the legal limits. The interests of these authorities in restoring IT systems, investigating incidents and prosecuting the perpetrators are taken into account, as are
the interests in protection of the party affected.
The BSI will set up Mobile Incident Response Teams (MIRTs) to analyse and
clear up cyber incidents affecting institutions which are especially important to
society. On request, these teams will travel to constitutional bodies, federal
agencies, critical infrastructure operators and similarly important institutions to
help them deal quickly and flexibly with the technical aspects of managing security incidents, when there is a special public interest in doing so. This assistance is
intended to rapidly restore the safe technical operations of the institution concerned.
Cyber attacks may also require action by federal security authorities. For this
reason, the Federal Criminal Police Office (BKA) is setting up a specialized investigative unit, the Quick Reaction Force (QRF). In consultation with the responsible public prosecutor’s office or the Office of the Federal Prosecutor, the
QRF will take the first action that cannot be delayed under the Code of Criminal
Procedure on behalf of the law enforcement authorities. The Federal Office for
the Protection of the Constitution (BfV) is creating Mobile Cyber Teams made up
of IT specialists, intelligence specialists experienced in analysing cyber attacks
and, if necessary, staff with foreign language skills. These teams will travel to the
scene of cyber attacks with an intelligence or extremist/terrorist background, including possible sabotage cases. The Military Counterintelligence Service (MAD)
handles this task for agencies within the defence remit. As far as allowed by law,
the Federal Intelligence Service (BND) may monitor attacks as they are being
prepared and carried out. Information flows resulting from attacks are also registered. The Bundeswehr may also contribute, as far as allowed by the Constitution, to security preparedness with its Incident Response Teams and other relevant units.
Classic preventive measures may not be enough to deal with serious cyber attacks in the necessary time. The Federal Government will therefore examine the
22