Germany Warns Companies Over Missing Security Contact Files on Most Websites

Last updated: August 7, 2026 Reading time: 3 minutes
Disclosure
Share
Germany Warns Companies Over Missing Security Contact Files on Most Websites
  • Germany’s cyber agency BSI wants every website to publish a security.txt file so researchers can report bugs quickly.
  • The file gives hackers and safety teams a clear way to contact a company when they find a weak spot.
  • Only 1.8% of German websites use it right now, even though BSI calls it one of the easiest fixes around.

Germany’s cybersecurity watchdog wants companies to act fast. The Bundesamt für Sicherheit in der Informationstechnik (BSI) is now asking every business with a website to publish a security.txt file.

A security.txt file is a simple text document. Companies place it on their web servers. Ethical hackers created the idea. They needed a fast way to report bugs they found on a company’s site.

Before this, finding the right person to contact took too long. Hackers wasted precious time searching for an email or a name. Meanwhile, real criminals used that same gap to attack first.

Why the File Matters

A security.txt file fixes that gap. It lists exactly who to contact when someone finds a security flaw. Developers can then jump into action and patch the problem fast.

This speed matters a lot. It shrinks the window that attackers have to exploit a new weakness. It also protects everyday users from becoming victims of that flaw.

The file helps more than just company staff. Security researchers benefit from it too. So do Computer Emergency Response Teams (CERTs) and other groups that report threats. All of them get a direct, reliable way to reach the right person.

Companies that adopt it also send a clear signal. They show that they take security seriously. That builds public trust and boosts a company’s overall cyber resilience.

Most Companies Still Aren’t Using It

Despite the clear benefits, adoption remains extremely low. BSI reports that only 1.8% of German website owners currently publish a security.txt file. That means the vast majority of sites still lack a proper reporting channel.

The risks of inadequate security are illustrated by a separate incident in Australia where the Department of Parliamentary Services accidentally published private mobile numbers of hundreds of MPs, including former prime ministers, due to a simple redaction error.

BSI insists there’s no good excuse for skipping it. According to the agency, security.txt ranks among the simplest safety measures any company can set up. Setup takes very little time or technical skill.

The agency, alongside the Alliance for Cybersecurity, is now pushing hard. It’s calling on webmasters, site administrators, and business owners across Germany to publish the file without delay.

How Companies Can Set It Up

Setting up the file is straightforward. A business needs two basic details. First, contact information for a specific person or team. Second, an expiration date for that information.

The file also needs to live in one specific spot. It must sit at the web address ending in /.well-known/security.txt. That location lets automated tools and researchers find it instantly.

Some countries have gone further than encouragement. In the Netherlands, certain government bodies must use security.txt by law. This includes municipalities, provinces, water utility companies, and other executive offices.

Other public organizations in the Netherlands aren’t forced to comply. Officials still strongly recommend they adopt the standard anyway.

Germany hasn’t made the file mandatory yet. For now, BSI is relying on public pressure and plain advice. The agency wants business owners to understand the risk of waiting.

Every day without a security.txt file is a day attackers might move faster than defenders. A single contact file could mean the difference between a quick fix and a major breach.

BSI’s message is simple. Setup is easy. The benefits are large. And right now, almost no one in Germany is doing it.

Share this article

About the Author

Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.

More from Rebecca James

Related Posts