- Germany’s cyber agency BSI wants every website to publish a security.txt file so researchers can report bugs quickly.
- The file gives hackers and safety teams a clear way to contact a company when they find a weak spot.
- Only 1.8% of German websites use it right now, even though BSI calls it one of the easiest fixes around.
Germany’s cybersecurity watchdog wants companies to act fast. The Bundesamt für Sicherheit in der Informationstechnik (BSI) is now asking every business with a website to publish a security.txt file.
A security.txt file is a simple text document. Companies place it on their web servers. Ethical hackers created the idea. They needed a fast way to report bugs they found on a company’s site.
Before this, finding the right person to contact took too long. Hackers wasted precious time searching for an email or a name. Meanwhile, real criminals used that same gap to attack first.
Why the File Matters
A security.txt file fixes that gap. It lists exactly who to contact when someone finds a security flaw. Developers can then jump into action and patch the problem fast.
This speed matters a lot. It shrinks the window that attackers have to exploit a new weakness. It also protects everyday users from becoming victims of that flaw.
The file helps more than just company staff. Security researchers benefit from it too. So do Computer Emergency Response Teams (CERTs) and other groups that report threats. All of them get a direct, reliable way to reach the right person.
Companies that adopt it also send a clear signal. They show that they take security seriously. That builds public trust and boosts a company’s overall cyber resilience.
Most Companies Still Aren’t Using It
Despite the clear benefits, adoption remains extremely low. BSI reports that only 1.8% of German website owners currently publish a security.txt file. That means the vast majority of sites still lack a proper reporting channel.
The risks of inadequate security are illustrated by a separate incident in Australia where the Department of Parliamentary Services accidentally published private mobile numbers of hundreds of MPs, including former prime ministers, due to a simple redaction error.
BSI insists there’s no good excuse for skipping it. According to the agency, security.txt ranks among the simplest safety measures any company can set up. Setup takes very little time or technical skill.
The agency, alongside the Alliance for Cybersecurity, is now pushing hard. It’s calling on webmasters, site administrators, and business owners across Germany to publish the file without delay.
How Companies Can Set It Up
Setting up the file is straightforward. A business needs two basic details. First, contact information for a specific person or team. Second, an expiration date for that information.
The file also needs to live in one specific spot. It must sit at the web address ending in /.well-known/security.txt. That location lets automated tools and researchers find it instantly.
Some countries have gone further than encouragement. In the Netherlands, certain government bodies must use security.txt by law. This includes municipalities, provinces, water utility companies, and other executive offices.
Other public organizations in the Netherlands aren’t forced to comply. Officials still strongly recommend they adopt the standard anyway.
Germany hasn’t made the file mandatory yet. For now, BSI is relying on public pressure and plain advice. The agency wants business owners to understand the risk of waiting.
Every day without a security.txt file is a day attackers might move faster than defenders. A single contact file could mean the difference between a quick fix and a major breach.
BSI’s message is simple. Setup is easy. The benefits are large. And right now, almost no one in Germany is doing it.
Share this article
About the Author
Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.
More from Rebecca JamesRelated Posts
Firefox Users on iOS Can Now Block Ads without an Extension
Mozilla is slowly rolling out a built-in ad blocker for Firefox on iPhones and iPads, no extension n...
Suspected Chinese Hackers Exploit Critical VMware vCenter Flaw Across 47 Countries
Several servers across 47 countries record a compromise via an exploit of Vmware vCenter directory-t...
WhatsApp Tests On-Device Scam Alert without Reading User Messages
WhatsApp is testing a new tool called Scam Alert that spots scam messages right on your phone. The t...
Apple Faces Lawsuit Over Claims that iCloud Private Relay Leaks User IP Addresses
A law firm sued Apple, saying its Private Relay tool did not protect user privacy as promised. Exper...
Hackers Exploit TrueConf Servers to Distribute Malware Through Fake Software Updates
A hacker group named Head Mare broke into TrueConf video meeting servers and swapped safe installers...
New NatJack Attack Exposes Hidden Weakness in How Networks Handle Internet Connections
Security researcher Malcolm Stagg has uncovered NatJack, a new class of attacks that exploits a fund...