Cyber insurance
Is it important for companies?
The threat situation in the area of IT security has been intensifying for years. Countless companies in Germany are hacked every day, and according to the BKA (Federal Criminal Police Office) and the digital association Bitkom, this caused damage of over EUR 200 million to the German economy in 2022 alone. For a company, adequate protection against internet crime is absolutely essential. Insurance against cyberattacks is consequently coming more and more into the focus of business owners. But how useful is cyber insurance for companies?
Table of contents
What is cyber insurance?
Cyber protection insurance is intended to protect against the financial consequences of cyberattacks. This includes, among other things, damages such as data recovery, liability claims from affected parties, costs for forensic investigations and loss of earnings due to business interruptions as a result of cyberattacks.
Some cyber security insurance policies also cover the payment of ransoms, which can offer advantages in some cases. In principle, however, it is also important to know that policyholders must take preventive care of the protection of their IT systems, because only then will cyber insurance actually pay out in the event of a claim.
Cyber threats in view
How can you protect yourself against cybercrime?
Managing directors bear overall responsibility for their company, and IT security today plays an indispensable part in protecting the business. IT security is therefore not solely the job of the IT department; rather, the respective management must show equal responsibility and take care of IT security aspects.
Strengthen IT security regularly
When it comes to protection against cybercrime, IT security is certainly the most important and most powerful tool. And just as hackers are constantly perfecting their methods, IT security in a company must also constantly evolve and be optimised.
Back up data
Automatic, daily, audit-proof backups in the cloud (of all devices/data) are your personal insurance and, even if you have taken out cyber insurance, remain an absolute must for companies. Because no insurance in the world can protect you from data loss. In addition, the data backup should be checked regularly for completeness and functionality. The maintenance and care of IT is therefore of great importance.
Create a crisis management plan
Management should prepare for the event of an attack with an appropriate crisis management plan. This can often significantly limit the damage.
Train employees
Regular training for employees can significantly reduce the security risk. Because even in a fundamentally secure IT environment, an untrained employee can quickly become a risk.
Take out cyber insurance
In combination with the other points already mentioned, cyber insurance can be sensible and helpful in order to also protect yourself against the financial damage of an attack. Especially for companies with few financial reserves, this is often the only way to cope with a crisis at all.
Minimising financial risks: why cyber insurance makes sense
A successful cyberattack always goes hand in hand with corresponding damage. The resulting damage can be very varied.
Many companies do not have sufficient financial resources available for such an attack. However, these are needed immediately, e.g. to restore the IT and close the security gap as quickly as possible. For these companies, insurance against cybercrime is definitely an advantage.
FAQ
1
IT security in companies is greatly enhanced by professional and good IT support. Nevertheless, there is no guarantee of 100 % protection. It is therefore important to prepare for the worst case with additional precautions, e.g. through good emergency planning.
Does cyber insurance protect me against cybercrime?
No – at most, the minimum requirements demanded by the insurer could contribute to better protection. Otherwise, this insurance only protects against the financial consequences of a cybercrime incident.
From what company size can cyber insurance make sense?
Company size is actually not decisive and does not protect against attacks either. However, since many companies only have the financial means to invest sufficiently in secure IT from a certain size, investing in cyber insurance can only be considered sensible from that point onwards.
Do cyber insurers always pay out for the damage incurred?
No – insurers usually try to prove negligence on the part of the customer through IT forensic experts. This is not uncommon, particularly with cyber insurance. In addition, you should check exactly in which cases and for which costs an insurance policy actually pays. The time it takes for the sum to be paid out is also often decisive.
Are small companies even of interest to criminals?
The vast majority of cyber incidents are not targeted. Automated scripts search for vulnerabilities in networks and attack them as soon as they are found. Hackers usually only know exactly whom they have hacked after their attack has succeeded, and then adjust, for example, the amount of the ransom demand accordingly.
I have no data that is relevant to hackers, so why should I protect myself?
Even a privately used laptop usually contains enough data to put its owner in a difficult position. An address list from the club or school, or photos of your partner, is already enough. Internet crime does not stop at privately used devices. Attackers have recognised the lucrative potential here too. Consequently, private individuals must equally expect increasing attack scenarios such as virus attacks, problems with online purchases, identity theft or data theft. In the private sphere, however, it is also worth checking existing insurance policies to see whether cyber risks are already covered, in full or in part.
Conclusion
Cyber insurance can be a truly sensible insurance. However, as is generally the case with insurance, it protects neither against the actual loss event nor against reputational damage, data theft, downtime, etc. Only the financial damage can be mitigated. You should therefore only take out cyber insurance if it really offers financial advantages.
Before thinking about taking out a policy, however, your IT should be state of the art. With a professional firewall, automatic data backup, regular, proactive maintenance and employee training on IT security and data protection, you can effectively protect your company against threats from the anonymous internet. These listed security precautions are often part of the requirements specified by the cyber insurer to ensure that a company is eligible for an insurance payout at all.
We offer companies exactly this proactive IT support at fixed prices.
Feel free to get in touch with us – we look forward to getting to know you personally!



