01
Small business package
Standard policies with a short questionnaire, limits up to around EUR 250,000, hotline, recovery and liability included, short business interruption period.
Home / Insurance broker / Business
If you run a company in Germany, a ransomware attack or data breach is your cost, not your IT provider's: forensics, recovery, lost revenue and claims from customers. A German cyber policy combines first-party losses, business interruption and liability in one contract and, above all, gives you an incident response team on the phone within hours. This page explains the German market for managers who know cyber cover from the UK or US and want to know what is different here.
The question almost everyone asks first
It is not compulsory, but most companies that depend on IT should have it, because no other standard German business policy covers a cyberattack properly. General liability (Betriebshaftpflicht) excludes most data losses, and property and electronics policies only pay for physical damage. In addition, since December 2025 Germany's NIS2 rules make senior management personally responsible for cybersecurity in many sectors. The policy does not replace that duty, but it pays for the response when prevention fails.
Do the maths
Ransomware locks every computer. Staff are there but cannot work, orders pile up, and the forensic team bills by the hour.
Eight working hours per day.
German policies are written under German insurance contract law (VVG) and usually in German. The structure is familiar: first-party costs, business interruption, third-party liability, incident response. What differs is the detail. German wordings often define duties before a loss (Obliegenheiten) as a list of security measures, and a breach can reduce the claim payment if it contributed to the loss. The pre-contract questionnaire counts as a legal disclosure; wrong answers can void cover.
Ransom payments are a grey area. Several German policies cover extortion costs and, where legally permitted, the ransom itself; others pay only for response and recovery. Fines under GDPR are only insured where that is legally allowed, which is disputed in Germany. If you are used to US policies that routinely list regulatory fines, do not assume the same here.
Germany implemented the EU NIS2 Directive through a revised BSI Act that took effect on 6 December 2025. It covers companies in listed sectors with at least 50 employees or more than EUR 10 million in turnover and balance sheet total, plus some entities regardless of size. Covered companies must register with the Federal Office for Information Security (BSI), run documented risk management and report significant incidents in stages.
Management must approve and oversee these measures and is personally liable for failures (section 38 BSI Act). Fines reach EUR 10 million or 2 percent of worldwide turnover for essential entities and EUR 7 million or 1.4 percent for important entities. The registration deadline has passed; if your company is in scope and not registered, register now.
The value of a cyber policy shows in the first night. Good German insurers run a 24/7 hotline with forensic firms and lawyers they have already contracted. Save the number outside your company network, for example on a printed sheet and on managers' phones, because your email and file server may be encrypted.
Business interruption is usually the largest loss. Check two figures: the waiting period before payment starts and the indemnity period, meaning how many months of lost profit are covered. A policy with 12 hours and 12 months is very different from one with three days and three months.
Wheel of misfortune
Six things that really happen. The wheel picks yours and shows who pays.
Cost:
Premiums depend on turnover, sector and the maturity of your IT security. There are no reliable published price comparisons for business cyber cover in Germany, so we do not quote ranges. German insurance tax is added to the premium.
The premium is only fixed in the quote, after the insurer has reviewed your questionnaire.
01
Standard policies with a short questionnaire, limits up to around EUR 250,000, hotline, recovery and liability included, short business interruption period.
02
Limits of EUR 1 to 2 million, longer indemnity periods, add-ons for payment fraud and outages at IT providers, individual underwriting.
03
High limits split between a primary policy and excess layers from several insurers, technical underwriting calls, alignment with global programmes of foreign parent companies.
| Criterion | Minimum standard | Strong policy | Why it matters |
|---|---|---|---|
| Incident response | hotline during office hours | 24/7, experts start without waiting for coverage confirmation | Attacks are timed for nights and weekends. |
| Indemnity period | three months | twelve months | Revenue does not return the day your servers restart. |
| Waiting period | 72 hours | 12 hours or less | Three days without systems can be the whole loss for a retailer. |
| Dependent business interruption | not covered | attacks on your cloud or IT providers trigger cover | Many companies stop because their software provider is hit, not them. |
| Duties before a loss | rigid list, breach can void cover | reduction only if the breach caused the loss | One missed update should not cost you the entire claim. |
| Operator error | external attacks only | also human error and programming faults | Much data loss happens without any attacker. |
| Language and jurisdiction | German wording only | English convenience translation, German courts | International management teams must understand what they sign. |
German cyber insurance is sold by large composite insurers and by specialists. Some well-known names, such as Hiscox, operate in Germany as branches of insurers from other EU countries and are therefore not on the BaFin list of insurers under German federal supervision, so they are not listed here. This is a market overview, not a statement about who we work with.
| Insurer | Background |
|---|---|
| Allianz | German property insurer of the Allianz group, agents and brokers |
| AXA | German company of the French AXA group |
| HDI | part of the Talanx group, business customers via brokers and agents |
| Markel | specialty insurer based in Munich, sells through brokers |
| Zurich | part of Zurich Insurance Group, commercial and industrial clients |
| R+V | insurer of the German cooperative banks |
| Gothaer | mutual group, agents and brokers |
| Baloise | German subsidiary of Swiss Baloise |
From the BaFin register
139
139 insurers supervised by BaFin, the German regulator, are licensed for this class of insurance. (Sonstige finanzielle Verluste, Allgemeine Haftpflicht)
Source: BaFin company database, retrieved 18 September 2026. Insurers from other EU countries selling through a branch or without a German office are not included.
Fixed modules for small companies, quick application, lower limits.
First-party, business interruption and liability chosen separately, each with its own limit.
Small cyber module inside a combined business policy, useful as a start but rarely enough.
Called Vertrauensschadenversicherung in Germany, covers theft and fraud by employees and impersonation fraud.
For German subsidiaries of international groups, a local policy that fits the parent's master policy and German law.
Myth or truth
Five things people say about this insurance. Guess first, then see the answer.
Every German company must report a cyber attack to the police.
This is false.
No, there is no general duty to go to the police. What is mandatory is notifying the data protection authority within 72 hours when personal data is at risk, and BSI reporting for companies under NIS2. Filing a police report is still wise and many insurers expect it.
In Germany you report a data breach to a regional authority, not a national one.
This is true.
True for most private companies. Data protection is supervised by the authority of the federal state where your company has its main establishment, for example in Bavaria or Berlin.
A company cyber policy also covers my hacked personal Instagram.
This is false.
No. Business cyber policies protect company data and systems. Private online risks are covered by separate add-ons, often sold with household or personal liability insurance.
Two-factor login can decide whether an insurer will offer cover at all.
This is true.
Yes. German insurers now ask about multi-factor authentication for email and remote access before quoting. Without it, many decline or offer only restricted terms.
Once the attacker is out of the network, the costs stop.
This is false.
Far from it. Lost orders, customer claims and follow-up checks can run for months after the systems are clean. That is why the indemnity period for business interruption matters so much.
Questions and answers
The legally binding wording is almost always German. Some insurers and brokers provide English translations or summaries for reference. We explain the key clauses in English, but the German text decides in a claim.
Only if it is structured to do so. Many global programmes need a local German policy to pay claims locally and comply with German insurance tax. Check this with the group's broker before relying on it.
Only where legally insurable, and in Germany that is disputed. Good policies include fines to the extent permitted, but you should not count on it. Legal defence costs and compensation claims by affected people are covered.
That is the most common entry point and is covered by good policies. Simple negligence by staff must not reduce the payment. Check that the wording does not exclude gross negligence of employees.
Check your sector against the lists in the German BSI Act and your size: at least 50 employees or more than EUR 10 million turnover and balance sheet total. The BSI offers an online self-check in German. If you are in scope and not yet registered, register immediately.
Estimate the cost of three to four weeks of downtime and add forensics, recovery and liability. Small firms often choose EUR 250,000 to 500,000, mid-sized companies EUR 1 million or more. The limit usually applies once per year for all claims together.
Often yes, at a basic level: offline backups, multi-factor authentication for email and remote access, current patches. Many German insurers decline companies without these. The measures reduce your risk anyway.
Business contracts usually run for one year and renew automatically unless you cancel three months before expiry. After a claim both sides may cancel. Arrange the new policy to start the same day the old one ends.
Because the differences sit in German clauses on waiting periods, duties and war exclusions, and the questionnaire must be answered correctly. As brokers we act for you, not the insurer, and explain the wording in English. The insurer pays our commission.
NAMMERT insurance broker
We obtain quotes and come back with a comparison. Free of charge and without obligation: the insurer pays our commission. You can write in English.
We will be in touch within one working day. If it is urgent: +49 3375 29 12 77.

Is business liability insurance compulsory in Germany?

What does business interruption insurance pay in Germany?

Can I be personally liable as managing director of a German GmbH?

Why do I need electronic equipment insurance if I have contents insurance?
Ten life situations, sorted honestly
Find your case, see which policy pays
What we would talk you out of
Boat or yacht? Here we are not the broker but the underwriting agency, with our own policies and our own claims handling.
Boat insuranceNAMMERT Assekuradeur GmbH, insurance broker licensed under section 34d(1) of the German Trade Regulation Act, broker register no. D-C08Q-TOSD4-37. For boat and yacht insurance we act as underwriting agency, not as broker. Statutory disclosure (German) · Updated