Austria's Cyber Deadline Looms as Just 2% of Firms Say They Are Ready
Published on 09/22/2026 at 01:00 | Editorial boerse-global.deWith less than a year until Austria's new network and information security law takes effect, a survey of 64 domestic companies has laid bare how far behind most of them are: a mere 2% report having fully implemented the NIS-2 requirements, and 26% have not even started.
The national Network and Information System Security Act (NISG 2026) was published on 23 December 2025 and enters into force on 1 October 2026. It will cover roughly 4,000 companies across 18 sectors. Firms in scope must register with the cybersecurity authority by 31 December 2026, with a self-declaration due by 1 October 2027.
The poll, conducted by comm:unications, Was-tun-Wenn and the Report Verlag, also found gaps in crisis planning — only 27.4% of respondents have begun concrete preparations for an IT crisis.
A lawyer's warning: many firms don't know they're covered
Much of the trouble traces back to awareness. A specialist lawyer at the firm Clyde & Co said in a September 2026 report that many businesses have yet to grasp that they fall under the new BSI Act on cybersecurity. Without a systematic review and implementation of the legal requirements, the consequences in the event of a breach could be severe — particularly around liability and insurance coverage disputes.
Three-quarters of German firms hit by an incident
Broader threat data from ManageEngine, based on a study of 302 IT and cybersecurity executives in Germany, underscores the pressure. Three-quarters of the German companies surveyed recorded at least one cybersecurity incident in the past twelve months, with phishing and social engineering the most common cause at 56% of recorded events.
Anxiety about emerging technology is mounting in parallel: 45% of those polled named AI-driven attacks as the biggest cyber risk over the next twelve months, and 35% said preparing for novel, AI-based threats is their top investment priority for the next two years.
Even so, management engagement often arrives late. In 39% of cases, according to the survey, executives only turn serious attention to cybersecurity once a crisis is already underway.
Recovery times vary widely. While 44% of companies restored operations within ten days, around 30% needed more than 20 days. Close to a third of IT teams are permanently in crisis mode or overstretched.
EU auditors find cross-border response wanting
Problems extend beyond national borders. A special report from the European Court of Auditors in September 2026 concluded that EU measures only partly make it easier to detect and respond to cross-border incidents. In 2025, just seven member states reported a total of 14 significant incidents, and a bloc-wide real-time platform for data exchange is still missing.
Meanwhile, the EU Cyber Resilience Act (CRA) puts obligations on hardware and software manufacturers, who must ensure protection against vulnerabilities across the entire lifecycle — for a minimum of five years. An expert at the company Onekey cautioned that time-to-market could suffer considerably without automated testing routines. Industrial controls in the IoT sector are especially exposed, since they frequently remain in service well beyond five years.
Critical infrastructure rules widen
On critical infrastructure, a draft of the Kritis-Verordnung (KritisV) retains a standard threshold of 500,000 supplied residents. Newly captured in the energy sector are, among other things, facilities connecting generators to the grid as well as energy storage. Germany's Federal Office for Information Security (BSI) expects a markedly higher number of registrations as the NIS2 implementation law takes hold.
Current specialist reporting points to substantial deficits in how NIS-2 is being put into practice, with experts warning of inadequate cyber resilience across the business world. Too often, the lack of preparation is only recognised as a critical operational risk when an incident actually strikes, according to a report dated 21 September 2026.
