Germany calls on administrators to implement security.txt on their websites
Security.txt would boost responsible vulnerability disclosure and improve Germany’s cyber resilience.

By Shutterstock
- Germany’s cybersecurity agency urged website operators to publish security.txt files to improve vulnerability reporting.
- Security.txt gives researchers and response teams clear contact details, helping organizations fix security flaws faster.
- Only 1.8% of German website operators currently use security.txt, despite BSI calling implementation simple and low effort.
- BSI says wider use would strengthen cyber resilience and reduce the time attackers have to exploit vulnerabilities.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany’s cybersecurity agency, is asking businesses and organizations to publish a security.txt file on their websites.
Security.txt is a standardized text file that companies and organizations can publish on their web servers. The file was initially designed by ethical hackers who discovered a vulnerability and wished to report it to the organization in question.
Finding the right contact person often proved time-consuming. As a result, valuable time was lost, giving threat actors, hackers, and cybercriminals more time to exploit the newly found vulnerability.
A security.txt file, containing all relevant details to report a bug or vulnerability, would significantly shorten the search for the correct contact information. In addition, it would help developers immensely to spring into action to patch the security vulnerability.
Not only does this reduce the likelihood that victims will fall prey to the exploit, but it also improves the digital resilience of a company or organization. Additionally, it provides security researchers, Computer Emergency Response Teams (CERTs), and other reporting entities with the appropriate means to contact a company when a vulnerability is discovered.
There are many good reasons for businesses and organizations to publish a security.txt document. However, according to the BSI, only 1.8% of website operators and owners in Germany currently provide a security.txt file.
The effort is minimal, but the benefits for a company’s IT security are considerable,the cybersecurity agency says in a press release.
The implementation itself is extremely simple: website operators are required only to provide the contact information for a specific person and the expiration date. Furthermore, the file must be accessible via the path /.well-known/security.txt.
“It’s one of the easiest IT security measures to implement,” the BSI reassures.
The agency and the Alliance for Cybersecurity call upon webmasters, administrators, and website owners to publish a security.txt file on their websites.
In some EU member states, such as the Netherlands, government entities such as municipalities, provinces, water utility companies, and executive bodies are required to implement security.txt.
Other public-sector institutions are recommended to implement the security standard.