MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Ransomware is hostage software that encrypts your files or systems, after which criminals demand a ransom — usually in cryptocurrency. In addition to direct damage, an attack can have legal consequences: you may be unable to fulfill contractual obligations, and there is a reporting obligation regarding leaked personal data. It is not only large companies that are targets; SMEs are particularly hard hit. Below, you can read about the legal consequences and how to protect yourself.
What is ransomware?
Ransomware is malicious software that encrypts files or entire systems and denies you access. Criminals then demand a ransom for decryption, often payable in cryptocurrency to make them difficult to trace. Increasingly, attackers also threaten to publish stolen data (double extortion). These cyberattacks affect individuals, SMEs, and large organizations, and lead to substantial financial and operational damage.
What are the legal consequences of a ransomware attack?
Consequences for existing agreements
Due to an attack, you are often unable to fulfill your contractual obligations—for example, you may be unable to access essential files, causing you to deliver late. This can lead to claims and disputes. Therefore, it is advisable to include clear agreements regarding cyber incidents in your contracts and general terms and conditions, for example through a force majeure clause in which a cyber attack is explicitly named as a force majeure situation.
Reporting obligation in the event of a data breach
If personal data is encrypted or stolen during an attack, this constitutes a data breach. Under the GDPR, you must in principle report a data breach to the Data Protection Authority within 72 hours, and in certain cases also to the data subjects themselves. Failure to report (in a timely manner) can constitute a separate violation. Therefore, document who does what within your organization in the event of an incident; read more about privacy and data protection.
How do you protect yourself against ransomware?
- Make regular backups and store at least one offline or separate from your network, so that encryption does not include it.
- Keep software up to date and use good security and antivirus software.
- Train your employees: many attacks start with a phishing email. Awareness is one of the strongest defenses.
- Restrict access rights and use multi-factor authentication (MFA).
- Draw up an incident plan so that you know exactly what to do in the event of an attack.
Depending on your sector and size, additional statutory security obligations may apply. Regulations in this area change; have the current requirements for your organization checked.
Is cyber insurance worthwhile?
Cyber insurance can offer financial protection against the consequences of an attack. Such insurance often covers the costs of crisis management, data recovery, and sometimes negotiations. However, pay close attention to the policy conditions: coverage is not automatic and depends on your security level. In practice, disputes regarding payouts frequently arise—think of coverage disputes and other policy disputes.
Frequently asked questions about ransomware
Do I have to pay the ransom?
Paying is discouraged: there is no guarantee that you will get your files back, and you are perpetuating the criminals' business model. Moreover, payment may entail legal risks, for example in connection with sanctions legislation if the recipient is on a sanctions list. In the event of an attack, immediately seek expert assistance and file a report.
What should I do first after an attack?
Isolate the affected systems to prevent spread, engage IT specialists, assess whether personal data has been leaked (in connection with the reporting obligation), and inform your insurer where necessary. File a report with the police. Document everything carefully.
Am I liable if I am unable to deliver due to ransomware?
That depends on your agreements. Without a force majeure clause, you run the risk of claims for non-performance. A good force majeure clause that specifies cyber incidents can significantly strengthen your position.
Legal assistance with ransomware and cyber incidents
The IT Law practice group at MKB Juristen provides support during cyber incidents: from contracts that account for cyber threats to the process following an attack and conflicts with cyber insurers. Schedule a no-obligation intake to increase your legal resilience.