Practice area
IT security law: cybersecurity and cybercrime
IT security law is spread across several statutes, regulations and directives, from the BSI Act through the NIS2 implementation to the Cyber Resilience Act.
IT security law has moved from a peripheral question to a duty of management. We handle the legal side of that, from Hannover and together with the affiliated consultancy for the operational work.
- Legal adviceWe advise you on all relevant statutory requirements for IT security.
- IT consultingThrough our affiliated data protection consultancy lexICT we also advise on operational implementation and offer training.
Your firm for IT security law
- Requirements under the IT Security Act 2.0
- Requirements under the BSI Act
- Implementation of the NIS2 Directive
- General Data Protection Regulation
- Digital Services Act and Telecommunications Act
- Criminal law provisions
- Security Operations Centre (SOC)
- Security Information and Event Management (SIEM)
When the emergency happens
After an attack several notification duties run alongside one another, with different addressees and different deadlines. Knowing the order in advance means not losing the first hours to sorting out who is responsible.
Step 1: Secure and document the situation
Preserve evidence, record the incident and log the decisions. Whatever is not documented now will be missing later towards the authority, the insurer and contractual partners.
Step 2: Check notification duties
Data protection authority, BSI, contractual partners, insurers and where applicable law enforcement. Which duty applies depends on sector, exposure and the data involved.
Step 3: Notify and communicate
We draft the notifications, conduct the correspondence with the authorities and agree the communication towards customers and staff with you.
Step 4: Claims and follow-up
After that it is about claims against service providers, the insurance payout and the question of what evidence the authority wants to see as proceedings continue.
The duties under IT security law
NIS2 and its German implementation
Whether an entity is in scope turns on sector and size, and the group perspective regularly leads to subsidiaries being counted as too small. Alongside the measures themselves stands the personal responsibility of management.
Cyber Resilience Act
Products with digital elements need security requirements across their whole lifecycle, including updates and the reporting of exploited vulnerabilities. The duties reach manufacturers, importers and distributors to different depths.
The security incident
After an attack several notification duties run in parallel, with different addressees and different deadlines. The first hours decide the evidential position, and what is not recorded now is missing later towards the authority and the insurer.
Whistleblower protection
Above a certain headcount an internal reporting channel is required, and how it is designed decides whether it is used at all. Confidentiality here is not a promise but a technical and organisational requirement.
Digital sovereignty
The question is rarely whether a provider is permissible, but how dependent you become and what a switch would look like. Data location, key management and exit paths therefore belong before procurement.
A security incident in the business?
With deadlines running, hours count. Get in touch before the first one passes.
Get in touch nowTopics in this practice area
- Cyber incidentRansomware, data exfiltration, compromised accounts: notification duties, deadlines and legal support in the first hours after an attack.
- Cyber Resilience ActThe Cyber Resilience Act: reporting duties from September 2026, full application from December 2027, and what makers of connected products must do now.
- Data breachNotification duty under Article 33 GDPR, the 72-hour deadline, informing data subjects: how to proceed after a data breach.
- Digital sovereigntyDigital sovereignty from a legal angle: third country access, control of keys, operating models and what of it can be secured by contract.
- Germany StackThe Deutschland-Stack as a shared foundation for public sector digitisation: status, core components and what it means for suppliers and authorities.
- Monitoring in the workplaceMonitoring potential usually arises as a side effect. How to establish it, reduce it technically and settle whatever remains with the works council.
- NIS2NIS2 in Germany: who is in scope, which duties have applied since December 2025 and what falls on management personally.
- Trade secrets and AIHow trade secret protection survives the use of AI, which safeguards count as reasonable, and how to protect your own models and outputs.
- Whistleblower protectionInternal reporting channels under the German Whistleblower Protection Act: duties from 50 staff, confidentiality, deadlines and the ban on reprisals.
Frequently asked questions
Does our company fall under NIS2?
That depends on sector and size. Beyond the classic critical infrastructures the directive covers further sectors and medium-sized companies as well. On top of that comes indirect exposure through the supply chain: anyone working for a covered company has its requirements passed down contractually. We assess where you sit.
After an attack, who do we have to inform first?
Several duties run in parallel with different deadlines: notification of the data protection authority where personal data is affected, the security notification to the BSI for covered entities, plus contractual partners, insurers and, depending on the situation, law enforcement. A prepared notification plan saves exactly the hours you will not have in an emergency.
Is management personally liable for IT security?
Management is responsible for the risk management measures and cannot fully shed that responsibility by delegating. Documented decisions, training and a demonstrable state of implementation are therefore not only technical questions but questions of liability.
Do we have to register anywhere?
Entities in scope have to register with the Federal Office for Information Security. Nobody determines that scope for you. It has to be assessed and documented by the entity itself. Skipping the assessment means missing not only the measures but the registration as well.
We have outsourced our IT. Does that take us out of scope?
No. The obligations bind the entity, not the service provider. Supply chain security is expressly part of the measures owed, which means the requirements belong in the contract with the provider and have to be verifiable there.
Does cyber insurance replace the measures?
No, it presupposes them. The policies contain conditions on updates, backups, access and reporting routes, and breaching them costs the cover when a loss occurs. The value lies additionally in immediate assistance, meaning forensics, crisis communication and support in dealing with authorities.
We have notified the Federal Office. Does that settle the data protection notification?
No. The security notification and the data protection notification have their own conditions, their own addressees and their own deadlines. They run in parallel, not in sequence, and one does not satisfy the other. Filing only one means missing the second.