
If you run a business in Germany, big or small, you're already living online. Invoices go out by email, client data sits in a cloud tool, payments run through a bank portal, maybe you've got a webshop ticking away in the background. None of that feels risky until the day it is: one phishing email, one bad password, one unpatched plugin, and suddenly your business is locked out of its own systems.
That's the exact gap cyber insurance ("Cyber-Versicherung") is built for. It's not the most glamorous insurance product, and unlike liability or health cover, most people in Germany, including a lot of Germans, have never had to think about it. But the numbers below suggest that's changing fast, and for good reason. Let's break down what it actually is, what it covers, what it costs, and whether you, specifically, need it.

What is cyber insurance, really?
Cyber insurance covers the financial fallout when your business gets hit by a cyberattack, a data breach, or even a system failure that has nothing to do with hackers, think a server crash that takes your accounting software offline for a week.
The functionality is, luckily, fairly simple to explain: instead of insuring a physical thing like a car or a building, you're insuring your digital operations and the data that flows through them. If something goes wrong online, the policy is there to cover the costs of fixing it, telling the people affected, and keeping your business running while you do. You can see how VBW structures this on our own cyber security insurance page.
Standard policies in the German market tend to bundle three broad categories of protection together:
- Data breach response - legal fees, forensic IT investigation, notifying affected customers, and (where needed) PR support to manage reputational damage.
- Business interruption - covering lost income and ongoing costs while your systems are down and you can't operate normally.
- Ransomware and extortion - costs tied to ransomware attacks, including, depending on the insurer and policy, negotiation support and payment where legally permitted.
Some policies extend further into third-party damages (if a breach on your end affects your clients or partners) and the extra cost of restoring corrupted or lost data.

Is the risk actually this big in Germany, or is it overhyped?
It's not overhyped. Germany's Federal Ministry of the Interior put the total damage from cyber crime to the German economy at €202.4 billion in 2025, roughly 4.5% of GDP. Around 334,000 cyber crime cases were recorded that year, two-thirds of them originating from outside Germany or from unknown locations, and the real number is almost certainly higher since a lot of cyber crime never gets reported at all.
Ransomware specifically is on the rise: 1,041 attacks were reported in 2025, a 10% increase over the previous year. And according to Germany's Federal Office for Information Security (BSI), average ransom demands are climbing even as fewer victims choose to pay.
Here's the part that surprises a lot of small business owners: this isn't mainly a big-corporation problem. The BSI found that around 80% of reported attacks in its most recent reporting period targeted small and medium-sized businesses, precisely because smaller companies tend to have fewer resources and less in-house expertise to defend themselves, while often overestimating how secure they actually are.
Separately, Bitkom's annual "Wirtschaftsschutz" survey, conducted with Germany's domestic security service, found that 87% of German companies were affected by data theft, espionage, or sabotage in the past twelve months, with total damages estimated at €289.2 billion.

What does this look like for a small business, in practice?
Say a small design studio gets hit by ransomware after someone opens the wrong email attachment. The shared drive is locked, client files are inaccessible, and work grinds to a halt.
Without cyber cover, the studio pays for all of it directly: the IT specialists to investigate and recover the systems, any legal obligation to notify clients whose data may have been exposed, rebuilding lost files, and the income lost while nobody can work. With a cyber policy in place, most of those costs are handled as part of the claim.
This is why the product exists specifically for people running digital operations of any size: freelancers, agencies, online shops, medical and law practices, anyone handling client data or payments online. It's not just for large companies with IT departments.

What does cyber insurance actually cost in Germany?
Less than most people expect. Small businesses and solo freelancers in Germany typically pay from the low hundreds to a few thousand euros per year, depending on your revenue, sector, and existing IT security (professional services and healthcare sit at the higher end because of the data they handle).
For scale: insurers usually quote well under 1% of yearly revenue, while a single cyberattack tends to cost a small business tens of thousands of euros in downtime, recovery, and legal costs. The maths usually favours having a policy.

Who actually needs this?
Short answer: anyone who handles client data, takes payments online, or would lose real money if their systems went down for a few days. That covers a lot more people than you'd think:
- Freelancers and consultants working with client data or contracts
- Online shops and anyone taking digital payments
- Agencies, studios, and small teams relying on cloud tools
- Medical and legal practices (higher regulatory exposure under GDPR)
- Any GmbH or UG with a website, email system, or customer database
If none of that applies to you, for instance if you're a purely offline trade with no digital customer data, the case is weaker. But for most modern businesses in Germany, including most one-person operations, this now sits alongside liability and legal insurance as a baseline consideration rather than a nice-to-have. If you want the wider picture of what protects a company here, our business insurance category page lays out how the pieces fit together.
Don't I already have this covered under business liability insurance?
This is one of the most common mix-ups, and an understandable one. Business liability insurance (Betriebshaftpflicht) covers damage your business causes to third parties, injury, property damage, that kind of thing. It generally does not cover data breaches, ransomware, or the cost of restoring your own systems after an attack. Some liability policies now offer limited cyber add-ons, but they tend to be much narrower than a standalone cyber policy, particularly when it comes to business interruption and your own recovery costs.
The two products are complementary, not interchangeable. If you're weighing up your coverage, it's worth looking at them side by side rather than assuming one covers the other.
Cyber incidents also frequently turn into legal disputes, with regulators, with affected customers, sometimes with vendors. Business legal expenses insurance can help cover the legal costs of defending your business through that process, which is worth keeping in mind alongside your cyber policy rather than as a separate, unrelated decision.

What happens if I get breached and I'm not insured?
Under the GDPR, any business handling personal data has a legal duty to notify the relevant supervisory authority within 72 hours of becoming aware of a data breach that risks affecting individuals' rights or freedoms, and to notify the affected individuals directly if the risk is high. Missing that window, or handling it badly, is treated as an aggravating factor if the case escalates.
Without insurance, all of that, forensic investigation, legal advice, notification logistics, potential fines, falls on you directly, on top of whatever it costs to actually recover your systems and data. That's the real value of a cyber policy: it's not just about the ransom or the hack itself, it's about having someone in your corner for the weeks of cleanup that follow.

How do I choose the right policy?
A few things worth checking before you sign anything:
- What triggers a claim? Some policies distinguish between malicious attacks and simple system failures, make sure both are covered if that matters to you.
- What's the coverage limit, and does it match your actual exposure? A five-person consultancy and a fifty-person online retailer have very different risk profiles.
- What security measures does the insurer require? Policies assume a baseline of IT hygiene (current software, backups, and so on), and under German insurance law an insurer can reduce or refuse a payout if you caused the incident through gross negligence ("grobe Fahrlässigkeit"). Know what you're committing to maintain.
- Is business interruption included, or is it an add-on? For many small businesses, lost income during downtime is the biggest real-world cost, not the ransom itself.
- How does the insurer handle the claims process? Some German insurers now bundle in incident response support (IT forensics, legal, PR) as part of the policy itself, which can be far more useful in the moment than a payout alone.
Given how much variation there is between providers on all of the above, this is exactly the kind of decision where a broker who can compare cyber security insurance policies side by side, rather than relying on the pitch from a single insurer, tends to save people from expensive gaps in coverage. If you'd rather not wade through the fine print alone, get in touch and we can walk you through it.

Frequently asked questions
Is cyber insurance mandatory in Germany?
No, it's not a legal requirement for most businesses. What has changed is regulatory pressure around it: NIS2 requires certain companies to register with the BSI and maintain cybersecurity measures, and GDPR obligations around data breaches apply regardless of whether you're insured. Cyber insurance itself remains voluntary, but an increasingly common part of standard business protection.
Does cyber insurance cover ransom payments?
Many policies include cover for ransomware-related costs, including, in some cases, ransom payments themselves, though this varies by insurer and by policy, and is subject to legal restrictions (paying certain sanctioned groups is illegal regardless of insurance). It's worth checking this specifically rather than assuming it's included.
I'm a freelancer working from home. Do I really need this?
If you handle client data, contracts, or payments digitally, yes, it's worth at least getting a quote. Premiums for solo freelancers and very small businesses tend to be modest, and the exposure, a locked laptop with a client's confidential files on it, is very real even at a one-person scale.
How is this different from my household or private liability insurance?
Private liability insurance covers damage you cause in your personal life. It doesn't extend to business data, client information, or commercial systems, even if you work from your home office. Business cyber cover is a separate, dedicated product.
What information will an insurer ask for before offering a policy?
Typically your revenue, industry, number of employees, what kind of data you handle, and details of your existing IT security setup (backups, antivirus, password policies, and so on). Being upfront here matters, since misrepresenting your setup at application stage is one of the more common reasons claims get disputed later.
Does having cyber insurance mean I can skip basic IT security?
No, and insurers will generally check. Coverage assumes a baseline level of security hygiene is already in place. Think of the policy as the safety net under the security measures you're already taking, not a replacement for them.
What's next?
Cyber insurance might not feel as urgent as health or liability cover, right up until the day it is. Between rising attack numbers, tightening regulation under NIS2, and the simple fact that most German businesses now run at least partly online, it's worth at least a conversation about where your business actually stands.
If you want to talk through whether cyber insurance makes sense for your business, or how it fits alongside liability, legal, or D&O cover you might already have, get in touch with us. We help expats and business owners in Germany cut through exactly this kind of decision, with clear, independent advice in English.

Contact our cyber insurance expert!
Daniel Weiss
Email: daniel.weiss@versicherungsbuero-weiss.com
Telefon: +49 30-40 36 31 95 1
Mobil: +49 178-140 584 0

