EMERGENCY ASSISTANCE IN CYBER ATTACKS / Incident Response
Legal guardianship / Ransom negotiation / Handling of ransom payment
Cyberattacks are not merely an IT problem, but an acute legal, economic, and strategic crisis.
Emergency assistance and incident response in the event of cyberattacks. The battle-tested lawyers and negotiators of ATB.LAW provide companies and decision-makers with immediate and comprehensive support during ransomware and hacker attacks. From compliance with mandatory reporting to authorities (data protection authority, CERT, etc.) and conducting negotiations with the attackers to the organization and processing of ransom payments, we stand by your side 24/7 from day 1 of the attack.
Victim of a cyberattack? Legal Incident Response from Vienna
A hacker attack or cyber attack is an exceptional situation. Wrong decisions in the first hours, for example regarding communication, reporting, or payments, can trigger significant liability risks for companies and management. As part of incident response, we do more than just provide traditional legal support. We conduct negotiations with the attackers and organize—if necessary—the payment processing. The advantage: law, negotiation, and implementation are coordinated from a single source. This saves time, reduces errors, and ensures a consistent strategy during a crisis.
-
Legally sound decisions in the acute phase
(Managing communication, notifications, and measures correctly from the beginning) -
Negotiation with the attackers from a single source
(legally advised, tactically coordinated and continuously documented) -
Coordinated payment processing on demand
(legally vetted, structurally prepared and cleanly implemented) -
Fewer interfaces, fewer errors, more speed
(Law, negotiation and implementation mesh seamlessly) -
Protection against liability and consequential risks
(for companies and responsible bodies) -
Central coordination of all participants
(IT, forensics, insurance, authorities, and internal decision-makers)
Cyberattack – what now? Our services in the event of a crisis
Legal Solutions & Crisis Management
As soon as the attack becomes known, we will assume overall legal and strategic coordination. The objective is to establish a rapid, legally compliant, and documented basis for decision-making in the crisis situation.
- Ongoing data protection assessment of the incident
- Review and fulfillment of reporting and information obligations
- Internal and external communication
- Representation in civil and administrative proceedings
- Strategic Risk and Liability Assessment
Negotiation with ransomware attackers
In close coordination with you, we take over the contact and conduct negotiations with the attackers.
- Safe and controlled contact
- Professional negotiation with the attackers
- Examination of the seriousness of threats and commitments
- Ongoing legal classification of the negotiation steps
- Documentation of communication for internal and external purposes
Review and processing of ransom payments
If desired, legally permissible, and strategically sound, we will handle the coordinated processing of the ransom payment. Decision-making, negotiation, and execution remain in a single hand.
- Review of the legal admissibility of the payment
- Assessment of money laundering, sanctions and criminal law risks
- Structured preparation and support of payment processing
- Coordination with IT forensics, wallet providers, and service providers
- Legal documentation of decision-making and payment processes
Cyberattack THIS IS WHAT NEEDS TO BE DONE NOW
- Stay calm and act methodically: The first few hours are crucial. Premature decisions regarding communication, reports, or payments can increase liability risks and jeopardize evidence.
- Immediately assemble a crisis team. This specifically includes management, IT, IT forensics, legal counsel, ransom negotiators, data protection/compliance, and – depending on the case – insurance and communications. Only when all parties are coordinated at an early stage can measures be implemented in a legally secure, technically sound manner, and without unnecessary loss of time.
We support you in the legal and operational coordination of the crisis team. Upon request, we also provide the necessary external specialists – IT forensics/cybersecurity experts, communication consultants, and other technical service providers. You receive a coordinated setup from a single source – from crisis management and negotiation to legally reviewed payment processing.
That is why you choose ATB.LAW
- Specialized in cybercrime, incident response, data protection, and cryptocurrencies
- Extensive experience in managing cyber attacks and data leaks
- Law, negotiation management and payment processing from a single source
- Provision and coordination of external specialists (IT forensics, incident response, communication)
- Clear, pragmatic recommendations for action for management and crisis team
Our Experts
ExpertsPosts
Questions on the topicRANSOMWARE ATTACK
What does incident response mean?
Incident response refers to the structured procedure for handling an IT security incident, such as a hacker attack, data leak, ransomware, or a compromised email account.
The goal is to rapidly contain the incident, prevent further damage, preserve evidence, and restore the systems as securely as possible. This also includes the legal assessment, potential reporting obligations, and communication with affected individuals or authorities.
Must a ransomware attack be reported?
Whether a ransomware attack must be reported depends on several factors – in particular, whether personal data is affected, what type of data was processed, and what risk exists for the data subjects. In many cases, there is an obligation to report to the data protection authority within 72 hours. In addition, industry-specific reporting obligations (e.g., KRITIS, NIS2) may be relevant. We will promptly examine the specific situation and handle the legally secure assessment and – if necessary – the complete communication with the competent authorities.
Is the payment of ransom allowed?
The payment of ransom is not prohibited across the board in Austria, but it can be highly problematic from a legal perspective. Depending on the specific circumstances, there may be risks under criminal, administrative, corporate, or sanctions law—such as in the event of violations of anti-money laundering or sanctions regulations. Before making a payment, the legal and factual admissibility of a ransom payment must be examined and documented. ATB.LAW undertakes this review and provides structured legal support for the decision. We advise you clearly and transparently on the legal risks and alternatives before a decision is made.
Who is taking over the negotiations with the hackers?
ATB.LAW takes over the Negotiation with the attackers. We have the experience and the setup to initiate negotiations with the hackers at any time. Our negotiation team usually consists of an experienced lawyer and an IT expert - ensuring that we achieve the best possible negotiation result.
Who will help me pay the ransom?
ATB.LAW organizes and assists with the ransom payment.
We structure the process, coordinate the involved parties, and ensure a legally and operationally sound implementation, provided that a ransom payment is legally permissible and strategically sensible.
Where do I get Bitcoin for a ransom?
ATB.LAW organizes the procurement of the required cryptocurrency and accompanies the entire process. For emergencies such as a hacker attack, we have established "priority lanes" or "rapid KYC procedures" at several crypto exchanges, which enable smooth processing in a short amount of time.
Do you work with IT security and forensics experts?
ATB.LAW collaborates with experienced IT security and forensics professionals and has a large network.
We can quickly integrate the appropriate external service providers and centrally coordinate the collaboration. This ensures that legal, technical, and organizational measures interlock seamlessly – from attack analysis and containment to follow-up and the prevention of further incidents.
Can we also be contacted if the attack happened some time ago?
Yes, absolutely. Even in the case of cyberattacks that occurred some time ago, legal obligations, liability issues, or subsequent reporting may still be relevant. We analyze the past course of events, identify remaining risks, and provide support for legally compliant processing—including internal documentation and external communication.
How quickly is ATB.LAW available in an emergency?
In the event of a cyberattack / hacker attack ATB.LAW on site within a few hours or working remotely. ATB.LAW has a 24/7 emergency service.