Breach Counsel

In the event of IT security incidents, quick, decisive, and well-thought-out action is crucial. Data leaks, ransomware attacks, and other cyberattacks can have far-reaching legal, financial, and reputational consequences for your company. A Breach Counsel is your reliable partner, supporting you in dealing with such incidents and ensuring you remain legally compliant.

What is a Breach Counsel?

A breach counsel is a specialized lawyer who assists companies during IT security or data protection incidents. In the event of a data leak, cyberattack, or other threat, the breach counsel helps respond quickly and with legal certainty. They help set up a crisis organization for making well-founded and legally compliant decisions swiftly. This includes communication with authorities (police, public prosecutor's office, and data protection authorities) and advice on legally compliant communication with customers, partners, and employees. During the crisis, the breach counsel supports decision-making in a way that can later be documented for insurers and other parties involved. Their role extends beyond handling the incident to assessing and mitigating damages and communicating with the insurance company. Additionally, the breach counsel advises on legal consequences, such as possible fines or claims for damages, and supports system recovery and security process optimization to prevent future incidents. They ensure companies act quickly in crisis situations while fully complying with legal requirements.

When is a Breach Counsel advantageous?

A breach counsel is particularly beneficial when a company is affected by a data protection incident or cyberattack. Their support enables a fast, targeted, and legally compliant response to security incidents from the beginning to the final settlement. A key benefit is the minimization of legal and financial risks, as the breach counsel ensures timely compliance with all legal and contractual reporting obligations, avoiding potential claims for damages or fines. They also protect the company's reputation by ensuring clear and coordinated communication with affected customers, authorities, and partners. The breach counsel not only helps manage the immediate impact of an incident but also contributes to long-term security strategy improvements, helping the company better prevent future incidents. This ensures business continuity and strengthens confidence in the company.

Our services as Breach Counsel

  • Incident Response
    We offer you reliable support in dealing with IT security incidents such as data leakage, hacking or ransomware attacks.
  • Risk assessment
    We analyze the incident to quickly identify and mitigate legal, financial and operational risks.
  • Reporting and obligations
    We support you in legally compliant reporting of incidents to data protection authorities and notifying data subjects.
  • Communication
    We advise you on transparent and strategic communication with customers, partners and the media.
  • Coordination with authorities and insurance companies
    We handle communication with data protection supervisory authorities to represent your interests and with insurers to ensure that your claims are settled correctly.
  • Follow-up
    We support you in implementing preventive measures to avoid future incidents.

Contact person

Dirk Koch

Dirk Koch

Attorney at Law | Partner

CEHv11 – Certified Ethical Hacker | Data Protection Risk Manager | CIPP/E

FAQ: Breach Counsel

First, the facts must be established: What happened, when was the incident discovered, which systems, data, information and business processes are affected, and whether personal data, trade secrets or other confidential information may be involved. In parallel, immediate measures must be initiated to contain the incident and preserve evidence, such as securing log files, restricting affected access and engaging IT forensics. It must be borne in mind that data protection reporting deadlines are very short and start running as soon as the incident becomes known. Only on this basis can it be reliably assessed which next steps are required, in particular internal escalation, crisis communications, restoration of operations and potential reporting and notification obligations under the GDPR, cybersecurity law or other applicable requirements.

Breach Counsel refers to specialised legal assistance provided to a company immediately after a data protection or security incident, in particular in relation to the legal assessment, reporting obligations and communication with authorities and data subjects. This assistance often also co-ordinates co-operation with forensic IT service providers, including the enforcement of claims against the insurer. The aim is to minimise legal, regulatory and reputational risks in an acute crisis situation while keeping operational disruption as low as possible.

No. From a legal perspective, dealing with an IT security incident often does not end with technical containment, restoration of the systems or compliance with any reporting obligations. Where cyber insurance exists, in particular, the costs incurred, the measures taken and the causal links must be prepared and evidenced in a comprehensible manner for the insurer. In practice, disputes frequently arise between insured parties and insurers, for example over whether individual measures were necessary, the amount of reimbursable costs or the scope of insurance cover. Data subject requests, claims for compensation under Article 82 GDPR and enquiries from supervisory authorities are also common. Early legal assistance is therefore useful to ensure from the outset that the documentation is prepared in a manner capable of withstanding scrutiny by the insurer and to enable claims to be pursued in a structured manner in the event of a dispute.

No. Whether an IT security incident must be reported depends on which reporting obligation applies. Under data protection law, a notification to the data protection supervisory authority under Article 33 GDPR is required only if a personal data breach is likely to result in a risk to the rights and freedoms of data subjects; the notification must be made without undue delay, if possible within 72 hours. Independently of this, certain companies may have reporting obligations to the BSI (German Federal Office for Information Security) if a significant security incident has occurred; these obligations do not arise directly from the NIS-2 Directive but from national implementing law, in particular the BSI Act as amended from time to time. Financial undertakings and certain ICT third-party service providers may also be subject to reporting obligations under DORA. The Cyber Resilience Act relates primarily to manufacturers and providers of products with digital elements and may trigger reporting obligations in the event of actively exploited vulnerabilities or serious security incidents; the staggered dates of application must also be taken into account here. Companies should therefore assess incidents separately under each regulatory regime and document the decision.

Data subjects must be informed under Article 34 GDPR if the incident is likely to result in a high risk to their rights and freedoms, for example where sensitive health or financial data have been disclosed. The notification must be made without undue delay and in clear, comprehensible language. Under certain conditions, notification may be dispensed with, for example where the data were effectively encrypted or subsequent measures have ensured that the high risk no longer exists.

Legal assistance helps assess the legal risks of a possible payment, for example in relation to criminal law, sanctions law and foreign trade law aspects where payments are made to certain recipients. It also supports the parallel fulfilment of reporting and documentation obligations that exist independently of any decision to pay. The question whether the payment decision was made and documented consistently with management’s duties of care should also be addressed with legal support. Communications with insurers, authorities and affected customers should likewise be co-ordinated from a legal perspective.