Action area 2: Government and private industry working together Trusting cooperation and close interaction between government and the private sector are essential to maintain a high level of cyber security in Germany over the long term. New avenues should be taken as part of a cooperative approach in order to combine strengths. Businesses in Germany must be able to protect themselves and their customers effectively against cyber attacks. Operators of critical infrastructure deserve special attention. But other businesses are also very important for government, society and the economy and require special protection. With the help of the cooperative approach established with the IT Security Act, the necessary conditions should be improved and extended to other economic sectors as needed. Government and private industry need to work together closely and on the basis of mutual trust in developing and implementing effective, needs-based IT security standards. For this to happen, Germany needs a strong IT industry promoted with the help of modern economic policy. The Federal Government will also draft measures to improve Germany’s start-up culture in the field of IT and cyber security, which is weak in international comparison. In detecting and averting cyber attacks, it is essential to include providers and IT security services in Germany. Strategic objectives and measures Securing critical infrastructures Protecting critical infrastructures is the central focus of joint activities by government and the private sector. The interconnectedness of these systems means that protecting the IT of critical infrastructures is especially important. This cyber prevention and defence task is shared by the federal, state and local governments, because internal and external security in the cyber area are closely interrelated. In implementing the IT Security Act, government and the private sector must work together closely at all levels and share information on the basis of trust, among others in the public–private partnership UP KRITIS. Minimum standards and reporting channels are drafted, implemented and further developed in cooperation with the private sector. Whether to extend such obligations 16

Select target paragraph3