requires clear roles, defined escalation levels, communication rules, technical analysis capabilities and links to management, legal, data protection, communications and business departments.

Post-incident review is just as important. Every incident and every exercise should be documented and evaluated. Which decisions were made? Which measures worked? Where were there delays? Which controls need to be improved?

This turns incident response into a continuous improvement process.

Suppliers and External Dependencies as a Risk Factor

Cyber crises rarely affect only one organisation. Many critical processes depend on IT service providers, cloud providers, software vendors, network operators, logistics partners or specialised platforms.

Such dependencies are particularly important in the railway and maritime sectors. But the same principle applies in other industries: companies that do not know their critical third parties will struggle to respond quickly and effectively during an incident.

Companies should therefore know which service providers are relevant for critical processes, which contact and escalation channels exist, which contractual obligations apply and which evidence is available.

Vendor risk management is becoming a permanent part of cyber resilience. It is not enough to assess suppliers once. Dependencies must be monitored continuously and included in crisis exercises.

Why Evidence and Documentation Are Critical

After a cyber crisis, it is not only important what was done. It is also important whether the company can show what was done in a reliable and traceable way.

Documentation is therefore not an administrative side issue. It is central for audits, regulatory inquiries, internal lessons learned, insurance claims, customer communication and possible legal assessments.

In an emergency, companies must be able to trace when an incident was detected, who was informed, which decisions were made, which measures were implemented and which systems were affected.

Cyber Europe 2026 shows that evidence is part of resilience. Companies that cannot document their response will later struggle to demonstrate effectiveness, due care and improvement.

What Companies Should Do Now

Companies should use Cyber Europe 2026 as an opportunity to review their own crisis readiness. The most important step is an honest assessment of the current state.

Are critical processes known? Are incident response plans up to date? Are roles and escalation paths clear? Have crisis exercises been conducted? Are suppliers integrated into emergency processes? Is there a connection between cybersecurity, BCM, risk management and management reporting?

Tabletop exercises are particularly useful. They allow organisations to run through a realistic crisis scenario without affecting production systems. Such exercises quickly show whether responsibilities are clear and whether decision-making paths work.

Companies should also review their evidence management. Risks, controls, measures, incidents, exercises and lessons learned should not be scattered across individual files, but managed in a structured way.

Common Weaknesses in Cyber Crises

Many organisations underestimate organisational weaknesses. In practice, crisis response rarely fails only because of missing technology. More often, the problem lies in unclear responsibilities, outdated contact lists, slow escalation, incomplete situational awareness or inconsistent communication.

Another weakness is the separation of IT and business processes. If technical teams do not know which processes are business-critical, recovery priorities may be set incorrectly.

External dependencies are also often considered too late. If a critical service provider cannot be reached or contractual reporting channels are unclear, the company loses valuable time.

Cyber Europe 2026 therefore shows that resilience is not created by individual measures. It is created through the interaction of people, processes, technology, governance and practice.

Conclusion

Cyber Europe 2026 was an important practical test of Europe’s cyber resilience. The focus was on railway and maritime transport, two sectors whose disruption can have far-reaching consequences for mobility, supply chains and public safety.

The exercise clearly shows that cybersecurity is no longer a purely technical task. Companies must be able to manage cyber incidents organisationally, operationally and strategically. This includes incident response, business continuity management, crisis communication, vendor management, management responsibility and reliable evidence.

For companies in Europe and Switzerland, the most important lesson is this: cyber resilience must be exercised. Plans, policies and controls are necessary, but only realistic exercises show whether they work in practice.

Cyber Europe 2026 is not just an isolated public-sector event. It is a clear signal to all organisations: the next stage of cybersecurity is operational resilience.

FAQ on Cyber Europe 2026

What is Cyber Europe 2026?

Cyber Europe 2026 was a Europe-wide cyber crisis exercise organised by ENISA. Its goal was to test Europe’s collective response capability during major cyber incidents and strengthen the cyber resilience of essential services.

When did Cyber Europe 2026 take place?

Cyber Europe 2026 took place on 10 and 11 June 2026.

Which sectors were in focus?

The exercise focused on the railway and maritime sectors. It tested the handling of cyber incidents that could affect transport and logistics infrastructure.

Did Switzerland participate in Cyber Europe 2026?

Yes. Switzerland participated under the lead of the Federal Office for Cybersecurity, BACS. National and cantonal authorities as well as operators of critical infrastructure were involved.

What was tested during Cyber Europe 2026?

The exercise tested incident response, crisis coordination, business continuity, information exchange, communication with authorities and the ability to maintain essential services despite cyber incidents.

Why is Cyber Europe 2026 relevant for companies?

The exercise shows that cyber resilience does not depend only on technical security measures. Companies must also be organisationally prepared, have clear roles, coordinate incidents and document their response.

What does Cyber Europe 2026 have to do with NIS2?

NIS2 strengthens requirements for cybersecurity, risk management, incident reporting and management responsibility. Cyber Europe 2026 shows in practical terms why these capabilities are essential in realistic crisis scenarios.

Why does business continuity management play such an important role?

Cyber incidents can interrupt critical business processes. Business continuity management helps companies maintain essential processes even during system outages, attacks or supplier disruptions.

What should companies do after Cyber Europe 2026?

Companies should review their incident response plans, BCM processes, crisis roles, supplier dependencies and evidence management. Regular tabletop exercises and realistic crisis simulations are especially valuable.

What is the main lesson from Cyber Europe 2026?

The main lesson is that cyber resilience is not created by policies alone. Companies must exercise their crisis capabilities, clarify responsibilities, understand dependencies and act in a traceable way during an incident.

Related posts

21 April 2026 | 13 min

NIS 2: Why Germany Is Falling Behind

NIS-2 has been enforceable law in Germany since December 2025. No transition period, no grace period, no exceptions. Around 29,500 companies across 18 sectors are required to implement risk management, report security incidents, and register with the BSI. And yet: at the 21st German IT Security Congress of the Federal Office for Information Security, the BSI was forced to admit that implementation is falling far short of expectations. Registration numbers are disappointing, awareness of the directive is alarmingly low, and a significant number of affected companies have made a deliberate choice not to register at all.

What is driving this? And more importantly: how can companies finally clear the compliance hurdle without overstretching their operational resources? The answer lies, to a large degree, in modern GRC software solutions.

  • According to the BSI, nearly half of all German companies had never heard of NIS-2 by the end of 2024.
  • The NIS-2 Implementation Act has been in force since December 6, 2025, with no transition period. The BSI registration deadline expired on March 6, 2026.
  • The main reasons for non-compliance: lack of awareness, perceived complexity, resource constraints, and a deliberate wait-and-see approach.
  • Non-compliance can result in fines of up to 10 million euros or 2% of global annual turnover.
  • Managing directors and executives face personal liability for meeting cybersecurity obligations.
  • GRC software demonstrably reduces implementation effort by up to 40–50% and delivers structure, automation, and audit-readiness in a single tool.

The Wake-Up Call from the BSI Congress: Germany Is Asleep at the Wheel

At the 21st BSI Security Congress, Manuel Bach of the BSI’s Cybersecurity in Business division spoke plainly: registration numbers in the BSI’s reporting portal remain well below expectations. Worse still, the BSI is aware of companies that — after consulting their legal counsel — have made a conscious decision not to register, hoping to stay below the radar.

And then came perhaps the most alarming statistic: nearly half of all German companies had never heard the term “NIS-2” at the time of a BSI study conducted at the end of 2024. Not unfamiliar as an obligation — simply unknown as a concept.

Younes Ahmadzei, who examined NIS-2 implementation in German SMEs as part of his bachelor’s thesis at the Technical University of Munich, painted a similar picture: many of the companies he surveyed had only begun engaging seriously with the topic at the start of 2026 — after the law had already come into force without a transition period. And even those who are aware of the directive often doubt whether implementing it would actually improve their company’s IT security. NIS-2 is being perceived as a bureaucratic checkbox exercise, not as a strategic opportunity.

This finding is alarming — and, at the same time, entirely explainable.

Why So Many Companies Are Ignoring NIS-2: The Five Biggest Barriers

1. Lack of Awareness and Uncertainty About Being Affected

The first and most fundamental reason is simply a lack of awareness. Many companies do not know that NIS-2 applies to them. The directive has dramatically expanded the circle of organizations under obligation: from around 4,500 companies under the old NIS directive to more than 29,500 in Germany alone. Now covered are mid-sized companies across 18 sectors — including energy, transport, healthcare, manufacturing, digital services, financial services, and public administration.

As a general rule: companies with at least 50 employees or more than 10 million euros in annual revenue may fall within scope. Those who do not actively ask whether this applies to their organization risk overlooking their own legal obligations.

2. The Perceived Complexity of the Regulatory Framework

NIS-2 is complex. Germany attempted to address multiple regulatory challenges simultaneously within a single piece of legislation — the result is a layered rulebook that even experts find challenging. For many mid-sized businesses, the legal text feels abstract and difficult to translate into concrete operational measures.

According to the study “Cybersecurity & Digital Resilience 2026,” 47 percent of surveyed companies rate the implementation of NIS-2 as difficult or very difficult. The most commonly cited barriers — each named by around 39 percent of respondents — are the high effort required to adapt processes and policies, and the sheer complexity of the requirements themselves. A further third cite unclear regulatory guidance and integration challenges with existing IT systems.

Governance obligations, risk management, incident response, supplier assessments — many of these requirements feel as though they were written for large corporations with dedicated compliance teams. For a mechanical engineering firm with 80 employees in southern Germany, the reality looks very different.

3. Resource Constraints in SMEs

Large companies have dedicated IT departments, security teams, and in-house compliance expertise. Small and medium-sized enterprises — precisely the group that NIS-2 brings into scope for the first time — simply do not. In interviews with affected business representatives, the workload was estimated at a minimum of one person spending two to three days per week on this topic alone — a realistic assessment that many SMEs cannot absorb without significant additional cost.

There is another layer to this: many companies are technically reasonably well set up, but fall short when it comes to organizational structures and documentation. Missing process frameworks, no embedded security culture, barely any reporting structures in place — all of this makes compliance work laborious and draining.

4. The Wait-and-See Strategy

For as long as the national implementation law was not finalized, many companies chose to wait. This hesitation was a deliberate strategic calculation: investing too early might mean heading in a direction that the final legislation would correct. This posture led to a dangerous standstill — and when the law came into force in December 2025 without a transition period, many companies were completely unprepared.

That argument is now obsolete. The law is in effect. The registration deadline passed on March 6, 2026. Any company that has not yet registered is already risking a fine.

5. Underestimating Personal Liability

NIS-2 is the first German cybersecurity law to hold managing directors personally accountable. Section 38 of the new BSIG requires company management to, among other things, regularly undergo training in four core areas — at least every three years. And any executive who ignores their organization’s reporting obligations faces personal liability.

Manuel Bach of the BSI drew a sharp analogy at the congress: you cannot simply decide for yourself that you are not subject to tax obligations. The same logic applies here. Just because a company believes it falls outside the scope of NIS-2 does not make that belief legally valid.

The Cost of Inaction: What Companies Are Risking

The fine frameworks under NIS-2 are substantial. For particularly important entities, sanctions can reach up to 10 million euros or 2 percent of global annual turnover — whichever is higher. For important entities, the framework is up to 7 million euros or 1.4 percent of global revenue.

On top of that comes the personal liability of senior management, the full weight of which many executive teams have yet to appreciate. Companies with inadequate security measures also face significant reputational damage if a security incident becomes public and it is clear that no appropriate steps had been taken.

And finally: companies that are part of a supply chain are increasingly being scrutinized by larger customers and partners for compliance status. NIS-2 compliance is becoming a competitive differentiator.

Why Manual Implementation Hits a Wall

The traditional approach — bringing in consultants, maintaining Excel spreadsheets, assembling documentation in Word files — works for large corporations with the necessary resources. For mid-sized businesses, it is simply too time-consuming, too error-prone, and too difficult to scale.

NIS-2 is not a one-time project you can tick off and forget. It demands continuous risk management, regular review of security measures, structured incident response within strict reporting deadlines — significant security incidents must be reported to the BSI within 24 hours — and ongoing documentation of supply chain security.

That is not a workload you can manage with a checklist in a drawer.

How GRC Software Closes the Compliance Gap

Governance, Risk & Compliance — or GRC — software was built precisely for this problem: translating complex regulatory requirements into structured, scalable, and traceable action. For NIS-2, GRC software is not a nice-to-have. It is a strategic tool.

A Structured Starting Point Instead of Disorientation

Modern GRC platforms deliver pre-configured NIS-2 frameworks that include all relevant control areas, compliance objectives, and documentation templates. Instead of starting from scratch, a company begins with a structured gap assessment: where does the organization stand today? Which requirements are already met? Where do gaps remain?

This gap analysis is the foundation for a prioritized action plan — and exactly what many companies have been missing: a clear picture of where to start.

Automated Risk Management

NIS-2 demands the continuous identification, assessment, and mitigation of risks. Handled manually, that means recurring workshops, spreadsheet maintenance, and internal coordination rounds. A GRC platform automates these processes: risks are captured, assessed, linked to specific measures, and documented in a living risk register — one that updates automatically as the threat landscape or organizational structure evolves.

Incident Management with Integrated Reporting Workflows

The 24-hour reporting deadline for significant security incidents is one of the toughest operational requirements in NIS-2. Without structured processes, it is nearly impossible to meet. GRC software provides integrated incident management modules: incidents are recorded in a structured way, automatically classified, relevant stakeholders are notified, and reporting pathways to the BSI can be prepared in advance. Comprehensive documentation also protects management in the event of a liability claim.

Supply Chain Security and Third-Party Management

NIS-2 also requires companies to secure their supply chains. That means: suppliers and service providers must be assessed for their security practices. A GRC platform allows this third-party management to be mapped systematically — with automated questionnaires, structured assessment workflows, and a central overview of all relevant partners.

Audit-Readiness at the Push of a Button

Particularly important entities must demonstrate their measures to the BSI within three years. Organizations that map their NIS-2 compliance in a GRC platform are audit-ready at any time: all evidence, documents, risk assessments, and action logs are stored in one central location, versioned, and retrievable on demand.

Relieving the Burden on Management and IT

An often-underestimated benefit: GRC software takes pressure off executive leadership. Instead of being overwhelmed by compliance details, decision-makers get clear dashboards that show at a glance where the organization stands on NIS-2 conformity. IT teams are relieved because routine tasks are automated — by up to 40 percent, according to research data.

Multi-Framework Coverage: NIS-2 Does Not Stand Alone

Companies required to implement NIS-2 often carry other regulatory obligations as well: GDPR, ISO 27001, DORA (for financial entities), TISAX (for the automotive industry), or the forthcoming KRITIS Umbrella Act. Well-integrated GRC platforms can map these frameworks in parallel and leverage synergies — organizations that are already ISO 27001 certified have a significant head start on NIS-2 compliance.

Zazoon: GRC Software That Does Not Overwhelm

At Zazoon, we have observed the realities of the mid-market up close. Companies do not need another checklist or another consultant’s slide deck. They need a software solution that breaks NIS-2 down into manageable steps, guides the implementation, and does not demand more IT expertise than realistically exists within the organization.

Our GRC platform delivers exactly that: a structured NIS-2 onboarding experience, integrated risk management, automated documentation, and a central dashboard for both management and IT — without requiring a dedicated compliance team to be built from scratch.

Conclusion: The Cost of Waiting Is Too High

NIS-2 is not a bureaucratic construct you can wait out. It is enforceable law with substantial penalties and personal liability for management. The sobering figures from the BSI Congress show that a significant portion of German business has yet to grasp this reality — or is deliberately choosing to ignore it.

The good news: it is not too late to get started in a structured way. And GRC software makes it realistic for the first time to achieve NIS-2 compliance without a large compliance team and without six-figure consulting budgets. Companies that act now are not just protecting themselves from fines and liability risks. They are building the foundation for a more resilient IT infrastructure, strengthening the trust of their customers and partners, and positioning themselves as dependable links in a security-conscious supply chain.

The effort is real. But it is manageable — with the right tools.

Frequently Asked Questions (FAQ)

Does NIS-2 apply to my company if we are not a technology business?
Yes, in many cases. NIS-2 covers companies across 18 sectors, including energy, transport, healthcare, mechanical engineering, chemicals, food production, and public administration. As a general rule: organizations with at least 50 employees or more than 10 million euros in annual revenue should actively check whether they fall within scope. This assessment should be carried out as soon as possible.

What happens if my company missed the registration deadline?
The BSI registration deadline expired on March 6, 2026. Companies that have not yet registered are at risk of fines and should complete registration without delay. The BSI has indicated that it is actively monitoring compliance with the obligations.

How significant are the potential fines?
For particularly important entities, fines can reach up to 10 million euros or 2 percent of global annual turnover. For important entities, the framework allows for fines of up to 7 million euros or 1.4 percent of global revenue.

What is the difference between “important” and “particularly important” entities?
Particularly important entities are larger organizations in critical sectors such as energy, water, financial market infrastructure, and healthcare. Important entities include mid-sized companies and organizations from additional sectors such as manufacturing, food, and digital services. The precise classification depends on sector, company size, and market position.

Does ISO 27001 certification help with NIS-2 implementation?
Yes, significantly. ISO 27001 and NIS-2 overlap in many areas — particularly around the information security management system (ISMS), risk analysis, and the documentation of security measures. Organizations that are already ISO 27001 certified have a meaningful head start. Good GRC platforms map both frameworks in parallel and use existing work as the foundation for NIS-2 compliance.

How long does NIS-2 implementation take with GRC software?
It depends on the organization’s starting point. With a GRC platform that includes structured templates, gap analyses, and automated workflows, well-prepared companies can reduce the time to compliance by up to 50 percent compared to a purely manual approach. Realistic timelines for reaching an initial solid compliance baseline are three to six months.

What exactly do I need to do as a managing director or executive?
Under Section 38 of the new BSIG, company management must actively oversee and approve the implementation of risk management measures. Regular training in four core areas is also mandatory — at a minimum every three years. Those who neglect these obligations face personal liability. A GRC platform helps document and evidence these activities in a structured and verifiable way.

Can GRC software also cover supply chain security?
Yes. Modern GRC platforms offer third-party management modules that allow suppliers and service providers to be systematically assessed and documented. This is particularly important given that NIS-2 explicitly requires supply chain security as part of an organization’s overall risk management obligations.

22 December 2025 | 5 min

GRC Regulation 2026: New Laws and Key Dates in the DACH Region

The turn of the year traditionally marks the starting point for new regulatory requirements in the field of Governance, Risk, and Compliance. While 2025 was heavily characterized by the final implementation of major EU frameworks such as DORA and NIS 2, the year 2026 is defined by expansion and technological deepening. For companies in the DACH region (Germany, Austria, Switzerland), January 1, 2026, specifically means: Grace periods are over, new reporting standards in the crypto sector take effect, and sustainability reporting reaches the next escalation level regarding the breadth of affected companies.

  • In Switzerland, the automatic exchange of information on crypto-assets (CARF) enters into force on January 1, 2026.
  • The CSRD reporting obligation expands to large, non-capital-market-oriented companies starting with the 2026 financial year.
  • For DORA and NIS 2, the implementation phase ends; from 2026 onwards, supervisory authorities will focus on auditing and sanctioning.
  • The EU AI Act approaches decisive deadlines, making 2026 the central year for AI governance implementation.

Switzerland: Transparency Push via CARF and Expanded AEOI

A central focus at the start of 2026 lies on Switzerland. On January 1, 2026, the Federal Council enacts the Crypto-Asset Reporting Framework (CARF) as well as amendments to the Common Reporting Standard (AIA/AEOI). This is a decisive step for tax transparency in the realm of digital assets.

The CARF framework obliges Swiss crypto service providers to record transaction data of their clients and information on held crypto-assets. This data must be reported to the Federal Tax Administration (FTA), which in turn exchanges it with partner states. The goal is to close tax loopholes that existed due to the previous non-recording of crypto-assets in the classic AEOI. For GRC managers at Swiss financial institutions and crypto service providers, this means that due diligence processes and KYC procedures (Know Your Customer) must be fully adapted to the new asset classes and reporting standards by the January 2026 deadline.

In parallel, amendments to the AEOI Act come into force, implementing recommendations of the Global Forum on Transparency and Exchange of Information for Tax Purposes. This affects, among other things, more precise due diligence obligations for Non-Reporting Financial Institutions.

CSRD: The Second Wave Rolls In

At the European level, January 1, 2026, is a crucial date for the Corporate Sustainability Reporting Directive (CSRD). While previously primarily capital-market-oriented companies were subject to reporting obligations, the obligation for large limited liability companies that are not capital-market-oriented begins with the 2026 financial year.

Companies fall under this second wave if they exceed at least two of the three following criteria: more than 250 employees, more than 50 million euros in net turnover, or more than 25 million euros in balance sheet total (taking into account inflation-related threshold adjustments). For compliance departments in these companies, the start of the 2026 financial year means that data collection for the report to be published in 2027 must now be operational. The time for preparation is over; from now on, ESG data must be recorded in an audit-proof manner. This requires functioning Internal Control Systems (ICS) for sustainability information.

DORA and NIS 2: From Project Mode to Regular Operations

Both the Digital Operational Resilience Act (DORA) and the NIS 2 Directive formally entered into force before 2026. Nevertheless, January 2026 marks a watershed moment. The phase of “Day 1 Compliance,” which was often still characterized by transitional solutions, is over.

From 2026 onwards, it is expected that national supervisory authorities – such as BaFin in Germany or FMA in Austria – will intensify their auditing activities. For DORA, this means that ICT third-party risk management must not only exist on paper, but contractual adjustments with IT service providers must be concluded. Registers of information relationships must be current and complete. GRC experts should use the year 2026 to test the processes implemented in the previous year for their operational effectiveness (e.g., through TLPT – Threat Led Penetration Testing), as real sanctions now loom.

Outlook: Supply Chain Acts and CSDDD

In Germany, the Supply Chain Due Diligence Act (LkSG) remains relevant, but the focus is increasingly shifting towards harmonization with the European Corporate Sustainability Due Diligence Directive (CSDDD). Although the national implementation laws of the CSDDD will only fully enter into force later, companies must strategically align their risk analyses with the more far-reaching requirements of the EU Directive from 2026 onwards to avoid double work. In particular, the climate transition plans, which are part of the CSDDD, require a lead time that should begin in January 2026.

FAQ

Who does the new CARF law in Switzerland affect starting January 2026?

It primarily affects Crypto-Asset Service Providers (CASPs/VASPs) resident in Switzerland. They must record client data and transactions and report them to the tax authorities.

Does my company have to create a CSRD report starting in 2026?

If your company is not capital-market-oriented but meets two of the three criteria (Balance sheet > 25m EUR, Turnover > 50m EUR, > 250 employees), the duty to collect data begins for the financial year 2026. The report itself will then appear in 2027.

What changes in 2026 regarding DORA?

Regulatorily, nothing new changes, but the grace period is over. From 2026, the first in-depth audits by supervisory authorities are expected to take place, and processes must be “lived and tested.”

What role does the EU AI Act play in January 2026?

The AI Act is already in force, but many obligations for high-risk AI systems only become strictly effective in mid-2026. January 2026 is therefore the starting signal for the final implementation phase of these requirements.

11 December 2025 | 6 min

Holiday gifts for business partners in the DACH region

During the Christmas season, many companies take the opportunity to thank their business partners with small gifts. These gestures strengthen relationships, show appreciation and are often part of a company’s culture. At the same time, tax rules, compliance requirements and internal guidelines must be respected – and these differ between Germany, Austria and Switzerland.

This article provides a current and balanced overview of the legal and practical framework for holiday gifts in all three DACH countries. It explains what companies should consider in order to give appropriately, avoid risks and maintain trust.

  • In all three countries, the same core principles apply: gifts must be business related, appropriate and transparent.
  • Germany has a tax threshold of 50 euros per recipient and calendar year for business gifts.
  • Austria and Switzerland do not use a single statutory value limit, but focus on appropriateness, business purpose and documentation.
  • Clear internal guidelines and consistent documentation are recommended throughout the DACH region.
  • Gifts to people in the public sector or highly regulated industries require particular caution.

Why clear rules are important in all three countries

Regardless of whether a company is based in Austria, Switzerland or Germany, gifts must never give the impression that they are intended to influence business decisions improperly. Compliance standards, anti-corruption rules and tax legislation are designed to ensure clean business relationships.

Companies should therefore apply clear and comprehensible principles in every country in which they operate. This prevents misunderstandings, reduces legal and tax risks and creates a uniform standard for all employees.

Current regulations at a glance

Germany

Germany is the only DACH country with a clearly defined tax limit for gifts to business partners. Business gifts are tax deductible up to 50 euros per recipient and calendar year if they are business related and properly documented.

For gifts that exceed this amount, the tax deduction may be denied unless the gift is clearly and exclusively usable for business purposes.

Austria

Austria does not work with a uniform fixed value limit. Instead, the following aspects are crucial:

  • the gift must serve a clear business purpose
  • the value must be reasonable in relation to the relationship and the occasion
  • the gift must be documented in a comprehensible way

As in the other DACH countries, gifts must not be used to gain improper advantages. Particular care is required in the public sector and in strongly regulated industries.

Switzerland

Switzerland also has no statutory standard limit for gifts to business partners. The focus is on:

  • usual appropriateness according to Swiss business practice
  • transparency and traceability
  • compliance with internal rules and industry-specific regulations

Swiss business culture tends to favour modest, high-quality but unobtrusive gifts rather than expensive luxury items.

Common basic principles for the entire DACH region

Despite the legal differences, companies in Germany, Austria and Switzerland can follow a common set of basic rules.

Appropriateness

The gift should match the business relationship, the role of the recipient and the occasion. Very expensive or flashy gifts can quickly appear inappropriate.

Business purpose

Holiday gifts should always serve a legitimate business purpose, such as maintaining a good relationship or thanking partners for successful cooperation. They must not be used to steer decisions or promises of business.

Documentation

For every gift, companies should record at least the following:

  • name of the recipient and company
  • occasion
  • date
  • value
  • business purpose

This documentation helps during tax audits and internal or external compliance checks.

Caution with public sector recipients

For employees of authorities, public hospitals, universities, municipalities and similar organisations, stricter requirements usually apply in all three countries. Often only very small tokens are permitted, and in some cases gifts are completely prohibited. When in doubt, it is better to ask in advance or avoid gifts altogether.

Recommendations for companies in the DACH region

  1. Create a clear, written gifting policy that applies in all locations.
  2. Define maximum values for gifts per person and per year.
  3. Ensure consistent documentation of all gifts to business partners.
  4. Pay special attention to sensitive sectors such as the public sector, healthcare or regulated industries.
  5. Plan gifts early and avoid borderline cases in terms of value or type of gift.
  6. Consider alternatives such as charitable donations in the name of a business partner instead of material gifts.

Why restraint is often the best strategy

No matter in which of the three countries a company operates, gifts that are too expensive or too personal can send the wrong signal. They may be perceived as an attempt to influence decisions and can trigger tax or compliance issues.

Modest, tasteful gifts or a personal handwritten card are often more effective and credible than high-value items. What counts in the long term is trust and partnership – not the material value of a present.

FAQ – Frequently asked questions in the DACH region

Is there a single value limit that applies to the whole DACH region?

No. Germany has a defined tax threshold of 50 euros per recipient and calendar year for business gifts. Austria and Switzerland use the principles of appropriateness, business purpose and documentation instead of fixed legal limits.

May I give expensive gifts in Austria or Switzerland if they seem appropriate?

In principle this is possible, but it is usually not advisable. High-value gifts increase the risk of compliance concerns, negative perceptions and disputes during audits. In practice, modest gifts are safer and more in line with expectations.

How should a business gift be documented correctly?

For each gift you should record who received it, for which company the person works, the date, the occasion, the value and the business reason. This information should be stored centrally, for example in a simple gifts register.

Are gifts to employees treated in the same way as gifts to business partners?

No. Gifts to employees are subject to different tax and payroll regulations in all three countries. Companies should therefore treat gifts to staff separately from gifts to external business partners and observe the respective rules.

How should I handle gifts to governmental bodies or public organisations?

With particular caution. In all DACH countries there are strict rules for the public sector, and many organisations either prohibit gifts completely or limit them to very small amounts. If you are unsure, ask for written guidance or refrain from giving a gift.

2 July 2025 | 4 min

Leadership Change in Risk Management at N26: What Companies Can Learn from a GRC Perspective

Intro

In the summer of 2025, German neobank N26 announced a significant leadership change: Chief Risk Officer (CRO) Carina Kozole will leave the company. She will be succeeded by Jochen Klöpper, formerly with Santander Consumer Bank.

Leadership transitions in key risk roles are always noteworthy – not only because of their impact on the organization itself, but also for what they reveal about the structural requirements of Governance, Risk, and Compliance (GRC) in fast-growing and heavily regulated businesses.

This article analyzes the developments at N26 through a systemic lens, outlines common challenges for digital financial service providers, and explains how integrated GRC systems help companies remain stable, compliant, and resilient during leadership transitions.

What Happened at N26?

Carina Kozole joined N26 in late 2023 as Chief Risk Officer and was responsible for enterprise-wide risk and compliance oversight. In 2025, the company announced her departure and named Jochen Klöpper as her successor. Klöpper brings extensive experience in risk management from his previous roles at Santander and other banks.

The timing is notable: N26, like many neobanks, is under increasing regulatory scrutiny. Topics such as AML compliance, IT security, credit risk, and internal controls are becoming critical not only from a regulatory perspective but also in terms of business continuity and market trust.

The Challenge: Growth, Complexity, and Regulatory Exposure

Digital organizations like N26 often face three structural issues:

1. Growth outpaces governance

Startups and digital scale-ups tend to prioritize innovation and customer growth. Governance, compliance, and process maturity often come later – sometimes too late.

2. Layered, evolving regulation

Digital banks operate under overlapping and evolving regulatory frameworks across jurisdictions. Without structured systems to track and manage these requirements, even competent teams can fall behind.

3. Dependency on individuals

In organizations where governance processes are not systematized, key responsibilities may rest with individuals. When those people leave, knowledge gaps, delays, or even compliance breaches can occur.

The GRC Perspective: Mitigating Risk Through Structure

Modern GRC systems help institutionalize risk and compliance processes, reduce dependency on individuals, and provide transparency across the organization.

What GRC software enables:

1. Centralized, auditable risk management

Risk categories, ownership, evaluations, and mitigation measures are documented in a structured, traceable system – not in spreadsheets.

2. Real-time regulatory oversight

Requirements (e.g., AML laws, data protection regulations, banking guidelines) are tracked centrally, with automated compliance status and escalation workflows.

3. Continuity during leadership transitions

With roles, responsibilities, deadlines, and documentation centralized, a new CRO can pick up critical tasks without process disruption or blind spots.

4. Visible governance culture

GRC systems can also track qualitative indicators – such as training effectiveness, audit response times, and cultural maturity – and contribute to an overall view of risk readiness.

Lessons Learned: From N26 to the Broader Market

  • People matter – but systems carry the organization. GRC systems ensure continuity when leadership changes.
  • Regulation is continuous, not project-based. Real-time visibility and structured compliance management are essential.
  • Good governance combines structure and culture. Systems alone are not enough; values, communication, and accountability must follow.
  • GRC tools are strategic, not just administrative. When well-integrated, they reduce risk exposure, improve investor confidence, and support long-term resilience.

Conclusion

The CRO transition at N26 illustrates the high stakes of governance and compliance in modern digital organizations. Especially in regulated sectors, leadership continuity and process integrity are inseparable.

A robust GRC system turns governance from a reactive obligation into a proactive capability – one that protects the organization, enables growth, and earns trust.


FAQ – Frequently Asked Questions on CRO Transitions and GRC

What does CRO stand for?
CRO stands for Chief Risk Officer – the executive responsible for enterprise-wide risk governance, including financial, regulatory, operational, and strategic risks.

Why is a CRO transition significant in banking?
Banks operate under strict regulatory regimes. A leadership change in the risk function may signal strategic shifts, regulatory attention, or internal restructuring. It can also affect market perception.

What happened at N26?
Carina Kozole will leave N26 in 2025. She will be succeeded by Jochen Klöpper, a seasoned risk executive from Santander. The move comes amid continued focus on strengthening risk and compliance capabilities.

What is a GRC system?
GRC (Governance, Risk, and Compliance) systems are software solutions that integrate regulatory management, risk monitoring, policy controls, and reporting into one framework.

How does a GRC platform support leadership transitions?
It ensures that responsibilities, regulatory obligations, and ongoing tasks are transparent and documented. That way, new leaders can take over without disruption or knowledge gaps.

Is GRC only relevant to large corporations or banks?
No. Any organization facing regulatory complexity, rapid growth, or cross-functional risk exposure can benefit from GRC systems – including in health care, energy, technology, and public administration.

What are the benefits of using GRC software?

  • Full visibility into risks and control measures
  • Regulatory tracking and automated compliance reporting
  • Role continuity and institutional memory
  • Improved audit readiness and accountability
  • Enhanced risk culture and decision-making

3 June 2025 | 3 min

How BaFin Uses Artificial Intelligence: Digitizing Financial Supervision

Germany’s Federal Financial Supervisory Authority (BaFin) is modernizing its tools for monitoring financial markets. To do this, it is increasingly relying on Artificial Intelligence (AI) to detect risks faster, uncover market manipulation, and automate compliance processes. In this blog post, we explore how BaFin uses AI, what benefits it brings, and what it means for companies and consumers.

AI in Market Surveillance: Algorithms Against Insider Trading

A key application of AI at BaFin is the detection of suspicious trading patterns. Using machine learning, BaFin analyzes vast amounts of trading data to uncover market manipulation and insider trading. These patterns are often hard for human analysts to detect but can be statistically significant indicators of abuse.

Automated Analysis of Company Data

Another field of application is the analysis of annual reports, ad-hoc disclosures, and financial statements. BaFin employs Natural Language Processing (NLP) to automatically identify risks, irregularities, or anomalies in corporate data. This accelerates the auditing of financial reports and helps detect adverse trends early.

AI in Banking Supervision: Risk Assessment and Early Warning Systems

AI is also used in regulatory assessments of banks and insurers. AI-powered early warning systems analyze metrics, capital structures, and market movements to identify risks early. This enables BaFin to intervene more quickly in times of crisis and prevent potential failures.

Anti-Money Laundering with AI

BaFin also uses AI to combat money laundering. By analyzing transaction patterns, suspicious activities can be automatically detected and reported. In collaboration with financial institutions, this improves both efficiency and the accuracy of prevention systems.

SupTech: Technological Shift in Supervision

Under the term SupTech (Supervisory Technology), BaFin is driving the digital transformation of its supervisory functions. AI plays a key role in processing large volumes of data, automating procedures, and making data-driven decisions.

Conclusion: Smarter Supervision Through Intelligent Systems

BaFin’s use of AI represents a decisive step toward modern, data-driven financial supervision. For companies, this means more transparency and faster processes. For consumers, it means greater protection from market abuse and financial crime. It also makes clear: supervisory authorities must evolve in the digital age to remain effective.


FAQ: Frequently Asked Questions About AI at BaFin

What is BaFin’s goal in using AI?

BaFin aims to detect risks earlier, uncover market abuse faster, and make supervision more efficient.

What technologies are being used?

Primarily machine learning, natural language processing (NLP), and data analytics.

Is the use of AI legally regulated?

Yes, BaFin must adhere to all applicable laws, including data protection and administrative law.

How do financial firms benefit?

Through clearer risk indicators, faster communication with regulators, and early warnings of potential problems.

What is SupTech?

SupTech refers to the technological advancement of supervisory work. AI is a central component of this development.

26 September 2023 | 0 min

Supply chain due diligence act (LkSG) from 1.1.2023

No content found

Share