How Borussia Dortmund's IT Chief Makes the Case for Cybersecurity

Written by

Borussia Dortmund is one of world football's most recognizable brands, attracting millions of fans globally and packing more than 80,000 supporters into its historic Westfalenstadion on home matchdays.

Behind the scenes, the Bundesliga giant faces many of the same cybersecurity challenges as any other organization, alongside a unique set of risks that come with operating a major sports institution.

From protecting sensitive player contract data and securing critical matchday infrastructure to defending against disruptive attacks from rival fans and managing a complex array of business operations, Borussia Dortmund's IT team is responsible for far more than keeping systems online.

Speaking to Infosecurity at ESET World 2026 in Berlin, David Kemkpen, head of IT at Borussia Dortmund (BVB), discussed the club's evolving cyber strategy and partners it is working with, the growing threat posed by AI-enabled attacks and how to make the case for cybersecurity to the wider business.

David Kemkpen, head of IT at Borussia Dortmund
David Kemkpen, head of IT at Borussia Dortmund

Infosecurity Magazine: What do you think are some of the cybersecurity challenges you would describe as unique to a football club like Borussia Dortmund?

David Kemkpen: We have the fan aspect in the stadium and of course they are very passionate and sometimes people do interesting stuff. But we also have other clubs’ fans that might want to disrupt our operations – especially on match days.

It makes us an interesting target because if you are the one to bring down our website on a match day for example, you get bragging rights. There have been attempts before but fortunately we have a very ‘spike’ orientated infrastructure which can handle large peaks of incoming traffic and requests.

A private person without access to sophisticated methods doesn't have the capability to cause disruption. It’s a thing of the past because it just gets drowned out in the other traffic.

If one guy is trying to DDoS us among hundreds of thousands of other people trying to access our website, it’s not much difference in the traffic. We've not experienced any major attacks so far on that front, and we’ve not been the target of sophisticated attacks in that manner.

However, it could be just a question of time because these things are more accessible than ever. It is something we must keep in mind when we are planning our infrastructure.

IM: Outside of the fan aspect, what are the cybersecurity priorities for BVB as a business?

DK: The ‘business units’ of other industries are very focused on their singular tasks and don’t have to manage quite as many assets as we have, including the stadium and training grounds. They post a unique challenge regarding security, both physical and cyber.

We have many business units which are unusual for a company of our size. In Germany we’d be classed as a small-to-medium sized company.

However, we have a lot of things companies comparable to us do not have. We do our own video production, have our own press department and we must handle all the assets. This means the IT department is unusually large for a company of this size simply because of all the different requirements.

On top of that, football organizations, like UEFA, FIFA and the Deutsche Fußball Liga, have demands if we want to host local events or participate in tournaments. For instance, we have to bring the correct network infrastructure and security as well. They are asking for increased amounts of cybersecurity.

We are well equipped in this regard but with some of the smaller clubs, it’s not a focus for them.

Sometimes we have to fight to get these things because we are a football club, and when the IT department raises their hand and says ‘we have to do something about this’ it’s not necessarily on the minds of the CEOs most of the time because they are focused on the actual business of football.

IM: How have you been able to communicate cybersecurity needs to the wider business?

DK: Some topics appear in the foreground of a discussion for various reasons and if you have access to the people ‘up top’ so to speak, and they are focused on that specific topic, you have to take the opportunity.

But often we are successful by talking about risk and chances. We talk about business cases and if we can say we are able to allow departments to do certain things, that is obviously appealing to them.

For day-to-day security, we have to talk about risks to our capital, to the players and the assets. And of course, the match days – they are like the Holy Grail. If anything goes wrong then it’s immediately public knowledge, you could see it on live TV! For example, if the digital banners were hacked then you’d see that immediately and you’d have no time to react.

“The match days – they are like the Holy Grail. If anything goes wrong then it’s immediately public knowledge, you could see it on live TV!”

This is the kind of discussion we have with the business where we say that if that is something that you are afraid of, that you value highly, then we have to do something about it.

IM: What cybersecurity threats are of top concern for you today?

DK: We are basically exposed to the same threats as everyone else because we are a medium-sized company and we have the same cash flow and assets to be an interesting target in that regard.

We see typical CEO fraud where someone asks for a transfer of funds via gift cards for example, we actually had that happen to us and luckily the colleague alerted us before taking action.

This stuff happens and you must be aware of it. Especially as people are so focused on the sports side of things, they do not typically have much technical affinity. You have to advise on a lot of this stuff.

This is especially critical with footballer contracts. This is obviously a very sensitive matter and we’re talking about millions of euros being handled and written down in various clauses. If someone were to access and make these contracts public it would cause a huge issue, not just for us but for other clubs as well.

Also, state actors is an interesting area. We did a charity game against the Dynamo Kyiv team from Ukraine during an early phase of the conflict between Ukraine and Russia. We were advised by ESET, our cybersecurity partners, that this could cause us to be a target for Russian hackers.

This of course concerned us greatly, but luckily, we didn’t notice anything unusual. It has been years since then, but it was obviously something we had to keep in mind.

IM: You mentioned before you partnered with ESET cybersecurity was a more manual job, how has partnering with them helped you overcome these challenges?

DK: We did have an antivirus program before, but it didn’t offer the capabilities that ESET offers us, it’s a lot more useable. It has been a couple of years since the IT department has started to put more focus on cybersecurity and we have become drastically better in that regard.

It is an ongoing process and one of the measures to improve our capabilities in that regard was choosing a different vendor for these kinds of products. One that has more capabilities and is willing to work with us and talk about our unique challenges.

I wouldn’t say we were lost but we just weren’t experienced enough to evaluate what makes sense, what doesn’t and where to focus first.

We needed to know how to configure the policies so they make sense without breaking everything. ESET was very forthcoming in that regard, because they were partners as well. The deal was more like a reciprocal thing. We profited greatly from their willingness and ability to advise us on these matters.

IM: What does the BVB IT/cybersecurity team look like today?

DK: We are about 30 to 40 people right now, but we are constantly growing because we are putting people in key positions that we have been lacking. One of the positions that we think we need in the future is dedicated security people, because right now it's a group effort.

For instance, we have a guy that does the firewall stuff as well as his other tasks.

I'm handling the ESET product together with another colleague, but he's first level support. I'm more like a team lead and second level support.

We have people that take care of the network security, so it's distributed to different people according to their skill fields. It makes sense because the people that are taking care of network security are the network admins.

But we are trying to figure out if we need more dedicated people as we grow, the attention grows, and the challenges the environment or world poses grow.

What’s Hot on Infosecurity Magazine?