An employee opens an attachment on Monday morning. By Tuesday lunchtime the practice has stopped: no client files, no payroll run, no deadline control. Cyber attacks have long since stopped hitting only large corporations, and they hit professional firms particularly hard. Why that is, where professional indemnity insurance ends and what cyber insurance really delivers when it matters.
Why professional firms are a worthwhile target
Anyone attacking a tax firm is not attacking one company but hundreds at once. The systems of an average practice hold, bundled in one place, what criminals would otherwise have to piece together laboriously one by one:
On top of that comes a second factor that sets professional firms apart from every other business: their business is trust. The professional duty of confidentiality (Section 57 of the German Tax Advisory Act (StBerG), Section 203 of the German Criminal Code (StGB)) is not a side issue, it is the core of how the profession is practised. A data leak therefore damages not the IT but the basis of the business. To be clear: nobody who becomes the victim of an attack commits a criminal offence. Section 203 StGB requires a disclosure. What is damaged is something else, namely the trust the client relationship rests on.
What the standstill really costs
At the words cyber attack, most people think of ransom. In practice the extortion is rarely the most expensive part. What gets expensive is what follows: the forensics, the restoration, rebuilding systems, the additional costs for replacement IT, the loss of income, the notifications, the legal advice, the communication to the outside world.
For a professional firm the standstill has an edge of its own. It hits not only the firm's own business but the deadlines of its clients. Payroll runs do not wait. Filing deadlines do not move because a server has been encrypted. Anyone working for three hundred clients has three hundred callers when it happens, all wanting to know the same thing: are my data gone, and when will things be running again?
The first 72 hours
The moment an incident becomes known, a clock starts running. It is not set by the insurance contract but by data protection law.
The incident is noticed
Disconnect systems, delete nothing, alert internal IT and the insurer. The traces destroyed now are the ones missing later when the cause is established.
The forensics team takes over
What happened, what has leaked, what is still clean? In parallel, it is decided who is informed and when.
The report to the supervisory authority
Where the incident is likely to result in a risk to the individuals affected, Article 33 GDPR requires a report to the supervisory authority: without undue delay and, where feasible, not later than 72 hours after becoming aware of it, not after the investigation is complete. Anyone reporting later gives reasons for the delay. Missing information may be supplied afterwards.
Those affected, rebuilding, trust
Where a high risk is likely, notification of the individuals affected is added (Article 34 GDPR), without undue delay and not only once the report to the supervisory authority has gone out. For a professional firm that means the clients. Alongside it: restoration, legal questions, communication.
Anyone reading this sequence for the first time while it is happening loses the most valuable hours to organising. This is exactly where the practical value of cyber insurance lies: it provides the specialists who handle this sequence as a matter of routine, and it pays them.
Your professional indemnity insurance does not cover this
Every tax firm holds professional indemnity insurance; Section 67 StBerG requires it. From that an obvious thought follows: the topic is settled. It is wrong, and the error is expensive.
Professional indemnity insurance is cover for financial loss. It responds when a third party brings claims against the firm, typically after an advisory error. For what an attack does inside the firm itself, it does not respond under standard market terms. Which modules your particular set of terms contains is a question the policy itself answers.
What professional indemnity insurance covers
- Third-party claims arising from errors in professional work
- The defence against unjustified claims of that kind
What it does not cover
- Restoring the firm's own data and systems
- Loss of income while the practice stands still
- IT forensics and establishing the cause
- Reporting to the supervisory authority and notifying the clients
- Crisis communications and reputational damage
- Computer fraud and extortion situations
The two contracts do not compete. They cover two different directions: one protects against claims from outside, the other bears the damage on the inside and defends against claims arising from a data leak.
What cyber insurance delivers
The cover stands on two legs, and depending on the variant chosen it carries one or both.
Your own losses. Restoring data and programs, additional costs for IT and telecommunications, losses from computer fraud, damaged hardware and, in the more comprehensive variant, business interruption while the firm is at a standstill. Important in practice: operating errors by employees are covered. The case where someone deletes or clicks by accident is the normal case, not the exception.
Third-party claims. When client data leak or a virus is passed on unnoticed, outside claims are quickly on the table. Here the more comprehensive variant covers not only financial loss but also personal injury and property damage, plus contractual penalties from confidentiality agreements. And it defends against unjustified claims, which in practice is worth at least as much as paying the justified ones.
On top of that come the services, which when it matters often weigh more heavily than any sum insured: help from the point of reasonable suspicion, a claims hotline around the clock, IT specialists on site or via remote access, crisis and reputation management, legal advice including as a precaution. If a suspicion is not confirmed, depending on the plan up to two daily rates for the examination are still covered. The thinking behind it is right: no one should hesitate to call out of fear of the cost.
The value of cyber insurance is rarely decided by the sum insured, it is decided in the first 24 hours. Whoever can make one call instead of searching loses days less.
The short route for professional firms
For tax advisors, lawyers, auditors and notaries there is a simplified route in. The reason is a practical one: the risk profile of these professions is known and similar across firms. Depending on the plan, that results in a noticeably shorter route.
- Instead of a multi-page risk questionnaire, a handful of risk questions is enough.
- The premium depends solely on the number of qualified professionals. Salaried office staff play no part in it.
- A single overall sum insured covers all modules, instead of separate sums for each area.
- Only for larger units or higher sums insured does the route lead through the full questionnaire.
In practice that means: for most firms, taking stock is a matter of minutes, not days. And it starts with the question every practice puts to its clients, only this time about itself: what happens here if nothing works on Monday morning?
For companies: three ways in
Outside the professional firms, size determines what the route in looks like and which variant fits. Smaller units start with the lean variant, larger ones with the more comprehensive one covering third-party claims and business interruption.
Up to 1 million euros annual turnover
A direct proposal without a questionnaire. Ready to sign within a few days.
1 to 50 million euros annual turnover
A compact risk questionnaire that also shows where the company stands on IT security.
From 50 million euros annual turnover
A structured process together with your IT team, at enterprise scale.
For individual sectors with a clearly defined risk, such as the skilled trades, retail or hospitality, there is an additional simplified route without a questionnaire up to a defined turnover limit. Which route fits is settled within a few minutes in the initial consultation.
Prevention: the part most people skip
The biggest way in is not in the server room, it is at the desk. That is why the cover can be extended with a prevention package from a specialised partner:
The decisive point is not in the training plan, it is in the contractual consequences. Depending on the package, the excess falls in the first claim, down to zero up to a defined limit. Depending on the package, the insurer additionally waives its right to terminate after a claim and, up to a defined limit, the objection of gross negligence. In other words, precisely in the case that occurs most often in reality: an employee clicked.
Honestly speaking
Cyber insurance is not a shield. It does not prevent an attack, it bears the consequences. And it has limits. Those belong on the table beforehand, not afterwards.
- Terrorist attacks on IT systems and the failure of infrastructure, for example the internet or the power supply, are not insured.
- Two obligations come with the contract: operating systems and programs for which the manufacturer still supplies updates, and the prompt installation of those updates. In addition, a data backup at least once a week, kept separately from the originals.
Anyone who does not meet these requirements today is not shut out by that. Signing up is possible, and the cover starts as soon as the requirements are in place. In practice that is often the real gain from the conversation: you tidy up before something happens, not afterwards. A residual risk remains in every case. The question is not whether it can be eliminated, but who carries it.
Frequently asked questions
Our practice software runs through a data centre. Does that not already protect us?
The data centre protects the data processed there. It does not protect the devices in the firm, the email accounts, the payment traffic or the team's ability to work. The most common route of attack runs through an email to a workstation, not through the data centre. Under data protection law, the firm remains the controller for its client data. The data centre has its own obligations as a processor alongside that, but it does not take the firm's place.
We have professional indemnity insurance. Is that not enough?
Professional indemnity insurance is a liability policy: it steps in when a third party brings claims against the firm, typically after an advisory error. It does not cover the firm's own costs after an attack, meaning forensics, restoring the data, additional costs, notifying the individuals affected and crisis communications. That is exactly the gap cyber insurance closes, depending on the variant up to and including business interruption during the standstill. The two contracts do not compete, they complement each other.
We are a small practice. Are we even a target?
Most malware does not pick its victims, it spreads indiscriminately. Whoever is reachable gets hit. Small units are often hit harder, because the reserves to absorb a shutdown are missing and there is no IT department of their own to catch the emergency. That is why the route to cover is deliberately kept simple for professional firms.
An employee opened the attachment. Will the insurer pay at all in that case?
Yes. Operating errors by employees are covered, and that is the normal case rather than the exception. In cases of gross negligence an insurer can in principle reduce the benefit. Depending on the prevention package added, it waives this objection up to a defined limit and additionally waives its right to terminate after a claim. The exact arrangement depends on the plan and the package.
What happens if we only suspect an attack?
A reasonable suspicion is already enough for an IT service provider to be brought in, who establishes the cause and the extent. If the suspicion is not confirmed, depending on the plan up to two daily rates for that examination are still covered. The thinking behind it: no one should hesitate to pick up the phone out of fear of the cost. The most expensive mistake after an attack is the time lost.
Are fines following a data protection breach covered?
Depending on the variant, and as far as legally permissible, the reimbursement of fines after a personal data breach is included. Whether a fine is insurable at all in an individual case depends on the legal framework and is not decided by the contract alone. In every case the costs of reporting, of notifying the individuals affected and of legal advice form part of the cover.
Further reading
- Cyber protection at a glance: every perspective for companies
- Tax advisor and pension specialist: what makes collaboration on company pension schemes work
What responds at your firm if nothing works on Monday morning? In an initial consultation we clarify where your existing contracts end, what an attack would trigger in your structure and which route fits your size. No obligation, in Berlin at Gendarmenmarkt or online.
This content is general information and no substitute for individual advice. Tax structuring is carried out in coordination with the client's tax advisor.