Cyber insurance in Germany: Pitfalls in the claims settlement process

Cyber attacks can threaten the very survival of businesses. Many companies therefore protect themselves with cyber insurance. However, these policies often do not cover all losses or contain hidden clauses.

If a company falls victim to a cyber attack, this constitutes an insured event under German cyber insurance policies. The insured company expects to receive the cover it has purchased. At the same time, however, the cyber attack provides the cyber insurer with grounds to carry out a comprehensive review of the company’s risk management – and to reduce the insurance payout should any shortcomings be found. What can decision-makers do to ensure it does not come to this?

Claims settlement process

Claims settlement following cyber attacks is divided into various phases:

Phase 1: Crisis management

The first focus is on crisis management. The company attempts to assess the extent of the attack and to bring the attack – which may still be ongoing – to an end, often with the help of external service providers. The company then restores its operational capacity.

Phase 2: Loss Assessment

At the latest by the end of the acute crisis management phase, the cyber insurer begins to assess the extent of the loss and analyse the reasons for the successful cyber attack. In this phase, the cyber insurer usually requests comprehensive information and commissions third parties to assess the loss and the circumstances surrounding it.

Phase 3: Negotiations and settlement of the claim

Once the insurer has completed its assessment of the claim, negotiations usually begin between the company and its cyber insurer regarding the specific scope of the insurance cover. At this stage, many companies make mistakes that could easily be avoided.

Objection 1 – Breach of the duty of disclosure

As part of the claims settlement process, German cyber insurers always check whether the company provided incorrect answers to the questions asked prior to the conclusion of the cyber insurance contract and whether the cyber insurer is therefore exempt from paying benefits due to such – alleged – misrepresentation.

Duty of disclosure – what does this mean?

Before concluding a cyber insurance policy, the cyber insurer usually requires the company to answer a large number of questions designed to enable the insurer to assess the risk. For example, the insurer typically asks whether the company carries out regular updates and backups, and what other security measures (firewalls, MFA, etc.) the company has in place.

The company is then legally obliged (Section 19 of the German Insurance Contract Act (VVG)) to disclose the known circumstances relevant to the risk, as requested, to the cyber insurer (the so-called duty of disclosure). If the policyholder breaches this duty to disclose by providing a false answer due to gross negligence, the cyber insurer may rescind the insurance contract and the affected company will receive no insurance payout. It is precisely this significant legal consequence – no insurance payout – that thus creates considerable leverage in negotiations.

What arguments are helpful in the event of a dispute?

To verify whether the company answered a question incorrectly, the cyber insurer compares the findings of the forensic report with the answers provided prior to the conclusion of the contract and asks further questions. If the cyber insurer subsequently claims that the company answered a question incorrectly prior to the conclusion of the contract, it is important to contest this claim. Furthermore, the company should check whether the cyber insurer adequately informed the company of the legal consequences of providing an incorrect answer (in accordance with Section 19(5) of the German Insurance Contract Act (VVG)) and complied with the one-month withdrawal period (in accordance with Section 21(1) VVG). In addition, the company should seek to demonstrate that the alleged incorrect answer did not influence the cyber insurer’s settlement of the claim (so-called ‘counter-evidence of causality’).

Recommendations

Although this leaves the company with several arguments to counter the cyber insurer’s refusal to pay out, the mere threat of a complete withdrawal of cover often exerts considerable pressure. Decision-makers should therefore answer the cyber insurer’s questions carefully when purchasing a policy with a German cyber insurer.

Decision-makers should also avoid answering complex questions with a blanket ‘yes’ or ‘no’. Such absolute answers to questions that cannot be answered clearly make it easy for the insurer to later raise the objection that the duty to provide information has been breached.

An example: a company seeking insurance cover receives a questionnaire from the insurer. One question asks whether all the company’s servers are equipped with up-to-date operating systems. The company has five servers, four of which are running the latest version of the operating system. The fifth is running an operating system which, although it is an older version, will continue to receive updates and support from the manufacturer for a few more months. Can the company therefore answer ‘yes’ to the question about ‘up-to-date operating systems’ on all servers? 

A company’s individual risk profile is often more complex than the questions suggest. In such cases, it is advisable to explain the specific situation in writing, including the key details, rather than simply ticking ‘yes’ or ‘no’.

Good forensic analysis can safeguard insurance cover

It is also crucial that the forensic report identifies the causes of the cyber attack as precisely as possible. In a dispute heard before the Regional Court of Tübingen between a company that had been attacked and its cyber insurer, the company was able to demonstrate, with the help of a forensic report, that the attack would still have been successful even if all updates had been carried out on time. It was therefore irrelevant that the company may have answered questions about updates incorrectly (Tübingen Regional Court, r+s 2023, 652).

Objection 2 – Breach of obligations

Another typical objection raised by cyber insurers is the claim that the insured company breached its contractual IT obligations.

What is a breach of IT obligations?

Most German cyber insurance policies contain IT-related obligations and require the policyholding company, for example, to carry out regular backups or to install updates without delay. If the company breaches such an obligation through gross negligence, the cyber insurer is entitled to a pro rata reduction in cover (pursuant to Section 28(2) of the German Insurance Contract Act (VVG)). An intentional breach of an obligation may even result in the company losing its insurance cover entirely.

Lines of defence

In addition to technical arguments as to how, contrary to the cyber insurer’s view, the obligation was fulfilled, the company may argue that the obligation is invalid or has been superseded by an individual agreement.

The company may also defend itself by arguing that no representative (persons listed in the insurance terms and conditions) breached the obligation through gross negligence, or that the breach of the obligation did not affect the settlement of the claim.

Recommendations 

In addition to documenting the pre-contractual exchanges with the insurer – which is also key in this context – companies should have the validity of relevant obligations reviewed at an early stage by legal experts with experience in cyber insurance.

Furthermore, it is also important here to identify any other possible reasons for the successful cyber attack and to present these as part of the rebuttal of causality.

Objection 3 – The incident was caused through gross negligence

If a cyber attack was successful, it is clear that IT security was insufficient to prevent the attack. German cyber insurers sometimes use this realisation following any successful cyber attack as grounds to reduce cover on the basis of an alleged grossly negligent cause of the loss.

Grossly negligent causation of the loss

Under Section 81(2) of the German Insurance Contract Act (VVG), the cyber insurer is entitled to reduce its payment if the company caused the loss through gross negligence. From the insurer’s perspective, the company may be deemed to have caused the loss through gross negligence, for example, if the attackers exploited access that was not secured by multi-factor authentication (MFA).

Lines of defence

The company may object that the risk related circumstances (such as the absence of an MFA) already existed at the time the contract was concluded and that the insurer could have enquired about such circumstances. Section 81(2) of the Insurance Contract Act (VVG) does not oblige the company to improve the risk situation existing at the time the contract was concluded (Regional Court of Tübingen, r+s 2023, 652).

Recommendations

Many German insurers contractually waive the right to accuse the policyholder of causing the insured event. Such a waiver must be set out in writing in the policy conditions. The relevant clause has recently become the market standard. Policyholders should therefore request this waiver from their insurer or, failing that, switch insurers where possible.

Objection 4 – Inadequate evidence of loss

Even if the cyber insurer does not raise general objections to its liability, there is often a dispute over the amount of the restoration costs and the loss of business.

Demonstrating the loss

The company must demonstrate and prove the loss claimed. In practice, this is often difficult, as in the midst of a cyber attack the company usually has other priorities than accurately documenting the recovery costs – particularly when it is temporarily impossible to work on the systems. However, if the company cannot provide evidence of the specific recovery measures taken (such as overtime), the cyber insurer is not obliged to reimburse these recovery costs.

Furthermore, the precise calculation of the business interruption loss suffered is usually a matter of dispute. It is not uncommon for the loss adjusters commissioned by the cyber insurer to be closer to the insurer, as their regular client, than to the affected company.

Recommendations for action

It may be worthwhile for the affected company to have the business interruption loss assessed by an expert mandated by the policyholder as early as possible, or at least to ensure that a subsequent assessment is facilitated by having a sound set of data to hand.

Furthermore, preparation is crucial. The company should have physically stored contingency plans. External service providers should be familiar with the company even before a cyber attack occurs. If brought in at an early stage of the crisis, management consultants and solicitors can also provide valuable support with documentation and communication with the insurer.

Close coordination with the cyber insurer regarding the specific recovery measures is recommended. Measures approved by the insurer are, as a rule, also covered by the insurance policy.

Conclusion

The pitfalls on the path to a full settlement of a claim are manifold and should be identified and taken into account before an insurance contract is concluded. It is important to keep comprehensive written records of the contract negotiations and communications with the insurer. For businesses, the following applies: thorough preparation for a successful cyber attack not only minimises business interruption but also enables the insurance claim to be settled as effectively as possible. Furthermore, involving experts at an early stage – ideally those who are already familiar with the business prior to the cyber attack – increases the chances of a successful claim settlement.

This is an automatically generated translation of an article by David Ulrich, first published in the magazine "IT-Sicherheit" 05-2024

Beitrag teilen:

More News: