most attacked country worldwide
About us
The German Center for CyberSecurity e. V. (GC4C) is a non-profit association building a national cyber security ecosystem for Germany – for businesses, public authorities and society alike.
Who we are
GC4C is a registered non-profit association based in Berlin, founded on 26 August 2025 and publicly launched on 27 August 2026. Its purpose is to help organisations in Germany defend themselves against cybercrime – through prevention and awareness before an incident, and through fast, targeted technical and tactical support after one.
We are not a vendor. GC4C sells no products and no services, holds no commercial stake in any supplier, and earns no commission or referral fee. That independence is deliberate: it is what allows companies, public authorities and security agencies to exchange information with us and with each other.
The association works with cyber security and ICT companies, with industry bodies such as the BVMW and the Chambers of Commerce (IHK), and is in ongoing dialogue with German security authorities including the Federal Criminal Police Office (BKA) and the Federal Office for Information Security (BSI). Conceptually, GC4C builds on the experience of the earlier „G4C – German Competence Center against CyberCrime e. V.“, a smaller but highly active exchange platform between industry and law enforcement, and extends its mechanisms into a broader ecosystem model.
Mission
Our mission is to make Germany cyber-resilient and fit for the digital age: to raise the level of protection against attacks, to minimise the impact when attacks succeed, and to keep businesses and institutions operational – and with them the economic and social achievements that depend on them.
Everything we do serves one purpose: enabling organisations in Germany to protect themselves against cybercrime, to build robust prevention, to understand the threat and its consequences, to respond effectively, and to recover as quickly as possible after an attack.
„There is no security without working together.“
Why now
Germany is among the most attacked countries in the world
attacks in 30 days (March 2026, Telekom)
new vulnerabilities per day (avg. 119)
of attacks target small and mid-sized firms
According to Deutsche Telekom's security telemetry, Germany ranks second worldwide among the most attacked countries, with more than 700 million recorded attacks in a single 30-day period (March 2026). The Federal Office for Information Security (BSI) continues to describe the national threat situation as serious: an average of 119 new vulnerabilities become known every day, an increase of 24 % year on year. Ransomware, cyber espionage and disinformation remain the dominant threats.
The attack surface keeps growing, with critical weaknesses in perimeter systems such as firewalls and VPNs a particular concern. Small and mid-sized companies now account for around 80 % of reported incidents – and most of those incidents involve data leaks, or the threat of one, against which the affected organisations have no prepared response. Professional, often state-directed APT groups conduct espionage against public institutions and companies, and German intelligence services warn of espionage, sabotage and disinformation at a previously unseen level.
This is not a problem any single organisation can solve alone. Reducing the attack surface in 2026 requires manufacturers, service providers, public bodies and users to work on it together.
The structural problem behind the numbers
More than 99 % of German companies are small or mid-sized; roughly 83 % of them have fewer than ten employees. Most have little or no budget and no dedicated staff for cyber security, let alone the capacity to keep pace with the speed at which attackers innovate. Five questions decide whether anything actually changes:
- AWARENESS – Perception of the real threat, of one's own exposure and of the possible consequences – commercial as well as personal – is still insufficient.
- CAPABILITY – Smaller organisations rarely have the money or the people to address cyber security to the extent required.
- WILLINGNESS – For anyone not selling security, it does not visibly create value. Calculating a return on investment against a worst case that destroys the company – with personal, sometimes criminal liability attached – remains a largely theoretical exercise.
- ACTION & PERSISTENCE – Turning intent into sustained practice raises the practical questions: Who helps me? What do I actually need? Where do I start? Whom do I trust with it?
- TRUST – In a market where many projects fail, often through opportunistic behaviour on the supplier side and a lack of expertise on the buyer side, trust is the decisive factor. Which partner, which solution, which approach – and on what basis can that judgement be made?
Our approach
GC4C was founded to connect actors from very different backgrounds into a community that can actually act – so that knowledge and experience translate directly into prevention and response measures. Four strategic pillars carry that work:
A) Ecosystem
Building a living network of all relevant actors – those who provide protection and those who need it – under one roof.
PillarB) Quality assurance
Making sure the experts, organisations and tools contributing to cyber defence meet high standards – through transparent procedures, a binding code of conduct and qualified selection.
PillarC) Mindset
Cyber security is an attitude, not only a technology. We work on a shared understanding of information security, prevention and responsible digital culture – where the cause comes before opportunistic behaviour.
PillarD) Orchestration
Coordinating everyone involved under a shared mindset, on the basis of common principles of conduct and defined processes.
PillarIn practice this means threat analysis and research, early-warning and monitoring capability, joint emergency and response strategies, professional dialogue with industry associations and security authorities, training and working groups – and platforms such as PASCAL, our AI-supported cyber security knowledge platform for the preventive assessment of attack situations.
Board
The board is responsible for strategic direction, the prioritisation of initiatives and cooperation with partners.
Ralf Greis
More than 30 years of leadership experience in IT, consulting and entrepreneurship. Co-founder and member of the management of Zukunfts-Akademie, a consultancy for transformation; former CEO of an IT services company and interim CSO of an AI-assisted service business. Senator in the Senate of the Economy Germany.
ChairmanIngmar Weitemeier
Lawyer by training and a career officer in German law enforcement. Director of the State Criminal Police Office of Mecklenburg-Western Pomerania from 1995 to 2009, founding dean of the police faculty in Saxony-Anhalt, and part of the management of the former G4C. Advises companies and public bodies on economic crime, espionage and critical-infrastructure incidents.
Deputy ChairmanChristian Fenner
Profile to follow.
In progressAdvisory board
The advisory board contributes expertise from business, politics, security authorities, academia and practice. It acts as a sounding board and source of impulse for the professional and strategic development of the association, and is currently being built up step by step.
Confirmed
Lorenz Caffier
Short biography to follow.
ConfirmedGet involved
GC4C invites companies, public authorities, associations, institutions and committed professionals to join the community. Membership is open to any person or legal entity of good standing whose professional or non-material interests align with the purpose of the association; the board decides on admission following a written application.
Members gain access to situational reports and analyses, exchange formats, the PASCAL platform, a quality-assured network and support in an emergency. The membership application form is available in German: Mitglied werden. If you would prefer to start the conversation in English, simply write to us.
Contact
German Center for CyberSecurity e. V.
Leuchtenburgstraße 23 · 14165 Berlin · Germany
General enquiries: kontakt@gc4c-ev.de
Press enquiries: presse@gc4c-ev.de
Selected announcements are published in English in our English newsroom.