# Cyber insurance in Germany: what founders and managers need to know

> If you run a company in Germany, a ransomware attack or data breach is your cost, not your IT provider's: forensics, recovery, lost revenue and claims from customers. A German cyber policy combines first-party losses, business interruption and liability in one contract and, above all, gives you an incident response team on the phone within hours. This page explains the German market for managers who know cyber cover from the UK or US and want to know what is different here.

Quelle/Source: https://www.nammert.com/en/insurance-broker-cyber-insurance.php  
Updated: 2026-09-18

## Do I need cyber insurance for my company in Germany?

It is not compulsory, but most companies that depend on IT should have it, because no other standard German business policy covers a cyberattack properly. General liability (Betriebshaftpflicht) excludes most data losses, and property and electronics policies only pay for physical damage. In addition, since December 2025 Germany's NIS2 rules make senior management personally responsible for cybersecurity in many sectors. The policy does not replace that duty, but it pays for the response when prevention fails.

## At a glance

- **Compulsory?:** No; NIS2 requires risk management in covered sectors
- **Typical limit:** EUR 250,000 to 2 million, higher for larger firms
- **Data breach reporting:** 72 hours to the data protection authority (Art. 33 GDPR)
- **NIS2 incident reporting:** 24 hours early warning, 72 hours report, one month final report
- **Contract term:** usually one year, renews unless cancelled three months ahead

## How German cyber policies differ from UK and US cover

German policies are written under German insurance contract law (VVG) and usually in German. The structure is familiar: first-party costs, business interruption, third-party liability, incident response. What differs is the detail. German wordings often define duties before a loss (Obliegenheiten) as a list of security measures, and a breach can reduce the claim payment if it contributed to the loss. The pre-contract questionnaire counts as a legal disclosure; wrong answers can void cover.

Ransom payments are a grey area. Several German policies cover extortion costs and, where legally permitted, the ransom itself; others pay only for response and recovery. Fines under GDPR are only insured where that is legally allowed, which is disputed in Germany. If you are used to US policies that routinely list regulatory fines, do not assume the same here.

## NIS2 in Germany: who is affected

Germany implemented the EU NIS2 Directive through a revised BSI Act that took effect on 6 December 2025. It covers companies in listed sectors with at least 50 employees or more than EUR 10 million in turnover and balance sheet total, plus some entities regardless of size. Covered companies must register with the Federal Office for Information Security (BSI), run documented risk management and report significant incidents in stages.

Management must approve and oversee these measures and is personally liable for failures (section 38 BSI Act). Fines reach EUR 10 million or 2 percent of worldwide turnover for essential entities and EUR 7 million or 1.4 percent for important entities. The registration deadline has passed; if your company is in scope and not registered, register now.

## What matters when you actually get hit

The value of a cyber policy shows in the first night. Good German insurers run a 24/7 hotline with forensic firms and lawyers they have already contracted. Save the number outside your company network, for example on a printed sheet and on managers' phones, because your email and file server may be encrypted.

Business interruption is usually the largest loss. Check two figures: the waiting period before payment starts and the indemnity period, meaning how many months of lost profit are covered. A policy with 12 hours and 12 months is very different from one with three days and three months.

## What is covered

- 24/7 incident response hotline with forensic experts
- Investigation, containment and removal of attackers
- Restoring data and systems
- Loss of profit during business interruption after an attack
- Legal advice on GDPR reporting and notifying affected people
- Liability claims from customers after a data breach
- Crisis communication to protect your reputation
- Cyber extortion costs, depending on the policy
- Payment diversion fraud and fake invoices, as an add-on

## What is not covered

- Vulnerabilities you knew about before the policy started
- Intentional acts by management
- Failure of public power or telecom networks
- War and state-backed attacks as defined in the war exclusion
- Upgrading IT beyond its condition before the attack
- Fines where they are not legally insurable

## Who needs it

- Any company that cannot work without its computers, email or tills
- Start-ups and tech companies holding customer or payment data
- Online shops and companies with booking systems
- Companies in NIS2 sectors and their suppliers
- Medical practices, law firms and tax advisers bound by confidentiality

## Who can do without

- Businesses that genuinely store no customer data digitally and can work fully offline

## What it costs

Premiums depend on turnover, sector and the maturity of your IT security. There are no reliable published price comparisons for business cyber cover in Germany, so we do not quote ranges. German insurance tax is added to the premium.

**What drives the premium:**

- Annual turnover and number of employees
- Sector and type of data processed
- Limit of indemnity and deductible
- Security measures from the questionnaire, especially offline backups and multi-factor authentication
- Business interruption waiting period and indemnity period
- Previous incidents

_The premium is only fixed in the quote, after the insurer has reviewed your questionnaire._

## The policy levels on the market

- **Small business package:** Standard policies with a short questionnaire, limits up to around EUR 250,000, hotline, recovery and liability included, short business interruption period.
- **Mid-market policy:** Limits of EUR 1 to 2 million, longer indemnity periods, add-ons for payment fraud and outages at IT providers, individual underwriting.
- **Large corporate programme:** High limits split between a primary policy and excess layers from several insurers, technical underwriting calls, alignment with global programmes of foreign parent companies.

## How to recognise a good policy

| Criterion | Minimum standard | Strong policy | Why it matters |
| --- | --- | --- | --- |
| Incident response | hotline during office hours | 24/7, experts start without waiting for coverage confirmation | Attacks are timed for nights and weekends. |
| Indemnity period | three months | twelve months | Revenue does not return the day your servers restart. |
| Waiting period | 72 hours | 12 hours or less | Three days without systems can be the whole loss for a retailer. |
| Dependent business interruption | not covered | attacks on your cloud or IT providers trigger cover | Many companies stop because their software provider is hit, not them. |
| Duties before a loss | rigid list, breach can void cover | reduction only if the breach caused the loss | One missed update should not cost you the entire claim. |
| Operator error | external attacks only | also human error and programming faults | Much data loss happens without any attacker. |
| Language and jurisdiction | German wording only | English convenience translation, German courts | International management teams must understand what they sign. |

## Insurers on the German market

German cyber insurance is sold by large composite insurers and by specialists. Some well-known names, such as Hiscox, operate in Germany as branches of insurers from other EU countries and are therefore not on the BaFin list of insurers under German federal supervision, so they are not listed here. This is a market overview, not a statement about who we work with.

- **Allianz**: German property insurer of the Allianz group, agents and brokers
- **AXA**: German company of the French AXA group
- **HDI**: part of the Talanx group, business customers via brokers and agents
- **Markel**: specialty insurer based in Munich, sells through brokers
- **Zurich**: part of Zurich Insurance Group, commercial and industrial clients
- **R+V**: insurer of the German cooperative banks
- **Gothaer**: mutual group, agents and brokers
- **Baloise**: German subsidiary of Swiss Baloise

139 insurers supervised by BaFin, the German regulator, are licensed for this class of insurance. (Sonstige finanzielle Verluste, Allgemeine Haftpflicht). Source: BaFin company database, retrieved 2026-09-18. Insurers from other EU countries selling through a branch or without a German office are not included.

## Typical claims and who pays

- **Fake CEO orders an urgent transfer** (usually five figures, sometimes six): Payments made after a fake email from the boss count as social engineering fraud. Basic German policies exclude it; strong ones add it with a sublimit.
- **Ransomware hits on Good Friday** (€30,000 to €300,000 including downtime): Both pay to restore systems. Over a long holiday weekend the waiting period matters: basic policies start paying lost profit late, strong ones early.
- **Hacked Microsoft 365 mailbox** (around €5,000 to €30,000 for forensics and lawyers): Finding out what the attacker read and handling GDPR notifications is the core of every cyber policy.
- **Cloud provider down for two days** (lost revenue for the outage): Outages at your provider are not an attack on you. Some strong policies cover this dependent business interruption, basic ones do not.
- **New IT system after the attack** (the cost of the upgrade): Cyber insurance restores what you had before. If you use the rebuild to modernise, the extra cost is yours.
- **Your hacked server attacks others** (third-party claims, often five figures): If your systems spread malware to customers, they can claim damages. Strong policies include this liability in full, basic ones with low limits.

## Myth or truth

- „Every German company must report a cyber attack to the police." ✘ No, there is no general duty to go to the police. What is mandatory is notifying the data protection authority within 72 hours when personal data is at risk, and BSI reporting for companies under NIS2. Filing a police report is still wise and many insurers expect it.
- „In Germany you report a data breach to a regional authority, not a national one." ✔ True for most private companies. Data protection is supervised by the authority of the federal state where your company has its main establishment, for example in Bavaria or Berlin.
- „A company cyber policy also covers my hacked personal Instagram." ✘ No. Business cyber policies protect company data and systems. Private online risks are covered by separate add-ons, often sold with household or personal liability insurance.
- „Two-factor login can decide whether an insurer will offer cover at all." ✔ Yes. German insurers now ask about multi-factor authentication for email and remote access before quoting. Without it, many decline or offer only restricted terms.
- „Once the attacker is out of the network, the costs stop." ✘ Far from it. Lost orders, customer claims and follow-up checks can run for months after the systems are clean. That is why the indemnity period for business interruption matters so much.

## Common mistakes

- Having the questionnaire completed by finance rather than the person who runs IT
- Keeping backups on the same network the attacker encrypts
- Assuming your parent company's global policy covers the German entity without a local policy
- Storing the hotline number only in the email system that goes down
- Assuming GDPR fines are covered as they might be in a US policy

## FAQ

### Can I get a cyber policy in English in Germany?

The legally binding wording is almost always German. Some insurers and brokers provide English translations or summaries for reference. We explain the key clauses in English, but the German text decides in a claim.

### Does our global group policy cover the German company?

Only if it is structured to do so. Many global programmes need a local German policy to pay claims locally and comply with German insurance tax. Check this with the group's broker before relying on it.

### Are GDPR fines covered?

Only where legally insurable, and in Germany that is disputed. Good policies include fines to the extent permitted, but you should not count on it. Legal defence costs and compensation claims by affected people are covered.

### What happens if an employee clicks a phishing link?

That is the most common entry point and is covered by good policies. Simple negligence by staff must not reduce the payment. Check that the wording does not exclude gross negligence of employees.

### How do I know if my company falls under NIS2?

Check your sector against the lists in the German BSI Act and your size: at least 50 employees or more than EUR 10 million turnover and balance sheet total. The BSI offers an online self-check in German. If you are in scope and not yet registered, register immediately.

### How much cover should we buy?

Estimate the cost of three to four weeks of downtime and add forensics, recovery and liability. Small firms often choose EUR 250,000 to 500,000, mid-sized companies EUR 1 million or more. The limit usually applies once per year for all claims together.

### Do we need to improve our IT security before buying?

Often yes, at a basic level: offline backups, multi-factor authentication for email and remote access, current patches. Many German insurers decline companies without these. The measures reduce your risk anyway.

### How do I cancel a German cyber policy?

Business contracts usually run for one year and renew automatically unless you cancel three months before expiry. After a claim both sides may cancel. Arrange the new policy to start the same day the old one ends.

### Why use a broker for cyber insurance in Germany?

Because the differences sit in German clauses on waiting periods, duties and war exclusions, and the questionnaire must be answered correctly. As brokers we act for you, not the insurer, and explain the wording in English. The insurer pays our commission.

## Legal basis and sources

- [Insurance Contract Act (VVG, German)](https://www.gesetze-im-internet.de/vvg_2008/)
- [BaFin company database (licensed insurers)](https://portal.mvp.bafin.de/database/InstInfo/)

## Request quotes

We obtain quotes and come back with a comparison. Free of charge and without obligation: the insurer pays our commission. You can write in English. https://www.nammert.com/en/insurance-broker-cyber-insurance.php#anfrage

---

NAMMERT Assekuradeur GmbH, insurance broker licensed under section 34d(1) of the German Trade Regulation Act, broker register no. D-C08Q-TOSD4-37. For boat and yacht insurance we act as underwriting agency, not as broker.

NAMMERT Assekuradeur GmbH, Karl-Marx-Straße 4, 15711 Königs Wusterhausen, +49 3375 29 12 77, info@nammert.com. Wikidata: Q141141479.
