A security concept for savings banks requires a holistic view of physical and digital risks, aligned with statutory requirements such as KWG, MaRisk and the IT Security Act 2.0. Independent consulting supports threat and risk analysis, the planning of integrated system technology such as fire alarm systems (BMA) and intrusion detection systems (EMA), and ensuring legal compliance and manufacturer independence.

Independent planning and optimisation for physical and digital security

Financial institutions such as savings banks face complex security challenges that span both physical and digital threats. A robust security concept is not just a necessity but a strategic investment in future viability. Find out how independent consulting helps you master these challenges in a legally compliant and efficient way.

Key Takeaways

  • A holistic security concept for savings banks must consider physical and digital risks in an integrated way and align with KWG, MaRisk, BAIT and the IT Security Act 2.0.
  • Independent planning of system technology such as fire alarm systems (BMA), intrusion detection systems (EMA) and video surveillance to DIN and VdS standards is essential to avoid manufacturer dependency and optimise costs.
  • Security concepts are dynamic and require continuous threat analysis, risk assessment and adaptation to remain effective and legally compliant over the long term.

Ensuring security is of fundamental importance for financial institutions such as savings banks. It protects not only assets and data but also customer trust and the institution's reputation. As threats, both physical and in cyberspace, continue to grow and evolve, a well-considered and future-proof security concept is essential. This requires an in-depth analysis of the specific risk landscape, precise planning of system technology, and strict compliance with regulatory requirements. PLANATEL® has provided independent expertise for over 34 years to support savings banks in developing and implementing tailored security strategies.

Article image: Sicherheitskonzept Sparkasse Beratung - hero

The multi-layered requirements placed on security concepts for savings banks

As critical infrastructure (KRITIS) in the financial sector, savings banks face particular and multi-layered security requirements. These extend far beyond protection against traditional bank robberies and encompass a complex interplay of physical, organisational and information-technology risks. Maintaining business operations, protecting customer data and safeguarding liquidity are central objectives. A comprehensive security concept must therefore cover all relevant areas and be dynamically adapted to new threat scenarios.

The threat landscape for financial institutions is dynamic. While physical attacks on branches and cash machines continue to play a role, cyberattacks are increasing in quality and precision of targeting. According to the Cybersecurity Report for the first half of 2025, 40 percent of all repelled cyberattacks targeted banks and other financial service providers, underlining the sector's exposed position. This calls not only for robust IT security measures but also for close integration with physical protection concepts, for example to prevent unauthorised access to on-site IT infrastructure. The challenge lies in developing an integrated concept that effectively combines both preventive and reactive measures while taking account of each savings bank's specific circumstances. A generic solution rarely achieves the goal here, since branch structures, staff numbers and local risk factors can vary considerably.

Savings banks must also meet their customers' expectations for the highest security standards. Trust in the security of deposits and transactions is the foundation of banking business. Every security incident can cause not only financial but also significant reputational damage that undermines customer trust in the long term. Proactive, transparent security management is therefore a decisive competitive factor. PLANATEL® supports savings banks in translating these complex requirements into a coherent, actionable security concept that meets both statutory requirements and individual protection needs.

The financial sector in Germany is subject to one of the densest regulatory frameworks in the world. For savings banks, this means that every security concept must take into account the requirements of the Kreditwesengesetz (KWG), the Minimum Requirements for Risk Management (MaRisk) and the Supervisory Requirements for IT (BAIT) of the Federal Financial Supervisory Authority (BaFin), as well as the IT Security Act 2.0. These frameworks form the legal basis for the design and operation of security measures.

The Kreditwesengesetz (KWG) is the central law governing the regulation and supervision of banks and financial institutions in Germany. Among other things, it sets out capital requirements, risk management obligations and supervision by BaFin, in order to safeguard the stability of the financial system and protect investors. MaRisk gives concrete form to these requirements and provides a principles-based framework for managing all material risks. Among other things, it requires the establishment of an appropriate risk management system and the definition of processes for risk identification, assessment, control and monitoring. BaFin published the currently applicable version as Circular 06/2024 (BA).

BAIT in turn gives concrete form to the MaRisk requirements specifically for information technology. It sets out detailed requirements for IT security, IT risk management, IT contingency management and physical information security, including perimeter and building protection. Since the amendment of 16 August 2021, the chapters on "operational information security" and "IT contingency management" in particular have been expanded, requiring seamless documentation and regular review of IT structures and security measures. The IT Security Act 2.0, which came into force in May 2021, strengthens the powers of the Federal Office for Information Security (BSI) and widens the circle of critical infrastructure. It obliges operators to register with the BSI, report certain disruptions, and ensure minimum standards for IT security in order to detect and repel cyberattacks at an early stage. Violations can be punished with fines of up to 20 million euros. PLANATEL® supports savings banks in integrating these complex regulatory requirements into a practicable, legally compliant security concept.

Holistic threat analysis and risk assessment as the foundation

An effective security concept always begins with a comprehensive threat analysis and risk assessment. This is the cornerstone for identifying a savings bank's specific vulnerabilities and potential attack vectors, and defining targeted protective measures on that basis. Such an analysis goes beyond a mere checklist exercise and requires a deep understanding of the business models, infrastructure and operational processes involved.

PLANATEL® follows a structured approach to risk assessment that takes into account both physical and digital risks. First, the assets worth protecting are identified, from cash holdings and customer data to IT systems and the institution's reputation. A systematic survey of potential threats follows, ranging from burglary and robbery to cyberattacks such as phishing and ransomware, through to natural disasters. Internal risks such as human error or sabotage are not disregarded either. For the financial sector, the increasing professionalisation of cybercriminals and the use of global cloud infrastructure to conceal attacks are particularly relevant developments that must be taken into account in the analysis.

Risks are assessed by estimating the probability of occurrence and the potential extent of damage. This also considers the interactions between different risk areas. For example, a physical break-in can pave the way for a cyberattack if on-site IT systems are compromised. Based on this detailed analysis, protection objectives are defined and measures prioritised to ensure an acceptable level of risk. This enables management to make well-founded decisions about investment in security measures and to deploy resources efficiently. Regular review and adjustment of this risk assessment is essential, as threats and technologies continuously evolve. PLANATEL® offers the expertise to carry out these complex analyses and create a solid basis for your security concept.

Article image: Sicherheitskonzept Sparkasse Beratung - mid

Planning integrated system technology: from fire alarm systems to access control

A well-founded threat analysis and risk assessment is followed by the detailed planning of the technical system technology that forms the backbone of every security concept. PLANATEL® focuses here on the manufacturer-independent design and integration of systems that meet the highest standards and norms. This includes fire alarm systems (BMA), intrusion detection systems (EMA), video surveillance systems, access control systems, evacuation systems and security management systems (GMS).

For fire alarm systems (BMA), compliance with DIN 14675 and DIN VDE 0833-2 is of decisive importance. These standards set out the requirements for planning, installation, operation and servicing of BMA and are essential for protecting people and property in buildings. PLANATEL® plans BMA concepts that ensure early fire detection and effective alarming, taking into account integration with evacuation systems in line with DIN VDE 0833-4. For intrusion detection systems (EMA) and video surveillance systems, we are guided by VdS guidelines, such as VdS 2472 for banks and savings banks, which contain rules and recommendations for protection against burglary and robbery. A sensible link between EMA and specialised video systems is a key objective here, so as to be effective both preventively and as evidence in the event of an incident.

Access control systems are essential for regulating and logging access to sensitive areas. These systems are planned taking into account a savings bank's specific security zones, in order to prevent unauthorised access while ensuring smooth operations. Integrating all these individual systems into a higher-level security management system (GMS) enables central monitoring, control and coordination of all security functions. This optimises response times to incidents and improves the overall efficiency of the security concept. PLANATEL® plans these systems not only to the current state of the art but also with future expandability and scalability in mind, to ensure long-term investment security. We place great value on selecting certified components and complying with all relevant standards, to guarantee the highest reliability and legal compliance.

The importance of independent consulting for future-proof security strategies

The complexity of modern security requirements and the rapid development of technical solutions make independent, manufacturer-neutral consulting indispensable for savings banks. Without such expertise, there is a risk of investing in expensive, inefficient standalone solutions or becoming dependent on a manufacturer, which limits cost efficiency and flexibility in the long run. PLANATEL® has positioned itself since 1992 as a 100% independent and financially independent partner that acts exclusively in the customer's interest.

A central benefit of independent consulting lies in manufacturer independence. We receive no commissions from manufacturers or installers and are therefore free to select the best technologies and products for a savings bank's specific needs. This makes it possible to develop tailored solutions that are optimally matched to individual requirements rather than aimed at selling particular products. Selecting certified, interoperable systems is decisive here in ensuring high quality and future viability of the security concept.

Independent consulting also contributes significantly to cost optimisation. Precise requirements analysis and efficient planning avoid unnecessary investment and make optimal use of existing infrastructure. We support the creation of transparent tender documents, the evaluation of bids and contract negotiations, to secure the best possible terms for our customers. This also includes optimising maintenance concepts and selecting certified installers who ensure the reliable long-term function of the system technology. Avoiding manufacturer dependency is a strategic goal that strengthens a savings bank's flexibility and negotiating position over the long term. With over 34 years of experience planning complex infrastructure, PLANATEL® provides the assurance that your security concept will hold not only today but also in the future, and can adapt to new circumstances.

Digital security and IT infrastructure in focus

Alongside physical security, digital security is of existential importance for savings banks. The increasing digitalisation of banking, online banking and networked systems opens up new attack surfaces that require a robust IT security concept. The BaFin circulars MaRisk and BAIT set out detailed requirements here, ranging from management down to operational IT security.

A key aspect is protecting the IT infrastructure against cyberattacks. This includes measures for network security, cryptography, identity and rights management, and logging. Implementing attack detection systems (SzA) and security operations centres (SOC) is highly important for KRITIS operators such as savings banks, in order to detect and repel cyberattacks at an early stage. The Cybersecurity Report 2025 shows that the financial sector remains a prime target for cybercriminals, with attacks becoming ever more sophisticated. Continuous monitoring and rapid response capability are therefore crucial. PLANATEL® advises on designing these systems and integrating them into a comprehensive security concept that also takes into account the interfaces with physical security.

Another critical area is data protection. The General Data Protection Regulation (GDPR) and the new Federal Data Protection Act (BDSG neu) place high demands on the handling of personal data belonging to customers and employees. Savings banks must ensure that their data processing procedures are legally compliant and that suitable technical and organisational measures are in place to protect that data. This also includes protection against data leaks and unauthorised access. In its "Risks in Focus 2025" report, BaFin also highlighted physical risks, such as extreme weather events, as relevant to risk management at financial institutions, since these can indirectly affect IT infrastructure as well. PLANATEL® supports savings banks in developing a holistic concept that comprehensively covers both IT security and data protection and strengthens resilience against digital and physical threats.

Project management and quality assurance during implementation

Planning a comprehensive security concept is the first step; successful implementation and ensuring long-term functionality are equally decisive. PLANATEL® accompanies savings banks throughout the entire project cycle, from detailed planning through acceptance and beyond, to ensure smooth implementation and the highest quality. Our approach to project management is geared towards precisely defining the goals and milestones set and communicating progress continuously.

During the implementation phase, we act as an independent partner ensuring coordination between all parties involved, from the savings bank's internal departments to the selected installers. This includes monitoring compliance with the planning specifications, schedules and budget. We ensure that the installation of fire alarm systems, intrusion detection systems, video surveillance and access control systems complies with the DIN standards, VdS guidelines and the specific requirements of the security concept. Selecting certified installers is a critical success factor here in guaranteeing the quality of execution.

A further focus is on quality assurance and the acceptance inspection of the installed systems. PLANATEL® carries out detailed acceptance tests to verify correct function and compliance with all contractual and normative requirements. This also includes the operational-principle test of security management systems, to ensure that in an emergency all components work together as intended. Finally, a careful review of the final invoices is carried out to ensure financial transparency and compliance with the agreed terms. Through this comprehensive project management and strict quality assurance, PLANATEL® ensures that the security concept delivers its full effect not just on paper but in practice, and provides a high level of protection over the long term.

Continuous optimisation and adaptation of security concepts

A security concept is not a static document but a living system that requires continuous review, adaptation and optimisation. The threat landscape is constantly evolving, new technologies emerge, and regulatory requirements can change. For savings banks, it is therefore essential to regularly put their security concept to the test, in order to ensure its long-term effectiveness and be able to respond proactively to new challenges.

PLANATEL® supports savings banks in establishing a process for continuous optimisation. This begins with regular audits and reviews of existing system technology and processes. Not only technical aspects such as the functionality of fire alarm systems or video surveillance systems are assessed, but also organisational procedures and staff awareness. Lessons learned from real incidents or simulated attacks feed into this assessment, to identify vulnerabilities and uncover potential improvements. Insights from Bitkom's "Wirtschaftsschutz 2025" report, which examines the development of cybercrime and industrial espionage in Germany, can, for example, provide valuable pointers for adjustments.

Adapting the security concept can include integrating new technologies, updating software and hardware, or revising contingency plans. Changes to a savings bank's branch structure or range of services can also make adjustments necessary. PLANATEL® advises on the strategic further development of the security concept, to ensure it always reflects the current state of the art and the latest regulatory requirements. This also includes planning maintenance concepts that ensure preventive servicing and rapid fault resolution. Through this proactive approach to continuous optimisation, savings banks not only safeguard their investment in security but also strengthen their resilience against future threats and preserve the trust of their customers and supervisory authorities. Our more than 34 years of experience allow us to develop long-term, sustainable strategies.

Article image: Sicherheitskonzept Sparkasse Beratung - bottom

Next step

Contact us for a no-obligation initial consultation.

PLANATEL®: Independent planning and consulting since 1992
Tel: 040 / 23 73 02-30
E-Mail: info@planatel.de

Frequently asked questions

What are the core components of a threat analysis for a savings bank?

The core components of a threat analysis for a savings bank include identifying the assets worth protecting (e.g. cash, data, IT systems), systematically surveying potential threats (e.g. burglary, cyberattacks, natural disasters), and assessing vulnerabilities. The probability of occurrence and the potential extent of damage are then estimated for each risk, in order to define protection objectives and prioritise measures. This forms the basis for a targeted security concept.

How does PLANATEL® support the selection and integration of security systems?

PLANATEL® supports the selection and integration of security systems through manufacturer-neutral, independent consulting. We produce detailed planning concepts for fire alarm systems (BMA), intrusion detection systems (EMA), video surveillance and access control that meet the highest standards (e.g. DIN, VdS). Our focus is on creating integrated solutions that are optimally coordinated with one another and enable efficient control via security management systems. We select certified installers and accompany implementation through to acceptance.

What role does the IT Security Act 2.0 play for savings banks?

The IT Security Act 2.0 is highly significant for savings banks as operators of critical infrastructure (KRITIS). It strengthens the powers of the BSI and obliges savings banks to register, report disruptions, and implement minimum standards for IT security, including the use of attack detection systems. The aim is early detection and defence against cyberattacks, with violations punishable by substantial fines.

Why is a holistic approach to physical and digital security important?

A holistic approach is crucial because physical and digital risks are often interlinked. A physical break-in, for example, can provide access to IT systems, while cyberattacks can impair the control of physical security systems. Integrating both areas into a comprehensive security concept enables more effective prevention, faster response, and greater overall resilience for the savings bank against diverse threats.

How can manufacturer dependency in security systems be avoided?

Manufacturer dependency can be avoided through independent, manufacturer-neutral planning. PLANATEL® operates without commissions and selects systems based on the best technical and economic criteria. This includes specifying open interfaces, selecting interoperable components, and producing detailed tenders that promote competition. This ensures the savings bank remains flexible in the long term and is not tied to a single provider.

For security concepts at savings banks, the primary frameworks are the Kreditwesengesetz (KWG), the Minimum Requirements for Risk Management (MaRisk) and the Supervisory Requirements for IT (BAIT) from BaFin, as well as the IT Security Act 2.0. These frameworks define the scope for physical and digital security measures and risk management at financial institutions.

Why is manufacturer neutrality important in consulting for savings banks?

Independent consulting that receives no commissions can objectively select the best technologies and products without being tied to particular providers. This avoids manufacturer dependency and safeguards a savings bank's long-term flexibility and investment optimisation.

What role do fire alarm systems (BMA) play in a savings bank's security concept?

Fire alarm systems (BMA) are an integral part of a savings bank's security concept. They serve to protect people and property through early fire detection and alarming. The planning and operation of BMA must comply with the strict requirements of DIN 14675 and DIN VDE 0833-2, to ensure legal compliance and maximum safety.

How often should a savings bank's security concept be reviewed and adapted?

A savings bank's security concept should be continuously reviewed and adapted regularly, at least annually, to the constantly evolving threat landscape, new technologies and changing regulatory requirements. This ensures the long-term effectiveness and legal compliance of the protective measures and strengthens the institution's resilience.

Sources and further information

  • IT-Consulting – S-Management Services
  • IT-Sicherheit | Sparkasse Nürnberg
  • IT-Sicherheit im Unternehmen: Schlüssel zum Schutz sensibler Daten – Sparkasse
  • Sicherheit von Tresorräumen prüfen lassen | VdS Security Expertise
  • Datenschutz – Sparkassen Consulting