Cybercrime

CyberCrime – When is the managing director liable?

Cybercrime is a growing threat to businesses and their executive bodies

Ransomware attacks are increasing rapidly and presenting companies with immense challenges. But when is the managing director personally liable for the damages caused by such attacks? This article sheds light on the legal basis and provides practical advice on how managing directors can minimize their liability.

Managing director liability cybercrime

Table of Contents

Legal basis for managing director liability

The liability of a managing director is governed by various legal provisions, in particular the Limited Liability Companies Act (GmbH-Gesetz) and the Stock Corporation Act (Aktiengesetz). A managing director is personally liable if they breach their duties and this causes damage to the company. In the context of cybercrime, this can be the case, for example, if insufficient IT security measures have been implemented.

Managing director's duties of care

Managing directors have the duty to exercise the diligence of a prudent businessman. This means that they must comprehensively inform themselves about threats and take appropriate measures to fend off cyberattacks. This includes regular security updates, employee training, and the use of security software tailored to the specific needs of the respective company.

Preventive measures to avoid liability

To minimize liability, managing directors should take preventive measures. These include implementing a comprehensive IT security concept, regular security audits, employee training, and the creation of an emergency plan in the event of a cyber attack. It is also advisable to take out cyber insurance policies that cover potential damages.

Liability in the event of damage

If a successful cyberattack occurs despite all precautionary measures, the question of liability arises. Managing directors are liable if gross negligence or intent can be proven against them. This can be the case if fundamental security standards were disregarded or insufficient protective measures were taken.

Conclusion: Timely consultation is crucial

The liability of the managing director in the event of cybercrime attacks is a complex topic that requires comprehensive knowledge and experience in several areas of law and in the field of IT security. It is therefore advisable to contact an experienced lawyer who has the necessary expertise in a timely manner. For further information and individual consultation, please feel free to contact Anela Blöch (bloech@atb.law) and Roman Taudes (taudes@atb.law) available at any time.

More articles

ATB.LAW Cybercrime Lawyer

Cybercrime in Austria

Legal situation, figures, and action steps
Picture of Roman Taudes
Roman Taudes
Business Email Compromise (BEC)

Business E-Mail Compromise

Who is liable – and when does a GDPR reporting obligation apply?
Picture of Roman Taudes
Roman Taudes
Cyberattack reporting obligations NIS GDPR MAR

Reporting obligations in the event of cyber attacks

What the TeamViewer case means for Austrian companies
Picture of Roman Taudes
Roman Taudes