the legal limits. The interests of these authorities in restoring IT systems, investigating incidents and prosecuting the perpetrators are taken into account, as are the interests in protection of the party affected. The BSI will set up Mobile Incident Response Teams (MIRTs) to analyse and clear up cyber incidents affecting institutions which are especially important to society. On request, these teams will travel to constitutional bodies, federal agencies, critical infrastructure operators and similarly important institutions to help them deal quickly and flexibly with the technical aspects of managing security incidents, when there is a special public interest in doing so. This assistance is intended to rapidly restore the safe technical operations of the institution concerned. Cyber attacks may also require action by federal security authorities. For this reason, the Federal Criminal Police Office (BKA) is setting up a specialized investigative unit, the Quick Reaction Force (QRF). In consultation with the responsible public prosecutor’s office or the Office of the Federal Prosecutor, the QRF will take the first action that cannot be delayed under the Code of Criminal Procedure on behalf of the law enforcement authorities. The Federal Office for the Protection of the Constitution (BfV) is creating Mobile Cyber Teams made up of IT specialists, intelligence specialists experienced in analysing cyber attacks and, if necessary, staff with foreign language skills. These teams will travel to the scene of cyber attacks with an intelligence or extremist/terrorist background, including possible sabotage cases. The Military Counterintelligence Service (MAD) handles this task for agencies within the defence remit. As far as allowed by law, the Federal Intelligence Service (BND) may monitor attacks as they are being prepared and carried out. Information flows resulting from attacks are also registered. The Bundeswehr may also contribute, as far as allowed by the Constitution, to security preparedness with its Incident Response Teams and other relevant units. Classic preventive measures may not be enough to deal with serious cyber attacks in the necessary time. The Federal Government will therefore examine the 22

Select target paragraph3