Client story | Future Talks
Cybersecurity
Security in the digital age

Cybersecurity is one of the biggest challenges of our networked world. According to the Federal Office for Information Security, the situation has recently worsened due to increased cyberattacks by criminals and states, as well as vulnerabilities in IT and software. How can we protect ourselves more effectively? That was the subject discussed by experts from Germany and Israel at FPS Future Talks Cybersecurity.

Nowadays, it is impossible to imagine our business world without digitalisation – from digital factories to public administration services on the internet and cloud computing. But it also has a downside, as it provides cybercriminals with gateways for their illegal activities. ‘Digitalisation inevitably leads to greater vulnerability,’ says Dr Hauke Hansen, specialist lawyer for IT, copyright and media law and partner at FPS. ‘With that in mind, increased awareness of this vulnerability on the part of companies and authorities is essential.’ Dr Hansen cites the cyberattacks on the automotive supplier Continental and the bicycle manufacturer Prophete as prominent examples. Hackers even drove the latter into insolvency in early 2023: the company was not able to compensate for the losses incurred from stopping operations for several weeks.
 

A wide range of measures are needed in order to implement the best possible protection against cyberattacks – from careful handling of data to protection through technology. In addition, insurance can help limit any damage that does occur. In any case, if a cyberattack takes place, it is important to know exactly what the legal consequences are. At the FPS Future Talk Cybersecurity, experts from Germany and Israel talked about cybersecurity issues. The following films provide an insight into what was discussed.
 

Dr Nina Jarass Cohen
What can we learn from Israel?

Dr Nina Jarass Cohen, Head of the Israel Desk and partner at FPS: ‘Israel has a lot of experience in handling different levels of threat – we can learn from that.’

Dr Christoph Süßenberger
What legal aspects are important?

Dr Christoph Süßenberger, specialist lawyer and partner at FPS: ‘When companies go digital, they need watertight contracts and a legally secure framework.’

Carsten Wiesenthal
How can you protect against cyber-risks?

Carsten Wiesenthal, ALLCURA insurance company: ‘Cyber-risks can only be protected against in close coordination with the client.’

77 %
of cyberattacks can be traced back to a lack of awareness on the part of employees, according to VDE.
203 billion
euros of damages are sustained by the German economy each year due to IT attacks, according to Bitkom.
30 %
of small and medium-sized enterprises in Germany were attacked by cybercriminals between 2018 and 2020, according to KfW.
Yigal Unna
What approach do cybercriminals take?

Yigal Unna, Director General of the Israel National Cyber Directorate: ‘Above all, the criminals sow the seeds of mistrust – the best antidote is trusting partnerships.’

Shahar Alon
What role do shared values play?

Shahar Alon, Corporate Development Team at Checkmarx: ‘Shared values such as human dignity and privacy are decisive in defending against cyberattacks.’

Markus Wiegand
What can wider society do?

Markus Wiegand, Deputy Head of the Hessen CyberCompetenceCenter at the Hessian Ministry of the Interior and Sports: ‘We also have to be prepared to invest money and accept some inconvenience.’

An interview with Dr Hauke Hansen
 

1. What happens in the event of a cyberattack by hackers?

In the majority of cases, hackers carry out a ransomware attack. This is where malware, such as a Trojan virus disguised as a legitimate email attachment, is introduced into a corporate network so that all the data, including that of operating and control systems, is encrypted. This often brings all the systems to a standstill. In addition, the cybercriminals usually copy the data and threaten to publish it if a ransom is not paid. 

2. What does a good emergency plan involve?

Above all, an emergency plan should contain the measures to be taken immediately. After all, in the event of an attack, it is important to be able to react within hours – preferably within minutes – in order to limit the consequences. The questions at the very top of the list include: who should be informed and what happens if the email and phone systems no longer work? Who pulls the plug to prevent the attack from progressing further? And how can business operations be maintained or restored as quickly as possible?

3. Is it true that hacked companies are also threatened with administrative fines and thus required to pay twice over?

That is possible – specifically if the IT infrastructure was not state of the art at the time of the attack. The legislator underlines the importance of IT security through a legal provision in the General Data Protection Regulation and uses financial pressure to make companies aware of this. In other EU countries, data protection authorities have already imposed fines in the millions. Most German regulators are currently taking a different approach: they see the hacked companies as victims who should not be punished further.

4. How does FPS support the companies who have been victim of an attack?

On the day of the attack, we initially provide digital first aid: we establish contact with external experts, including IT forensics experts, cybersecurity companies and crisis communication agencies. If necessary, we lead the crisis team. On the second day at the latest, attention turns to the legal side: by when and in what way is the data protection authority to be informed in order to comply with the legal obligation and to avoid a fine at the same time? Do employees and customers need to be informed? And once operations are up and running again, we take care of fundamental issues such as defending against claims for damages.
 

Text: Silke Bauer
Images: Jens Lindemann

Any questions?

Feel free to get in touch with us if you have any questions or suggestions. We look forward to hearing from you.

Dr. Nina Jarass Cohen
Partnerin
Eschersheimer Landstraße 25-27
60322 Frankfurt am Main
Dr. Hauke Hansen
Partner
Eschersheimer Landstraße 25-27
60322 Frankfurt am Main
Dr. Christoph Süßenberger
Partner
Eschersheimer Landstraße 25-27
60322 Frankfurt am Main