Skip to content
Call, 0511 – 47 55 58 11

Cyber incident: the first hours

After an attack several notification duties run alongside one another, with different addressees and different deadlines. Knowing the order in advance means not losing the first hours to questions of responsibility.

deadline for the GDPR notification once personal data is affected
72 h
possible addressees: data protection authority, BSI, insurer, law enforcement
4
tasks at once, restore operations and preserve evidence
2
ransom decisions to be taken without prior legal assessment
0

The first steps

  1. Step 1: Secure and document the situation

    Block access, isolate affected systems, preserve evidence and log every decision with a timestamp.

  2. Step 2: Establish exposure

    Is personal data affected, are you a covered entity, are customers caught up through the supply chain? The obligations follow from that.

  3. Step 3: Sort the notification duties

    Data protection authority, BSI, contractual partners, insurers and, depending on the situation, law enforcement. The deadlines run alongside each other, not in sequence.

  4. Step 4: Notify and communicate

    We draft the notifications, conduct the correspondence and agree the communication towards customers and staff.

  5. Step 5: Work through the aftermath

    Claims against service providers, the insurance payout and the evidence the authority wants to see as proceedings continue.

Two notification routes that are not the same

Under data protection law

  • Requires that personal data is affected
  • Addressed to the competent data protection supervisory authority
  • A 72-hour deadline from awareness under Art. 33 GDPR
  • Where the risk is high, communication to data subjects is added

Under security law

  • Requires that you are a covered entity
  • Addressed to the Federal Office for Information Security
  • Its own staged deadlines with an initial and a follow-up report
  • Applies even where no personal data is affected

One notification does not discharge the other. Notifying only the data protection authority can leave the security duty breached, and the other way round.

An attack under way or just noticed?

Call before the first deadline passes. We are available at short notice.

Get in touch now

Frequently asked questions

Should we pay the ransom?

Alongside the commercial side this decision has a legal one that has to be settled before payment: sanctions limits, criminal law questions, your insurer position and the documentation towards authorities and shareholders. We settle that at short notice before payment, not after.

Can we rebuild the systems straight away?

Not before the evidence is secured. Whoever tidies up first can afterwards prove nothing to the authority, the insurer or the service providers. Restoration and evidence preservation therefore have to be planned in parallel.

Do we have to inform our customers?

That depends on several bases at once: the GDPR where personal data is affected, contractual information duties and, depending on sector, security law requirements. The answers differ, which is why communication has to be coordinated rather than improvised.

Related