€1.8m
average loss caused by a successful hacker attack on a large company
Corporate clients › Cyber insurance
Cyber risks through changing times
Cybercrime, consisting of offences committed through the internet or digital networks, has long since become an established and regrettable part of our online society. In its 2021 national situation report, Germany’s Federal Criminal Police Office recorded 146,363 offences, more than 12% above the previous year. And those are only the cases that were reported. Cybercrime now takes many forms, ranging from data theft to digital extortion.
The media regularly report attacks on major corporations, but small and medium-sized companies are also popular targets because their data is generally less well protected or not protected at all.

Evolution of Business Risks
From traditional merchant houses to the connected economy: Every era demands tailored protection strategies.
Victim and contributor
While you may be able to imagine the scale of the loss your own company could face, claims for damages made by affected third parties often come as a surprise. If you did not actively participate, why should you have to pay?
The courts take a clear position: anyone who contributes to harm suffered by a third party (for example through inadequate protection of their data) is jointly responsible (see, among other provisions, Germany’s IT Security Act, the EU General Data Protection Regulation and sections 202a et seq. of the German Criminal Code).
To protect your company comprehensively against the financial consequences of cyber risks, both first-party and third-party losses must be covered. The insurance industry has responded by developing suitable policies.
€1.8m
average loss caused by a successful hacker attack on a large company
€70,000
average loss for small and medium-sized companies
Coverage
Depending on the scope of the policy, justified liability claims resulting from misuse of data stored by your business are insured. Once liability for damages has been established, the insurer pays compensation up to the amount of the loss, but no more than the contractually agreed limit of indemnity.
The benefits of cyber-risk insurance primarily cover costs incurred by your company following an attack and financial losses suffered by third parties as a result of your involvement.
IT forensics costs
Legal advice
Notification costs
Credit monitoring services
Crisis management costs
PR consultancy costs
Business interruption losses
Contractual penalties (PCI)
Ransom payments
Restoration costs
Security improvements
Limits
Cyber-risk insurance may also contain exclusions. These regularly include:
Breaches of antitrust, competition or patent law
Losses caused intentionally
Effects of war or terrorism
Losses arising from enforcement by public authorities
Fines or financial penalties
Internal claims between the policyholder and an insured person
Guarantees
Source: Source: VEMA