Emergency help for companies

Ransomware attack on your company: what to do now

Your systems are encrypted, data has been exfiltrated, or you have received a ransom note? Here you will find the first steps and a checklist that calculates your statutory notification deadlines from your answers. You can then send your answers directly to our team.

Lead counsel for cyber emergencies: Christian Galetzka · deputy lead: Patrizia Frankenberger.

Office hours (Berlin time)
Mon–Thu 8–17 · Fri 8–15 
Outside office hours
Checklist right awayNo callback is guaranteed.

Affected as a private individual, for example by a hacked social media account? JUNLOCK (in German) is the right point of contact.

The first hours

[ Regardless of the specific case ]

These steps apply to almost every ransomware incident. They preserve evidence and lay the groundwork for all later decisions.

1Immediately

Disconnect affected systems from the network

Unplug the network cable and disable Wi-Fi. Do not shut the devices down: the working memory contains traces that matter for the forensic analysis. This is also what the Federal Office for Information Security (BSI) recommends.

2Immediately

Communicate through a secure channel

Assume that the attackers are reading your emails and chats. Coordinate by phone or via personal devices. Treat all credentials on affected systems as compromised.

3Immediately

Do not negotiate with the attackers

Do not make contact and do not make any payment before the legal questions have been resolved. These concern sanctions law and criminal law. In addition, your cyber insurer usually makes payments subject to its consent.

4Immediately

Notify your cyber insurer

Under § 30(1) VVG (German Insurance Contract Act), you must report the insured event without undue delay. Many policy terms require notification via a claims hotline and coordination before you engage service providers.

5Within the first hour

Start an incident log

Record, with timestamps, who noticed and initiated what and when. Preserve ransom notes and screenshots. Do not delete anything and do not rebuild any systems before a forensic image has been taken.

6Today

Keep an eye on notification deadlines

Statutory deadlines start running from the moment you become aware of the incident, some of them expire after 24 hours. The intake below determines which ones apply to you. The deadlines run hour by hour, including over weekends and public holidays.

Backups

Check whether clean offline backups exist and keep them disconnected from the network. Restore backups only once it is clear how the attackers got in. Otherwise you risk being encrypted again.

Emergency intake

[ Takes about 3 minutes ]

From your answers we immediately generate your personal checklist with the calculated notification deadlines. At the end you decide whether to send your answers to us or to use the checklist only.

  1. 1 · Incident
  2. 2 · Obligations
  3. 3 · Contact

What happened?

Multiple answers possible. “Don’t know” is always a valid answer.

Decisive for all deadlines. If in doubt, enter the earliest point in time.
What have you observed?
Are email, Microsoft 365, or your chat systems affected?
Have the attackers set a payment deadline?
Has anyone already been in contact with the attackers?

How we support you

[ Legal incident support ]

We advise on the legal questions of the incident. We do not provide IT forensic analysis, system recovery, or technical hardening; for these you engage IT specialists separately. We work together with those providers so that the technical findings and the legal steps fit together.

01
Notifications

Notifications to authorities

Review and drafting of notifications under Art. 33 GDPR, § 32 BSIG, and Art. 14 CRA. We align the notifications with one another so that they do not contradict each other.

02
Insurance

Coordination with the insurer

Reporting the insured event, complying with policy obligations, and clarifying cost coverage for forensics and recovery.

03
Extortion

Handling the ransom demand

Legal assessment of a payment under sanctions and criminal law. The decision remains yours; we provide a sound basis for it.

04
Data subjects

Informing affected individuals

Communication under Art. 34 GDPR and with customers, employees, and contractual partners, aligned with your contractual obligations.

05
Investigations

Criminal complaint and investigating authorities

Filing a criminal complaint, working with the police’s Central Cybercrime Contact Point (ZAC), and obtaining access to the investigation file for your further claims.

06
Afterwards

Liability and claims

Defending against damages claims under Art. 82 GDPR, claims against service providers, and reviewing management’s responsibility.

Frequently asked questions

Will someone call us back?
During our office hours (Monday to Thursday 8 a.m. to 5 p.m., Friday 8 a.m. to 3 p.m., Berlin time), a member of our cybersecurity team will call you as soon as possible. Outside office hours we do not guarantee a callback. Your inquiry will then be handled as a priority at the start of the next office hours. You can use the checklist right away at any time.
Does submitting the intake already constitute an engagement?
No. An engagement (Mandat) only comes into existence once we agree on it with you. Before that, we check for conflicts of interest.
What does the intake cost?
The intake and the checklist are free of charge. We discuss the fees for legal advice with you before we start working.
Do we have to notify even though we know very little yet?
The law anticipates this situation. Under Art. 33(4) GDPR, you may provide information in phases. § 32(1) no. 1 BSIG expressly provides for an early warning, followed later by the detailed notification. An incomplete notification within the deadline is therefore usually better than a complete notification after the deadline has passed.
Are we allowed to pay the ransom?
There is no blanket answer. Criminal law, EU and U.S. sanctions lists, and your insurance terms all play a role. Do not make this decision without legal advice, and document your reasons.
What happens to our answers?
Your answers are transmitted in encrypted form and go directly by email to the lawyers handling the matter. They are not stored permanently on our server. They are covered by attorney-client privilege. If you choose “Create checklist only”, all answers remain in your browser.

Your cybersecurity team

During the incident you are supported by lawyers who bring together IT security law, data protection, and IT contract law.