EMERGENCY ASSISTANCE IN CYBER ATTACKS / Incident Response

Legal guardianship / Ransom negotiation / Handling of ransom payment

Cyberattacks are not merely an IT problem, but an acute legal, economic, and strategic crisis.

Emergency assistance and incident response in the event of cyberattacks. The battle-tested lawyers and negotiators of ATB.LAW provide companies and decision-makers with immediate and comprehensive support during ransomware and hacker attacks. From compliance with mandatory reporting to authorities (data protection authority, CERT, etc.) and conducting negotiations with the attackers to the organization and processing of ransom payments, we stand by your side 24/7 from day 1 of the attack.

Roman Taudes, Andreas Wallner

A hacker attack or cyber attack is an exceptional situation. Wrong decisions in the first hours, for example regarding communication, reporting, or payments, can trigger significant liability risks for companies and management. As part of incident response, we do more than just provide traditional legal support. We conduct negotiations with the attackers and organize—if necessary—the payment processing. The advantage: law, negotiation, and implementation are coordinated from a single source. This saves time, reduces errors, and ensures a consistent strategy during a crisis.

Cyberattack – what now? Our services in the event of a crisis

Legal Solutions & Crisis Management

As soon as the attack becomes known, we will assume overall legal and strategic coordination. The objective is to establish a rapid, legally compliant, and documented basis for decision-making in the crisis situation.

Negotiation with ransomware attackers

In close coordination with you, we take over the contact and conduct negotiations with the attackers.

Review and processing of ransom payments

If desired, legally permissible, and strategically sound, we will handle the coordinated processing of the ransom payment. Decision-making, negotiation, and execution remain in a single hand.

Cyberattack THIS IS WHAT NEEDS TO BE DONE NOW

Mag. Roman Taudes Lawyer Vienna

We support you in the legal and operational coordination of the crisis team. Upon request, we also provide the necessary external specialists – IT forensics/cybersecurity experts, communication consultants, and other technical service providers. You receive a coordinated setup from a single source – from crisis management and negotiation to legally reviewed payment processing.

That is why you choose ATB.LAW

Our Experts

ExpertsPosts

ATB.LAW Cybercrime Lawyer

Cybercrime in Austria

Legal situation, figures, and action steps
Business Email Compromise (BEC)

Business E-Mail Compromise

Who is liable – and when does a GDPR reporting obligation apply?
Cyberattack reporting obligations NIS GDPR MAR

Reporting obligations in the event of cyber attacks

What the TeamViewer case means for Austrian companies

Questions on the topicRANSOMWARE ATTACK

Incident response refers to the structured procedure for handling an IT security incident, such as a hacker attack, data leak, ransomware, or a compromised email account.

The goal is to rapidly contain the incident, prevent further damage, preserve evidence, and restore the systems as securely as possible. This also includes the legal assessment, potential reporting obligations, and communication with affected individuals or authorities.

Whether a ransomware attack must be reported depends on several factors – in particular, whether personal data is affected, what type of data was processed, and what risk exists for the data subjects. In many cases, there is an obligation to report to the data protection authority within 72 hours. In addition, industry-specific reporting obligations (e.g., KRITIS, NIS2) may be relevant. We will promptly examine the specific situation and handle the legally secure assessment and – if necessary – the complete communication with the competent authorities.

The payment of ransom is not prohibited across the board in Austria, but it can be highly problematic from a legal perspective. Depending on the specific circumstances, there may be risks under criminal, administrative, corporate, or sanctions law—such as in the event of violations of anti-money laundering or sanctions regulations. Before making a payment, the legal and factual admissibility of a ransom payment must be examined and documented. ATB.LAW undertakes this review and provides structured legal support for the decision. We advise you clearly and transparently on the legal risks and alternatives before a decision is made.

ATB.LAW takes over the Negotiation with the attackers. We have the experience and the setup to initiate negotiations with the hackers at any time. Our negotiation team usually consists of an experienced lawyer and an IT expert - ensuring that we achieve the best possible negotiation result.  

ATB.LAW organizes and assists with the ransom payment.
We structure the process, coordinate the involved parties, and ensure a legally and operationally sound implementation, provided that a ransom payment is legally permissible and strategically sensible.

ATB.LAW organizes the procurement of the required cryptocurrency and accompanies the entire process. For emergencies such as a hacker attack, we have established "priority lanes" or "rapid KYC procedures" at several crypto exchanges, which enable smooth processing in a short amount of time. 

ATB.LAW collaborates with experienced IT security and forensics professionals and has a large network.
We can quickly integrate the appropriate external service providers and centrally coordinate the collaboration. This ensures that legal, technical, and organizational measures interlock seamlessly – from attack analysis and containment to follow-up and the prevention of further incidents.

Yes, absolutely. Even in the case of cyberattacks that occurred some time ago, legal obligations, liability issues, or subsequent reporting may still be relevant. We analyze the past course of events, identify remaining risks, and provide support for legally compliant processing—including internal documentation and external communication.

In the event of a cyberattack / hacker attack ATB.LAW on site within a few hours or working remotely. ATB.LAW has a 24/7 emergency service.