• Latest
  • Trending
d18d1e1d82c0cecc1bcb94866a5316f4

Cyber insurance refuses to pay benefits after hacker attack due to false information

18. June 2024
BGH considers Uber Black to be anti-competitive

Distance learning, coaching and synchronous online formats

2. March 2026
Media outlets consider influencers law pointless

Manipulated QR codes and quishing

27. February 2026
AI agents as autonomous contractual partners?

AI agents as autonomous contractual partners?

26. February 2026
Platform cooperatives as a financing and business model

AI training data as an asset: accounting, IP strategy and exit factor

25. February 2026
Streaming setup, influencers and contract law

Influencers: when marketing suddenly becomes commercial agency law

18. February 2026
Insolvency administrator and access to tax office data?

NRW audits influencers – and suddenly normal rules apply?

12. February 2026
iStock 1405433207 scaled

Legal pitfalls in revenue-based financing for start-ups

12. February 2026
Streaming setup, influencers and contract law

Streaming setup, influencers and contract law

9. February 2026
Platform cooperatives as a financing and business model

Platform cooperatives as a financing and business model

8. February 2026
Frankfurt district court a.M. softens influencer jurisdiction

VAT on donations, gifts and “support” from influencers?

5. February 2026
Chamber Court on obligations to injuntture in the case of acts of third parties

Jurisdiction in the contract: one word too many, one word too few

4. February 2026
New info on the status of the State Media Treaty

Customer hotline and support in SaaS

2. February 2026
BGH considers Uber Black to be anti-competitive

BGH: FRAND objection fails due to lack of willingness to license

28. January 2026
marianregel

InformationCheck.de is live: side project for source-based classification of social media claims

22. January 2026
DPMA

Paid mods, fan guidelines and EULA: when monetization is possible

21. January 2026
Is an 8 year old allowed to be an Esport player?

LOI, term sheet, MoU, often binding for startups?

20. January 2026
What actually is an IP? In the games, music and film industry!

Freelancer paid, but still not getting rights?

19. January 2026
Affiliate links for streamers and influencers

Comparison sites as an SEO trick

16. January 2026
Reverse vesting

Vesting, good leavers, bad leavers – why a lack of regulations costs startups dearly

15. January 2026
ai generated g63ed67bf8 1280

AI guideline for agencies and external service providers

14. January 2026
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Cyber insurance refuses to pay benefits after hacker attack due to false information

18. June 2024
in Other
Reading Time: 3 mins read
0 0
A A
0
d18d1e1d82c0cecc1bcb94866a5316f4

In a ruling dated 23.05.2024 (Ref. 5 O 128/21), the Regional Court of Kiel ruled that a cyber insurance policy is exempt from payment due to false information in the insurance application. The insurer had contested the contract on the grounds of fraudulent misrepresentation after the insured company, a timber wholesaler, suffered a hacker attack resulting in significant damage.

Content Hide
1. Inadequate IT security despite information to the contrary
2. Fraudulent misrepresentation leads to exemption from benefits
3. Significance for companies and insurance companies
3.1. Author: Marian Härtel
Key Facts
  • Kiel Regional Court ruled that cyber insurance is exempt from payment due to false information in the application.
  • The timber wholesaler had declared insufficient IT security despite providing false information in the insurance application.
  • Important systems were equipped with outdated operating systems and without virus protection, which led to a hacker attack.
  • The IT manager >must have recognized the security flaws and could have checked them, which was considered malice.
  • The ruling emphasizes the importance of correct answers to risk questions in cyber insurance policies.
  • External security experts can help to objectively assess the IT security situation and mitigate risks.
  • The ruling reminds companies to take their IT security seriously and not just rely on insurance cover.

Inadequate IT security despite information to the contrary

In this case, when taking out cyber insurance in 2020, the timber wholesaler had stated, among other things, that all work computers were equipped with up-to-date malware detection and that available security updates were carried out without culpable hesitation. However, there were actually several servers in use with outdated, insecure operating systems for which updates were no longer available. The employee responsible for IT at the timber wholesaler stated during the trial that he had “deliberately overlooked” the systems in question when answering the risk questions. These were not subordinate computers, but servers with central functions for operations. An unprotected server with an outdated Windows system served as a connection between the web store and the company’s merchandise management system. For companies with complex IT systems in particular, it can make sense to commission external security experts to carry out an objective review of the system landscape. An external perspective often makes it easier to identify weaknesses than internal employees, who may be blind to the company’s operations or do not have an overview of all areas due to time constraints. Such a security analysis can also help to correctly present IT security to insurers and avoid unpleasant surprises in the event of a claim.

Fraudulent misrepresentation leads to exemption from benefits

The court considered the false information to be fraudulent misrepresentation on the part of the insurer, as the questions were answered incorrectly “in the blue”. The responsible IT manager could and should have recognized the security deficiencies. Due to the fraudulent misrepresentation, the insurance contract was null and void so that the insurer did not have to pay out. the decisive factor for the court’s assessment was that the inadequately protected systems had central functions in the company. The outdated Windows server was essential as a connection between the web store and merchandise management. The domain controller for managing access rights in the network was also still in an insecure delivery state. In the case of such important systems, the court could not believe that their security deficiencies had remained hidden from the IT manager, who, according to an expert witness, could have quickly checked that the virus protection and security updates were up-to-date by looking at the administration consoles. The fact that he had failed to do so before answering the risk questions was considered by the court to be an indication of fraudulent intent. Especially when taking out cyber insurance, the person responsible must be aware of how important the insurer takes the information on IT security.

Significance for companies and insurance companies

The ruling shows how important it is to answer risk questions correctly for cyber insurance policies. Companies must ensure that their IT security standards correspond to the information in insurance applications in order to be covered in the event of a claim. False statements, even if they are only made negligently, can lead to the insurer being released from its obligation to indemnify, and it can make sense for larger companies with complex IT systems in particular to have the risk questions answered by external security experts. This allows the actual security situation to be assessed objectively and presented correctly. It is also advisable to have penetration tests and vulnerability analyses carried out by specialized service providers at regular intervals in order to improve IT security overall. For insurers, the decision means that they can invoke fraudulent misrepresentation as a “sharp sword” if false statements can be proven. In view of the increasing threat of cybercrime, many insurers are likely to revise and specify their risk questions in order to avoid disputes and limit their exposure. Overall, the judgment of the Regional Court of Kiel is to be welcomed, as it underlines the importance of a truthful risk declaration and enables insurers to keep their liability risk calculable. It reminds companies to take their IT security seriously and not to rely solely on insurance cover. Because even with a cyber policy, prevention is better than cure.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: DomainEmployeesIT SecurityJudgmentServerSicherheit

Weitere spannende Blogposts

Exciting decision on e-mail access in civil procedure law

Exciting decision on e-mail access in civil procedure law
23. April 2024

Background to the decision Digital communication has become an integral part of modern legal transactions, but the question of the...

Read moreDetails

Domain seizure: BGH obliges DENIC

7. November 2022

While domains were actually just an address at the beginning of the Internet hype, they are increasingly becoming an economic...

Read moreDetails

German courts have jurisdiction at .de Domain

German courts have jurisdiction at .de Domain
20. March 2019

Time and again, especially with international Internet portals, the question arises as to whether German courts have jurisdiction, for example...

Read moreDetails

Corporate data protection: An often underestimated topic

Corporate data protection: An often underestimated topic
8. August 2023

In today's digital era, many of us have become accustomed to privacy statements and cookie banners. These are present almost...

Read moreDetails

Client portal as PWA

Client portal as PWA
7. November 2022

The client portal of mine can now also be used as a mobile app and thus, for example, added as...

Read moreDetails

Agreement on new State Treaty on Gambling

Agreement on new State Treaty on Gambling
7. November 2022

Next year, there will probably be a new State Gambling Treaty and casino apps will then be permitted throughout Germany....

Read moreDetails

Spree killings announced over the Internet?

Spree killings announced over the Internet?
7. November 2022

In Main 2013, the plaintiff in a case at the Aachen Administrative Court announced multiple rampage attacks at the Realschule...

Read moreDetails

What is the Artificial Intelligence Act?

What is the Artificial Intelligence Act?
6. January 2023

Introduction The Artificial Intelligence Act is a proposal for a European law on artificial intelligence (AI) - the first law....

Read moreDetails

SEO and law – a balancing act between visibility and security

img LkyqWNCTGcprds9IuQPTVGz9
21. November 2023

As a lawyer specializing in IT law, copyright law and competition law, I face the challenges that arise at the...

Read moreDetails
BGH considers Uber Black to be anti-competitive
Law and Esport

Distance learning, coaching and synchronous online formats

2. March 2026

The Distance Learning Protection Act (FernUSG) has been experiencing a renaissance for some time now. What for decades was considered...

Read moreDetails
Media outlets consider influencers law pointless

Manipulated QR codes and quishing

27. February 2026
AI agents as autonomous contractual partners?

AI agents as autonomous contractual partners?

26. February 2026
Platform cooperatives as a financing and business model

AI training data as an asset: accounting, IP strategy and exit factor

25. February 2026
Streaming setup, influencers and contract law

Influencers: when marketing suddenly becomes commercial agency law

18. February 2026

Podcastfolge

c9c5d7fd380061a8018074c2ca5a81bf

Startups and innovation in Germany – challenges and opportunities

26. September 2024

This insightful podcast episode takes an in-depth look at the startup and innovation landscape in Germany and Europe. The discussion...

Read moreDetails
d5e1e6cad87cb839a9e23af79034bd94

AI in the legal system: Towards a digital future of justice

16. October 2024
7c0b449a651fe0b81e5eec2e23515012 2

Copyright in the digital age

15. January 2025
43a60cb39d7ea477ac8f3845c1b7739c

Legal advice for start-ups – investments that pay off

8. December 2024
86fe194b0c4a43e7aef2a4773b88c2c4

On the dark side? A lawyer in the field of tension of innovative start-ups

26. September 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung