Cyber Security for Your Company
As digitalisation increases, cyber security is becoming more and more important. The real question isn’t if you’ll be hacked, but when you’ll be hacked. This is why cyber insurance is also called the fire insurance of the 21st century. Read on to find out how cyber insurance can help you in the event of a security breach.
Why Do I Need Cyber Insurance?
In recent years, there has been an enormous increase in cybercrime. The number of cyberattacks increased threefold from 2021 to 2023. Attackers are becoming more professional, and implementing a good security and defence system is becoming increasingly difficult. In 2022, nearly one in ten attacks was successful. These attacks can put the survival of a business at risk. It’s not only large corporations that are affected, but also small and medium-sized enterprises.
A popular method attackers use against SMEs is the so-called ransomware attack. Attackers look for specific security gaps in a company to gain access to its internal systems. Once they’re in, they encrypt all the data – and the company can no longer access it.
The hackers only lift the encryption once a ransom has been paid. Besides damage to your reputation, a cyberattack can lead to financial losses caused by business downtime and the recovery work that follows.
What Does Cyber Insurance Cover?
An insured event occurs:
- if unauthorised persons gain access to insured IT systems, for example through hackers, malware or internal sabotage
- if a data protection breach has occurred
- or if a policyholder is threatened with such a scenario in order to be blackmailed
Cyber insurance rests on three pillars:
| Crisis & Claims Management | First-Party Losses | Liability |
|---|---|---|
IT forensics Project manager for your claim PR agent |
Business interruption Data recovery Ransom payments |
|
The crisis and claims management part of cyber insurance includes different modules, depending on the insurer:
- IT forensics: specialists identify the gap in your system that the hackers used to get in
- 24/7 service hotline
- A claims agent, acting as a kind of “project manager”, who informs the policyholder about the most important points and supports and guides them. For example, this includes:
- meeting the deadlines for reporting the breach to the Data Protection Authority, filing a report with the State Criminal Police Office (dt. Landeskriminalamt) and informing your customers about the data leak
- communicating with the hackers in the event of blackmailing attempts
- PR work for external communication
The first-party loss component of cyber insurance works like comprehensive insurance. For example, when additional costs arise from restoring data or business interruptions. In Austria you’re also allowed to insure ransom payments for ransomware attacks.
The liability component of cyber insurance serves to defend you against unjustified claims for damages and to settle justified compensation claims. This is usually not covered by a “conventional” liability insurance policy unless you’ve included an extra module for it.
Insurers recommend that cyber insurance solutions should be tailored to a company’s individual needs. As an entrepreneur, you should therefore choose the right insurance components for your ideal insurance cover. This could be a combination of monthly risk analyses to prevent attacks, technical advice on IT and cyber problems as well as compensation payments for data loss or data manipulation caused by hacking attacks.
Your Obligations as a Policyholder
To take out cyber insurance, you have certain obligations. These differ from insurer to insurer, but in most cases, you’ll be asked for the following:
- Maintenance of your company’s IT by an IT expert
- Regular data backups on separate systems and storage media (at least weekly)
- Up-to-date antivirus programs & software systems
- Firewalls at all internet gateways for IT systems
- An authorisation concept with different tiers for IT managers (including identification)
Before taking out the insurance, you’ll usually also be asked whether your company has suffered any damage due to cyberattacks or problems. It’s important to answer these questions truthfully. If you provide false information, you might be faced with the worst-case scenario, in which your insurer isn’t obliged to pay for the damage caused. We recommend answering the insurer’s questions together with the IT expert who looks after your company.
How Much Does My Cyber Insurance Cost?
The cost of your cyber insurance depends mainly on your company’s turnover and industry, as well as its location. The sum insured also plays a role. The exact sum insured you should choose depends on your company. As cyber losses are generally quite costly, the usual recommendation is a sum of at least €1 million.
Prevention: Your First Line of Defence
To avoid a cyberattack or withstand one, preparation and prevention is essential. This includes:
- Basic protection with firewalls
- An antivirus program
- IT security training for employees
- Data backups
- Regular security updates
- Rules for creating and handling passwords
- Clear rules on how and by whom IT systems can be accessed
It also makes sense to have the security gaps in your IT system identified, for example with the help of a standardised audit or a “penetration test” carried out by an IT security expert. Many cyber insurers offer this before you take out the policy so that they can analyse your company’s risk and offer you the right insurance cover.
What Types of Cyberattacks Are There?
Besides the ransomware attacks mentioned above, there are other types of cyberattacks:
- Phishing emails: fake emails designed to trick people into falling for a scam
- Business Email Compromise (BEC) or CEO fraud: hackers gain access to one of the company’s email accounts or create an email account that closely resembles a genuine company address. They then use the stolen identity to deceive customers and employees, often asking them to transfer large sums of money to foreign bank accounts.
- Fake online banking pages: deceptively genuine-looking online banking pages ask bank customers, for example, to request a one-time code from their real bank and enter it. This gives the fraudsters access to the account.
- Social engineering or social manipulation: scammers call employees, sometimes pretending to be technicians, and claim they need confidential information such as login details to carry out their work.


