Germany is a strong country for cybersecurity research. Overall and per capita, its output performs quite well on international benchmarks. Germany has a long tradition in this field, demonstrating both breadth and peak excellence.
Some of the most prominent institutions in Germany are ATHENE, CASA, CISPA, CODE, and KASTEL.
ATHENE, for which I work, is somewhat of a virtual institution. Originally based in Darmstadt, it has since expanded to Frankfurt. ATHENE's funding comes from the BMBF (Federal Ministry of Education and Research) and the State of Hesse under a dedicated security funding line. The institution is managed by Fraunhofer, with the Fraunhofer SIT leading the initiative alongside several other partners. Fraunhofer is Germany's leading organization for applied research outside of the university system. It is structured as one large association that runs various largely independent institutes. ATHENE funds the work of researchers at its partner institutions and is very closely associated with TU Darmstadt, Goethe University Frankfurt, and the Darmstadt University of Applied Sciences (Hochschule Darmstadt). Looking back at its history, ATHENE evolved from CASED and EC SPRIDE, and was formerly named CRISP.
CASA is a Cluster of Excellence based at the Ruhr-University Bochum, funded by the BMBF under its Excellence Strategy. Such a cluster is a specialized research area that is regularly evaluated by international commissions.
CISPA is another Helmholtz Center, located in Saarbrücken. It is a single institution fully dedicated to cybersecurity. CISPA receives substantial funding from the BMBF and the State of Saarland. It cooperates with the Max Planck Institutes in Saarbrücken, Saarland University, and other universities. (The Max Planck Society is yet another non-university research institution, but it focuses entirely on basic science. Like Fraunhofer, it is a single umbrella organization that runs largely independent institutes). CISPA has constantly expanded into new buildings and has been managed by Michael Backes since its inception. Recently, CISPA made national news when Backes was suspended following allegations regarding Chinese researchers at CISPA accessing knowledge that may be sensitive and subject to export controls. Surely, a stressful time for the institution.
CODE is an institute of the UniBw München, which is a university of the German Armed Forces. Despite its name, the CODE research institute is fully dedicated to cybersecurity. It collaborates closely with LMU and TUM.
KASTEL is a triple-overloaded term; talking about KASTEL inevitably means talking about KIT (Karlsruhe Institute of Technology), my alma mater. First, KASTEL refers to an institute within the CS Department that encompasses security professors. Second, the KASTEL Research Labs represent an amalgamation of the KASTEL Institute and other security-related KIT research groups outside of the department. (Note that a Fraunhofer institute and a KIT institute do not mean the same thing). Third, KASTEL exists within the Helmholtz Association. Helmholtz is another non-university association, but it focuses on "big science." It is structured around independent research centers that are members of the association. Helmholtz coordinates the funding, but each center is funded independently by the federal government and the seat state. KIT holds a unique status because it is, somewhat paradoxically, both a university and a non-university Helmholtz center simultaneously. This is governed by state legislation, but the big science component is still federally funded, with the state acting as a pass-through entity. This third iteration of KASTEL includes other partners like Fraunhofer IOSB and the FZI. This is comparable to ATHENE. KIT conducts both university and non-university research well beyond the field of security.
ATHENE, CISPA, and KASTEL are closely considered by the same federal ministry. I do not know exactly how this funding is allocated within each institution, but each organization undergoes regular overall evaluations.
Honorable mentions: There is also a Max Planck Institute for Security and Privacy in Bochum. Fraunhofer AISEC in Munich started as a spinoff from Fraunhofer SIT during Claudia Eckert's tenure as SIT institute director. She now serves as the director of AISEC. The University of Bonn also boasts a strong cybersecurity output and collaborates with Fraunhofer FKIE and others.
I created a tier list template of the institutions mentioned above. Send me yours, and I will send you mine. I will update this post later with an aggregated tier list of these institutions. Send me additional institutions that you think should be included in the tier list. I will update the list and this post accordingly.
