Combating Abuse on the Internet in Germany – A Status Report
Patrick Ben Koetter of eco and sys4 AG, examines why Internet abuse is not primarily a legal problem, but a governance challenge requiring cooperation across the Internet ecosystem.
Image generated by AI
This article was originally published here and is republished with the author's permission.
Abuse encompasses many dimensions, and because abuse always involves the use of violence against a victimized person or organization, it is difficult to speak objectively and calmly about abuse or how to address it — it is simply associated with far too much harm, and the resulting pain evokes feelings of powerlessness, anger, and hatred.
In this article, I would like to discuss my work as head of the “Anti-Abuse” expert group at the eco Association. I want to write about what I have learned in more than 10 years as head of the group regarding the nature of combating abuse on the Internet, and why I believe that providers in the “Internet” market must assume they will soon be subject to regulation.
What do I mean when I speak of abuse?
Before I begin, I would like to provide a definition of abuse that I took from Wikipedia, so that it is clear what I am referring to when I use the term “abuse.”
Abuse is the act of improper usage or treatment of a person or thing, often to unfairly or improperly gain benefit. Abuse can come in many forms, such as: physical or verbal maltreatment, injury, assault, violation, rape, unjust practices, crimes, or other types of aggression. Some sources describe abuse as "socially constructed", which means there may be more or less recognition of the suffering of a victim at different times and societies. — Wikipedia (April 4, 2026)
When people speak of abuse in everyday life, the term is usually equated — quasi pars pro toto — with sexual abuse. This says a lot about the attention this particular form of abuse receives in our society, but this equation does not do justice to abuse, as I must write about it here, because the term is then too narrow.
When I speak of abuse in this article, I want us to bear in mind here and now that abuse extends not only to sexual abuse, but also to the “improper usage or treatment of a person or thing (…) such as: physical or verbal maltreatment, injury, assault, violation, rape, unjust practices, crimes, or other types of influence.” Defining this term so broadly is important for understanding the status quo of combating Internet abuse in Germany.
Who regulates abuse?
Politicians react almost reflexively when abuse has occurred, in public discourse and when the eyes of citizens turn to politics, by demanding laws or tougher laws. The reaction is emotionally understandable, as it demonstrates a willingness to act — an important trait for politicians — and aligns with the victims’ need for punishment. Exactly what those who suffer usually want.
From a legal perspective, however, such statements reveal a lack of expertise, as legal regulations already exist for most forms of abuse on the Internet.
A Criminal Code
The handling of abuse, which encompasses acts — to name just a few examples — such as theft, coercion, abuse of power and influence, or sexual abuse, is — as we can assume in democracies — already regulated. A country’s criminal code addresses these forms of abuse, regulates how they are handled, and entrusts authorities with prosecuting suspects and, upon proof of guilt, imposing an appropriate punishment.
Example 1. The Dilemma Facing Authorities
From conversations with investigators online, I have gotten the impression that the issue does not lie with the investigators’ motivation. Often, they lack the resources and expertise, and so suspects get away with it because they are faster, more knowledgeable, or better equipped.
For instance, it starts with the fact that requests for information are sometimes sent from personal email accounts to organizations because work email isn’t working at the moment. The urgency is clear, but any organization that takes its responsibility in responding to requests for information seriously must categorically refuse such inquiries, as they typically involve personal data, which may only be disclosed to authorized, identified individuals.
This is a very specific example, but it illustrates the motivation of law enforcement, their predicament, and the dilemma organizations face online when they want to assist in the prosecution of suspects.
I can just as well recall my ex-wife, who worked for a major internet service provider in Bavaria around 2010; she reported home in frustration that they were usually unable to respond to requests for information because the required log data had been deleted in accordance with the law after 7 days, but the request for information was not received until after that period had elapsed.
A Contract
And then there is the misuse of items — I’ll add services to that — which is also regulated online. Specifically, this is governed by the direct contractual relationship between customers and the company that provides its customers with resources and/or services. This contract specifies what the company has included in the agreement and what the customers have accepted.
For example, it might state that customers are not allowed to upload more than a certain amount of data within a specific time period, are not permitted to offer certain services to the general public via the company’s network, or are not allowed to open the on-site electrical cabinets and tap directly into the fiber-optic cable. Are you smiling? Have you ever seen the power distribution system in, say, Vietnam, where households, armed with knives and electrical tape and wearing no protective gear, “tap into” the local power distribution box? The same thing happens when it comes to the provision of IP and bandwidth on the Internet!
Nobody
And — now it gets interesting, because this brings me to the core message of my article — there is a legal space that is governed by neither state nor private law. This is the space where Internet market participants interact, where one depends on the other, but there is neither a state nor a private-sector regulation for dealing with abuse.
Such a situation arises, for example, when rights holders of soccer broadcasts encounter platform hosts who offer soccer matches illegally — that is, without paying licensing fees — as a streaming service.
There is no regulated legal relationship between the rights holders and the hosts. The rights holders want the stream to be shut down, and the hosts ask who will pay them to implement the measures. Usually, the rights holders fall back on the position that hosts must do so because it harms the rights holders. That is certainly true, but the host cannot pay its staff to shut down the streaming service based on a moral judgment of the abuse.
How has abuse prevention evolved in the Internet industry?
I entered the field of abuse prevention in the Internet industry around 2014 when I became head of the Anti-Abuse Competence Group at the eco Association. Since then and up to the present, the group has gone through the following phases.
Self-discovery and self-organization
I call this phase the founding era. The challenge facing the participants in this working group — who came from a wide variety of companies, both small and large — was the budget. How can we convey to our company leadership that abuse on our platform costs us a lot of money because we have to buy significantly more hardware and software than we need, spend an unnecessary amount of money on support, and lose customers because they feel let down and overwhelmed?
The breakthrough came when one member of the group began to view the situation from the perspective of company management and looked for business cases that demonstrated the necessity of the investment. And the answer was deceptively simple: if customers have to contact support just twice during their contract term to ask for help due to abuse, then it is no longer possible to make money from that customer, because the cost of support is so high that the profit margin is lost.
He presented this business case and was granted the budget to set up an anti-abuse team internally. Since then, measurable abuse originating from his employer’s network has dropped significantly and permanently to the per-thousand range, and the churn rate — customer attrition relative to the total customer base — has noticeably decreased because customers feel well-protected and in good hands.
With this approach, many participants returned to their companies and succeeded in establishing anti-abuse teams.
Anti-Abuse – an outdated term
“Anti-Abuse” is a loaded, imprecise, and negative term.
It is loaded because “abuse” is almost always equated with sexual abuse, and other forms of abuse are not recognized under the umbrella of the term “abuse.”
It is also imprecise because the term’s name does not make clear who is supposed to benefit from the fight against abuse. For example, does “anti-abuse” refer to DDoS countermeasures at the network level, when a provider’s network is to be overloaded with external requests, or does it refer to protecting customers from abuse?
And finally, it is negative in that it states what it is against, but not what it is for. In doing so, it emphasizes the threat — the abuse — rather than the benefit — customer security.
For some time now, the term “Customer Security” has therefore been gaining traction in the industry. It leaves room for many forms of abuse, specifies who the measure is intended for, and also who stands to benefit from them.
Service to Society
The second phase of combating Internet abuse is characterized by the joint action of Internet companies led by authorities such as the BSI (Federal Office for Information Security) for the benefit of society. This refers to simultaneous takedowns of malware-infected machines at customers’ sites, which — like worms through fruit — were eating their way through customer computers in the providers’ networks and threatened to cause massive, far-reaching damage.
They could only be stopped through a joint effort, and the actions were very successful. Not only because they were actually able to stop the spread of the malware, but also because the action was perceived very positively by the public. That was good for the companies, too.
Not my problem!
And that brings us to the current state of abuse prevention. One party suffers abuse, and another is expected to put a stop to it. Since the parties involved are companies, the business model of both companies dictates that money must change hands for the service to be provided. And that’s where the parties end up at odds.
The aggrieved party argues that it is the other party’s moral obligation “to take action,” and the party that could potentially put a stop to the abuse in question speaks up, saying it has received the report but cannot take action without compensation.
I witnessed this situation firsthand in Brussels during workshops involving rights holders from the U.S. movie industry, representatives of the hosting and DNS sectors, and the European Commission.
The reason for the meeting was the U.S. movie industry’s apparent effort to establish within EU policy the perception that any form of abuse constitutes DNS abuse. This is technically untenable, because no one in the offline world, for example, would think of holding the installers of place-name signs (DNS) responsible if bank robbers used those signs to find the local bank and rob it.
Politically, however, this is explosive, because if this lobby were to succeed in labeling every form of abuse as DNS abuse by analogy, then the US movie industry would only need to influence the IANA, the queen of all domain names — which, coincidentally, is under US control. And there, this technically incorrect generalization threatens to have dangerous consequences!
It would then be easy for the US movie industry to force hosting providers to comply by blocking their domains (→ IANA) to avoid payment. And because IANA is subject to US regulation and is not bound by EU law, this would — at least for an extended period and given current US policy, which perceives the US as a victim of other nations and seeks to enforce a protectorate for domestic industry through protective tariffs — create a dramatic situation for the EU internet industry.
In fact, this is about the misuse of products (in this case: movies), and it is solely up to the manufacturers to establish distribution channels that prevent misuse or render it insignificant. Ultimately, the music industry has also succeeded in distributing music over the internet in a way that allows it to make a living from it. I cannot see a moral obligation here.
Where is this heading?
Abuse is wrong. No matter what form of abuse it takes. The discussion about abuse on the Internet is usually conducted in a one-dimensional manner. This is understandable but does not do justice to the issue, because when measures to combat abuse are called for, the discussion usually focuses on laws rather than means. This is populist and does not improve the situation.
Many Internet companies invest in customer security because they have realized they can make money from it and protect their investments.
It remains to be seen how the fight against abuse among providers in the “Internet” market will unfold if one party suffers harm and another is required to invest money and working hours to mitigate that harm without compensation. Currently, it appears that the victims wish to enlist the state as a regulator.
In my view, this is a misguided development that could cause significant harm, potentially leading to economic warfare between nations. I very much hope that regulators recognize this insidious ambition and resist such attempts. In the business world, it is the manufacturer’s responsibility to secure distribution.
📚 Citation:
Koetter, Patrick Ben. (July 2026). Combating Abuse on the Internet in Germany: A Status Report. dotmagazine. https://www.dotmagazine.online/issues/building-the-internet-of-tomorrow-2026/combating-internet-abuse-germany-status-report
Patrick Ben Koetter is an email expert, and a board member of sys4 AG, which specializes in email, DNS, and the development of highly secure platforms and services. He contributes his knowledge and experience to eco as an expert and as Leader of the Email and Anti-Abuse Competence Groups.
FAQ
What is the main challenge in combating Internet abuse?
Patrick Koetter of sys4 explains that many forms of Internet abuse are already covered by criminal law or contractual rules. In his article for dotmagazine, published by eco – Association of the Internet Industry, he argues that the greater difficulty lies in unclear responsibilities between companies that have no direct legal relationship.
Why are new laws not always the most effective response to online abuse?
According to Patrick Koetter of sys4, the problem is often not the absence of legislation but the lack of resources, expertise, and workable procedures for enforcement. His dotmagazine article, published by eco – Association of the Internet Industry, emphasizes that practical implementation and cooperation can matter more than additional rules.
Why does the article prefer the term “Customer Security” to “Anti-Abuse”?
Patrick Koetter of sys4 argues that “Anti-Abuse” is broad, negative, and unclear about who benefits from the work. In dotmagazine, published by eco – Association of the Internet Industry, he presents “Customer Security” as a more precise term because it focuses on protecting users and improving service quality.
Why does Patrick Koetter warn against treating every form of online abuse as DNS abuse?
Patrick Koetter of sys4 argues that DNS is only one layer of Internet infrastructure and should not automatically be held responsible for every harmful activity online. His dotmagazine article, published by eco – Association of the Internet Industry, warns that overly broad definitions could shift liability to infrastructure providers that did not cause or control the underlying abuse.
Please note: The opinions expressed in articles published by dotmagazine are those of the respective authors and do not necessarily reflect the views of the publisher, eco – Association of the Internet Industry.