Skip to content
Call, 0511 – 47 55 58 11

Practice area

IT security law: cybersecurity and cybercrime

IT security law is spread across several statutes, regulations and directives, from the BSI Act through the NIS2 implementation to the Cyber Resilience Act.

IT security law has moved from a peripheral question to a duty of management. We handle the legal side of that, from Hannover and together with the affiliated consultancy for the operational work.

Your firm for IT security law

When the emergency happens

After an attack several notification duties run alongside one another, with different addressees and different deadlines. Knowing the order in advance means not losing the first hours to sorting out who is responsible.

  1. Step 1: Secure and document the situation

    Preserve evidence, record the incident and log the decisions. Whatever is not documented now will be missing later towards the authority, the insurer and contractual partners.

  2. Step 2: Check notification duties

    Data protection authority, BSI, contractual partners, insurers and where applicable law enforcement. Which duty applies depends on sector, exposure and the data involved.

  3. Step 3: Notify and communicate

    We draft the notifications, conduct the correspondence with the authorities and agree the communication towards customers and staff with you.

  4. Step 4: Claims and follow-up

    After that it is about claims against service providers, the insurance payout and the question of what evidence the authority wants to see as proceedings continue.

The duties under IT security law

NIS2 and its German implementation

Whether an entity is in scope turns on sector and size, and the group perspective regularly leads to subsidiaries being counted as too small. Alongside the measures themselves stands the personal responsibility of management.

NIS2 in detail

Cyber Resilience Act

Products with digital elements need security requirements across their whole lifecycle, including updates and the reporting of exploited vulnerabilities. The duties reach manufacturers, importers and distributors to different depths.

Cyber Resilience Act in detail

The security incident

After an attack several notification duties run in parallel, with different addressees and different deadlines. The first hours decide the evidential position, and what is not recorded now is missing later towards the authority and the insurer.

How to proceed after an incident

Whistleblower protection

Above a certain headcount an internal reporting channel is required, and how it is designed decides whether it is used at all. Confidentiality here is not a promise but a technical and organisational requirement.

Whistleblower protection in detail

Digital sovereignty

The question is rarely whether a provider is permissible, but how dependent you become and what a switch would look like. Data location, key management and exit paths therefore belong before procurement.

Digital sovereignty in detail

A security incident in the business?

With deadlines running, hours count. Get in touch before the first one passes.

Get in touch now

Topics in this practice area

Frequently asked questions

Does our company fall under NIS2?

That depends on sector and size. Beyond the classic critical infrastructures the directive covers further sectors and medium-sized companies as well. On top of that comes indirect exposure through the supply chain: anyone working for a covered company has its requirements passed down contractually. We assess where you sit.

After an attack, who do we have to inform first?

Several duties run in parallel with different deadlines: notification of the data protection authority where personal data is affected, the security notification to the BSI for covered entities, plus contractual partners, insurers and, depending on the situation, law enforcement. A prepared notification plan saves exactly the hours you will not have in an emergency.

Is management personally liable for IT security?

Management is responsible for the risk management measures and cannot fully shed that responsibility by delegating. Documented decisions, training and a demonstrable state of implementation are therefore not only technical questions but questions of liability.

Do we have to register anywhere?

Entities in scope have to register with the Federal Office for Information Security. Nobody determines that scope for you. It has to be assessed and documented by the entity itself. Skipping the assessment means missing not only the measures but the registration as well.

We have outsourced our IT. Does that take us out of scope?

No. The obligations bind the entity, not the service provider. Supply chain security is expressly part of the measures owed, which means the requirements belong in the contract with the provider and have to be verifiable there.

Does cyber insurance replace the measures?

No, it presupposes them. The policies contain conditions on updates, backups, access and reporting routes, and breaching them costs the cover when a loss occurs. The value lies additionally in immediate assistance, meaning forensics, crisis communication and support in dealing with authorities.

We have notified the Federal Office. Does that settle the data protection notification?

No. The security notification and the data protection notification have their own conditions, their own addressees and their own deadlines. They run in parallel, not in sequence, and one does not satisfy the other. Filing only one means missing the second.