Viewed from outside, Germany presents a curious contradiction. Few countries take standards, procedures and institutional safeguards more seriously. Yet in security, infrastructure and public administration, the machinery designed to prevent mistakes can itself become a source of strategic weakness. The problem is no longer a lack of knowledge. It is the distance between knowing and doing.
A recent Handelsblatt interview with German tunnelling entrepreneur Martin Herrenknecht offers an unusually revealing starting point. Herrenknecht’s immediate concern is infrastructure: the painfully slow German connection to the Brenner Base Tunnel route, where years of planning have sharpened the contrast with progress elsewhere in Europe. His language is characteristically unvarnished. Earlier this year, he warned that Germany risked heading “into the wall” without a drastic change of course and argued that today’s bureaucracy would make it almost impossible for him to establish his own company again. As evidence, he contrasted a logistics project in Baden-Württemberg that had already spent three and a half years in planning with a comparable project in Chennai that, according to him, received approval within three months.
One does not have to accept every element of Herrenknecht’s diagnosis to recognise the pathology he is pointing towards. India and Germany operate within very different legal, administrative and social frameworks; speed alone is not evidence of good government. Germany’s elaborate procedures exist for reasons: they protect competition, property, environmental interests, public money and individual rights. The more interesting question is what happens when safeguards accumulate until the system becomes exceptionally capable of explaining why a decision is difficult, but increasingly poor at making one. From outside, that is becoming one of the defining German contradictions: a state that is highly sophisticated in the management of process, yet frequently hesitant in the exercise of execution.
For the security sector, this should be uncomfortable reading. The same institutional habits that delay railways, energy infrastructure and industrial projects are visible in discussions about critical infrastructure protection, procurement, standards and emerging threats. Germany does not lack security strategies. It does not lack standards. It does not lack conferences, advisory councils, regulatory programmes or capable engineers. What it increasingly lacks is the confidence to convert all of these into decisions at the speed at which the threat environment changes.
Getting “Ahead of the Situation” — Eventually
German security language has developed a collection of phrases that reveal more than their authors may intend. Officials and industry representatives frequently speak of the need to “vor die Lage kommen” — literally, to get ahead of the situation. Organisations are encouraged to “ride the wave”, “take stakeholders with them”, “strengthen resilience”, “think holistically” and, when uncertainty becomes uncomfortable, “drive by sight”. Each expression is reasonable in isolation. Together they risk becoming the vocabulary of permanent preparation.
The irony is difficult to miss. An institution that continuously announces its intention to get ahead of the situation should eventually be judged on whether it actually does. Yet Germany often appears to be exceptionally good at recognising a wave once it is already visible, establishing a committee to examine its dimensions, consulting relevant stakeholders on the appropriate terminology, drafting a standard for responsible surfing — and then wondering why the water has moved on.
Critical infrastructure protection offers a useful example. Germany’s KRITIS umbrella law entered into force on 17 March 2026, establishing a cross-sector framework for the physical resilience of critical infrastructure. That is an important achievement. Yet the Federal Office of Civil Protection and Disaster Assistance itself notes that significant implementation measures are still being developed and coordinated, including regulations defining which facilities fall within the regime and methodological requirements for operator risk assessments. In some cases, operators cannot yet begin the relevant statutory process because the implementing framework is still being constructed.
This is not an argument against the KRITIS legislation. Germany needed a coherent framework. It is an argument about the difference between regulatory achievement and security effect. A statute does not harden a perimeter. A risk assessment does not stop an intruder. A resilience plan does not detect an unmanned aircraft. Standards and regulation create the conditions for security; they are not security themselves. Somewhere between the Bundestag, the regulator, the standardisation committee, the procurement department and the operator, somebody still has to install, integrate, test and maintain the thing that actually reduces the risk.
Threat actors enjoy an asymmetry here that is rarely discussed enough. They are under no obligation to await implementing regulations. Drone technology does not suspend development while procurement rules are harmonised. AI-enabled fraud does not respect consultation periods. Sabotage teams do not postpone reconnaissance until the relevant branch standard has been finalised. The adversary does not “drive by sight”. The adversary exploits the blind spot.
When Process Becomes a Substitute for Responsibility
The deeper German problem may therefore be less bureaucracy in the abstract than the way responsibility behaves inside bureaucracy. Complex projects distribute decisions across legal departments, procurement teams, technical planners, regulators, data-protection specialists, works councils, budget authorities and management boards. Each actor may perform its individual task entirely correctly. Yet the overall project can still take years to move.
This creates a peculiar form of institutional safety: everyone is responsible for a procedure, while responsibility for the outcome becomes progressively harder to locate. No conspiracy is required. It is the natural result of systems designed primarily to minimise individual error. If every difficult decision must pass through enough layers, the personal risk of making the wrong decision falls. Unfortunately, so does the ability to make a timely one.
Security procurement makes this particularly visible. A project may begin with a threat assessment, proceed through concept design, budget approval, procurement law, privacy review, technical specifications, construction planning and tendering before installation finally begins. Each step can be justified. The cumulative timescale can nevertheless mean that the solution ultimately deployed reflects a threat environment and technology market that existed several years earlier. The system has successfully minimised procedural risk while quietly increasing temporal risk.
That trade-off deserves much more attention. Security organisations are trained to evaluate the risks associated with action: false alarms, privacy consequences, interoperability failures, procurement challenges and financial exposure. They are often much less systematic about the risks associated with waiting. Yet a delayed correct decision can be as damaging as an incorrect one. A site that spends three years designing the ideal perimeter continues to operate for those three years with the perimeter it already has. An organisation that postpones drone detection until every legal uncertainty has been resolved remains exposed during the period of clarification.
Germany’s state-modernisation effort reveals a similar gap between ambition and completion. Bitkom’s June 2026 monitor assessed 222 projects intended to modernise government and administration. Implementation had begun on roughly two-thirds; only 9 per cent were reported as completed. There is something almost perfectly German about responding to an implementation problem with an exceptionally thorough monitor of implementation. The monitor is useful. The statistics are useful. The plans may be entirely sensible. But at some point modernisation must be visible not in the sophistication with which progress is measured, but in the time between identifying a problem and solving it.
Fewer Stages, More Decisions
The security industry itself is not innocent in this. Vendors, associations, authorities and consultants have become extremely proficient at presenting transformation. Almost every emerging threat produces a new summit, strategy paper, working group, webinar series, position paper and panel discussion. The vocabulary is polished: convergence, resilience, holistic security, sovereign solutions, ecosystems, transformation, next-generation capability.
Some of this exchange is essential. Much of it is valuable. But there is a point at which communication begins to compete with execution. Security is not improved in proportion to the number of people publicly explaining how important security has become.
The sector could benefit from rather less self-presentation and rather more institutional concentration. Not every regulatory development requires five conferences explaining that regulation is complicated. Not every risk needs its own communications architecture before the security architecture is in place. Not every organisation needs to announce that it is “taking a holistic approach” to a threat before demonstrating what it has actually changed.
A healthier operating culture would be almost aggressively simple: this is the risk; this is the priority; this person is responsible; this is what will be implemented; this is the deadline; this is how we will know whether it worked.
Such simplicity should not be confused with simplistic policymaking. Germany should not imitate jurisdictions that gain speed by weakening due process, public scrutiny or standards. That would destroy precisely the institutional qualities that make the country attractive and trustworthy. The objective is not fewer protections at any price. It is fewer layers that exist primarily because the system has lost confidence in the people making decisions.
Strong institutions require discretion as well as rules. If decision-makers are given responsibility, they must also be given room to decide. Conversely, if they are given discretion, they must be accountable for the result. Germany has gradually become uncomfortable with both halves of that equation: discretion appears risky, while personal accountability is diffused through procedure. The predictable response is more process.
Germany Does Not Need Fewer Standards. It Needs More Urgency.
From abroad, the temptation is to caricature Germany as a country paralysed by paperwork. That would be both unfair and intellectually lazy. Its standards culture, engineering discipline and insistence on legal certainty have produced extraordinary industrial and institutional strengths. German security technology benefits precisely from a culture that expects systems to be documented, tested and reliable rather than merely impressive in a demonstration.
The danger begins when these strengths become self-defeating. A standard should make implementation safer and easier, not become a reason to postpone it. Procurement should protect competition, not freeze technology at the moment a tender was conceived. Consultation should improve a decision, not make decision-making indefinite. Regulation should clarify responsibility, not multiply the number of parties able to delay action.
This is where Herrenknecht’s call for an “implementation sprint” deserves a wider hearing. Germany does not need a sprint in the sense of abandoning planning and running blindly. It needs one in the more demanding sense: deciding what matters most, concentrating authority, shortening the distance between analysis and execution, and accepting that responsible action always involves residual risk.
There is also a cultural point. In German security debates, “getting ahead of the situation” has become almost a ritual aspiration. Perhaps the phrase has outlived its usefulness. If the danger is already on the radar, endlessly discussing how to get ahead of it is not strategic foresight. It is delayed movement dressed in strategic language.
The same applies to “riding the wave”. Governments and companies that merely ride technological or regulatory waves are not leading them. And “driving by sight” may be prudent in fog, but it is an odd doctrine when the obstacles have already been mapped in multiple risk assessments.
Germany’s real challenge, then, is not intellectual. The country knows an extraordinary amount about its vulnerabilities. It has sophisticated institutions, capable companies, strong research and an almost inexhaustible capacity to formulate frameworks for improvement.
What it needs is a different measure of seriousness.
Not how many strategies were published, but how many vulnerabilities were closed. Not how many stakeholders were consulted, but whether someone ultimately made the decision. Not how comprehensive the plan became, but how quickly a known risk was reduced.
The German security debate has spent years asking how the country can get ahead of the situation.
Perhaps the more useful question now is much less elegant: What, exactly, has been done?
[DCM]


