Cyber insurance in Germany: Pitfalls in the claims settlement process
Cyber insurance in Germany: Pitfalls in the claims settlement process
Cyber attacks can threaten the very survival of businesses. Many companies therefore protect themselves with cyber insurance. However, these policies often do not cover all losses or contain hidden clauses.
Ihr Ansprechpartner
If a company falls victim to a cyber attack, this constitutes an insured event under German cyber insurance policies. The insured company expects to receive the cover it has purchased. At the same time, however, the cyber attack provides the cyber insurer with grounds to carry out a comprehensive review of the company’s risk management – and to reduce the insurance payout should any shortcomings be found. What can decision-makers do to ensure it does not come to this?
Claims settlement process
Claims settlement following cyber attacks is divided into various phases:
Phase 1: Crisis management
The first focus is on crisis management. The company attempts to assess the extent of the attack and to bring the attack – which may still be ongoing – to an end, often with the help of external service providers. The company then restores its operational capacity.
Phase 2: Loss Assessment
At the latest by the end of the acute crisis management phase, the cyber insurer begins to assess the extent of the loss and analyse the reasons for the successful cyber attack. In this phase, the cyber insurer usually requests comprehensive information and commissions third parties to assess the loss and the circumstances surrounding it.
Phase 3: Negotiations and settlement of the claim
Once the insurer has completed its assessment of the claim, negotiations usually begin between the company and its cyber insurer regarding the specific scope of the insurance cover. At this stage, many companies make mistakes that could easily be avoided.
Objection 1 – Breach of the duty of disclosure
As part of the claims settlement process, German cyber insurers always check whether the company provided incorrect answers to the questions asked prior to the conclusion of the cyber insurance contract and whether the cyber insurer is therefore exempt from paying benefits due to such – alleged – misrepresentation.
Duty of disclosure – what does this mean?
Before concluding a cyber insurance policy, the cyber insurer usually requires the company to answer a large number of questions designed to enable the insurer to assess the risk. For example, the insurer typically asks whether the company carries out regular updates and backups, and what other security measures (firewalls, MFA, etc.) the company has in place.
The company is then legally obliged (Section 19 of the German Insurance Contract Act (VVG)) to disclose the known circumstances relevant to the risk, as requested, to the cyber insurer (the so-called duty of disclosure). If the policyholder breaches this duty to disclose by providing a false answer due to gross negligence, the cyber insurer may rescind the insurance contract and the affected company will receive no insurance payout. It is precisely this significant legal consequence – no insurance payout – that thus creates considerable leverage in negotiations.
What arguments are helpful in the event of a dispute?
To verify whether the company answered a question incorrectly, the cyber insurer compares the findings of the forensic report with the answers provided prior to the conclusion of the contract and asks further questions. If the cyber insurer subsequently claims that the company answered a question incorrectly prior to the conclusion of the contract, it is important to contest this claim. Furthermore, the company should check whether the cyber insurer adequately informed the company of the legal consequences of providing an incorrect answer (in accordance with Section 19(5) of the German Insurance Contract Act (VVG)) and complied with the one-month withdrawal period (in accordance with Section 21(1) VVG). In addition, the company should seek to demonstrate that the alleged incorrect answer did not influence the cyber insurer’s settlement of the claim (so-called ‘counter-evidence of causality’).
Recommendations
Although this leaves the company with several arguments to counter the cyber insurer’s refusal to pay out, the mere threat of a complete withdrawal of cover often exerts considerable pressure. Decision-makers should therefore answer the cyber insurer’s questions carefully when purchasing a policy with a German cyber insurer.
Decision-makers should also avoid answering complex questions with a blanket ‘yes’ or ‘no’. Such absolute answers to questions that cannot be answered clearly make it easy for the insurer to later raise the objection that the duty to provide information has been breached.
An example: a company seeking insurance cover receives a questionnaire from the insurer. One question asks whether all the company’s servers are equipped with up-to-date operating systems. The company has five servers, four of which are running the latest version of the operating system. The fifth is running an operating system which, although it is an older version, will continue to receive updates and support from the manufacturer for a few more months. Can the company therefore answer ‘yes’ to the question about ‘up-to-date operating systems’ on all servers?
A company’s individual risk profile is often more complex than the questions suggest. In such cases, it is advisable to explain the specific situation in writing, including the key details, rather than simply ticking ‘yes’ or ‘no’.
Good forensic analysis can safeguard insurance cover
It is also crucial that the forensic report identifies the causes of the cyber attack as precisely as possible. In a dispute heard before the Regional Court of Tübingen between a company that had been attacked and its cyber insurer, the company was able to demonstrate, with the help of a forensic report, that the attack would still have been successful even if all updates had been carried out on time. It was therefore irrelevant that the company may have answered questions about updates incorrectly (Tübingen Regional Court, r+s 2023, 652).
Objection 2 – Breach of obligations
Another typical objection raised by cyber insurers is the claim that the insured company breached its contractual IT obligations.
What is a breach of IT obligations?
Most German cyber insurance policies contain IT-related obligations and require the policyholding company, for example, to carry out regular backups or to install updates without delay. If the company breaches such an obligation through gross negligence, the cyber insurer is entitled to a pro rata reduction in cover (pursuant to Section 28(2) of the German Insurance Contract Act (VVG)). An intentional breach of an obligation may even result in the company losing its insurance cover entirely.
Lines of defence
In addition to technical arguments as to how, contrary to the cyber insurer’s view, the obligation was fulfilled, the company may argue that the obligation is invalid or has been superseded by an individual agreement.
The company may also defend itself by arguing that no representative (persons listed in the insurance terms and conditions) breached the obligation through gross negligence, or that the breach of the obligation did not affect the settlement of the claim.
Recommendations
In addition to documenting the pre-contractual exchanges with the insurer – which is also key in this context – companies should have the validity of relevant obligations reviewed at an early stage by legal experts with experience in cyber insurance.
Furthermore, it is also important here to identify any other possible reasons for the successful cyber attack and to present these as part of the rebuttal of causality.
Objection 3 – The incident was caused through gross negligence
If a cyber attack was successful, it is clear that IT security was insufficient to prevent the attack. German cyber insurers sometimes use this realisation following any successful cyber attack as grounds to reduce cover on the basis of an alleged grossly negligent cause of the loss.
Grossly negligent causation of the loss
Under Section 81(2) of the German Insurance Contract Act (VVG), the cyber insurer is entitled to reduce its payment if the company caused the loss through gross negligence. From the insurer’s perspective, the company may be deemed to have caused the loss through gross negligence, for example, if the attackers exploited access that was not secured by multi-factor authentication (MFA).
Lines of defence
The company may object that the risk related circumstances (such as the absence of an MFA) already existed at the time the contract was concluded and that the insurer could have enquired about such circumstances. Section 81(2) of the Insurance Contract Act (VVG) does not oblige the company to improve the risk situation existing at the time the contract was concluded (Regional Court of Tübingen, r+s 2023, 652).
Recommendations
Many German insurers contractually waive the right to accuse the policyholder of causing the insured event. Such a waiver must be set out in writing in the policy conditions. The relevant clause has recently become the market standard. Policyholders should therefore request this waiver from their insurer or, failing that, switch insurers where possible.
Objection 4 – Inadequate evidence of loss
Even if the cyber insurer does not raise general objections to its liability, there is often a dispute over the amount of the restoration costs and the loss of business.
Demonstrating the loss
The company must demonstrate and prove the loss claimed. In practice, this is often difficult, as in the midst of a cyber attack the company usually has other priorities than accurately documenting the recovery costs – particularly when it is temporarily impossible to work on the systems. However, if the company cannot provide evidence of the specific recovery measures taken (such as overtime), the cyber insurer is not obliged to reimburse these recovery costs.
Furthermore, the precise calculation of the business interruption loss suffered is usually a matter of dispute. It is not uncommon for the loss adjusters commissioned by the cyber insurer to be closer to the insurer, as their regular client, than to the affected company.
Recommendations for action
It may be worthwhile for the affected company to have the business interruption loss assessed by an expert mandated by the policyholder as early as possible, or at least to ensure that a subsequent assessment is facilitated by having a sound set of data to hand.
Furthermore, preparation is crucial. The company should have physically stored contingency plans. External service providers should be familiar with the company even before a cyber attack occurs. If brought in at an early stage of the crisis, management consultants and solicitors can also provide valuable support with documentation and communication with the insurer.
Close coordination with the cyber insurer regarding the specific recovery measures is recommended. Measures approved by the insurer are, as a rule, also covered by the insurance policy.
Conclusion
The pitfalls on the path to a full settlement of a claim are manifold and should be identified and taken into account before an insurance contract is concluded. It is important to keep comprehensive written records of the contract negotiations and communications with the insurer. For businesses, the following applies: thorough preparation for a successful cyber attack not only minimises business interruption but also enables the insurance claim to be settled as effectively as possible. Furthermore, involving experts at an early stage – ideally those who are already familiar with the business prior to the cyber attack – increases the chances of a successful claim settlement.
This is an automatically generated translation of an article by David Ulrich, first published in the magazine "IT-Sicherheit" 05-2024
More News:
More News:
WILHELM Gründungsmitglied in internationalem Kanzlei-Netzwerk für Versicherungsnehmer
WILHELM Gründungsmitglied in internationalem Kanzlei-Netzwerk für Versicherungsnehmer
Die Sozietät WILHELM gehört zu den 14 Gründungsmitgliedern der neuen Global Policyholder Alliance, einem Netzwerk von Kanzleien, die in Deckungsstreitigkeiten die Versicherungsnehmer vertreten.
Behördliche Auflagen und Beschränkungen im Wiederaufbau: Mehrkostenersatz – mehr Ärger
Behördliche Auflagen und Beschränkungen im Wiederaufbau: Mehrkostenersatz – mehr Ärger
Wenn die Wiederherstellung nach einem Großschaden aufgrund neuer behördlicher Auflagen teurer wird, kommt die Mehrkostenversicherung zum Tragen. Was diese Versicherung deckt und was nicht, zeigt Tobias Wessel in seinem Beitrag.
Führungsklauseln im Fokus: OLG-Urteil gibt Orientierung
Führungsklauseln im Fokus: OLG-Urteil gibt Orientierung
Führungsklauseln bringen Ordnung in die offene Mitversicherung. Doch ihre Auslegung birgt Konfliktpotenzial. Von einem klarstellenden Urteil berichtet Dr. Fabian Herdter.
Handelsblatt-Ranking: Vier junge WILHELM-Anwälte unter den „Ones to Watch 2026“
Handelsblatt-Ranking: Vier junge WILHELM-Anwälte unter den „Ones to Watch 2026“
Mit drei Partnern, vier Associates und zwei Of Counseln ist unsere Sozietät im aktuellen Ranking „Deutschlands Beste Anwälte 2026“ von Handelsblatt und Best Lawyers vertreten.
Haftungsgefahren für Aufsichtsräte und der trügerische Versicherungsschutz
Haftungsgefahren für Aufsichtsräte und der trügerische Versicherungsschutz
Die Rechtsprechung und Schadenentwicklung der vergangenen Jahre zeichnet ein klares Bild: Längst ist die Haftung des Aufsichtsrats kein rein theoretisches Konstrukt mehr – und der Versicherungsschutz kein Selbstläufer. Dr. David Ulrich und Markus Hoffmann werfen einen Blick auf die aktuellen Entwicklungen.
Kritische Anlagen – kritische Haftung? Auswirkungen des KRITIS-Dachgesetzes
Kritische Anlagen – kritische Haftung? Auswirkungen des KRITIS-Dachgesetzes
Mit dem KRITIS-Dachgesetz soll systemrelevante Infrastruktur in Deutschland besseren Schutz erhalten. Welche Folgen das Gesetz für die Haftung und die Versicherung der Betreiber hat, erläutert Dr. Mark Wilhelm.
WILHELM erneut in Chambers und Legal 500 ausgezeichnet
WILHELM erneut in Chambers und Legal 500 ausgezeichnet
Laut Befragungen von Mandanten und Wettbewerbern gehört unsere Sozietät auch 2026 zu den führenden Kanzleien Deutschlands im Versicherungsrecht.
Streitfrage Fälligkeit – der steinige Weg vom Schadenfall zur Zahlung
Streitfrage Fälligkeit – der steinige Weg vom Schadenfall zur Zahlung
Wenn ein Schaden eintritt, erwartet der Versicherungsnehmer eine möglichst schnelle Kompensation vom Versicherer. Doch bis zur Fälligkeit des Versicherungsanspruchs sind einige Hürden zu nehmen, wie Johannes Laiblin in seinem Beitrag darlegt.
OLG Frankfurt: Bußgelder beim Vorstand regressierbar – Regress von D&O gedeckt
OLG Frankfurt: Bußgelder beim Vorstand regressierbar – Regress von D&O gedeckt
Das OLG Frankfurt bejaht die Möglichkeit der Unternehmen, ihnen auferlegte Geldbußen vom verantwortlichen Vorstand ersetzt zu bekommen. Grundsätzlich sei der Regress zudem auch von der D&O-Versicherung gedeckt.