Due to the General Data Protection Regulation (GDPR), companies are obliged to immediately report a cyberattack to the competent data protection authority to avert consequential damages from a data breach. Failure to comply with this legal obligation to report can have serious consequences. However, legal protection is also strongly recommended to assess the risk to your data correctly and to adapt preventive measures accordingly.
The German law firm Schlun & Elseven offers competent and committed legal advice to provide our clients with the support they need. As a multidisciplinary, technology-savvy legal services provider, we combine excellent legal expertise with technical know-how to offer our clients tailor-made innovative solutions, even in times of need. In the event of a cyberattack, we ensure – in cooperation with IT forensic experts – that evidence is carefully preserved. If you have been the victim of a cyberattack and would like personal legal advice, do not hesitate to contact us.
What are Exchange Servers?
With the Exchange servers, Microsoft offers its customers an e-mail, calendar, contact, scheduling and collaboration platform. By authenticating themselves to the Active Directory, the directory service of Microsoft Windows servers, hackers gain access to such sensitive company data as e-mails, address books and administrative access rights to the domain.
As a result, the German Federal Office for Information Security (BSI) was forced to declare the highest threat level “red” (“extremely critical”) for the Microsoft Exchange Server. Microsoft had already issued a report on 05.03.2021 about a severe new security vulnerability in its Exchange products. The reason for this was the attacks with which hackers of the Chinese “HAFNIUM Group” succeeded in authenticating themselves as Exchange servers at the Active Directory to gain access to private information of the companies. While such attacks were initially targeted at American authorities, research institutions and larger companies and served the purpose of data espionage, numerous German companies are now also affected.
How Does an Attack Affect the Servers?
The insidious thing about attacks is that they are hardly noticeable at first. Hackers enter the system via Outlook Web Access, ECP, ActiveSync or EWS interfaces. Once inside the system, blackmail Trojans are usually used, and the systems are encrypted. ECP is an administration interface, while ActiveSync is software for data synchronisation. The abbreviation EWS stands for “Exchange Web System”. The attacks are carried out through all the functions used by the Exchange servers, so it is difficult to determine when the system was compromised.
Prevention as the Best Protection
Even if one hundred per cent protection against attacks on the Outlook Exchange Server system cannot be guaranteed, several behavioural measures can significantly minimise the risk of attack. In addition to various technical precautions and regular workshops on IT security, legal protection is another preventive measure with which a company should prepare itself in the event of an attack.
The decisive factor for the efficiency of a security concept is that the legal assessment by a lawyer for IT law is not considered in isolation from the technical or structural circumstances of the company. The company must continually be assessed in its entirety. Therefore, it is advisable to use legal and strategic expertise even if no attack has occurred yet. Schlun und Elseven has developed a comprehensive consulting product for this purpose, which implies legal and technical preventive measures in cooperation with IT forensic experts. This interaction of the individual disciplines guarantees comprehensive legal protection in an emergency.
What to Do if an Attack has Already Taken Place?
Despite all security precautions, cyberattacks cannot be avoided entirely. To protect yourself legally and keep the damage as low as possible, it is, therefore, essential to act adequately in the event of an attack. It is important to act from a technical point of view. Your Exchange administrator should check the system as soon as possible. In addition, new updates should be installed to close any security gaps. Microsoft has provided a script for checking the system, which is available for download.
If your system is compromised, a reportable data protection incident, according to Article 33 of the General Data Protection Regulation (GDPR), has occurred. If this is the case, you are obliged to notify the competent authority within 72 hours. If there is also a personal data breach, an obligation to notify the data subjects may result from Art. 34 of the GDPR.
Exception to the Obligation to Notify
In exceptional cases, however, there may be an exception to the obligation to notify. This is when, after examining the individual case, no risk to the rights and freedoms of data subjects can be assumed (cf. Article 33 (1) of the GDPR). Any waiver of such notification should always be justified and adequately documented.m A notification obligation can also be waived if it was determined within the security audit of the system that there is no compromise. The exception to the notification obligation is justified by the fact that, in such a case, there is no risk to the rights and freedoms of the data subject. However, even in such a case, the controller must document the incident following Article 33 (5) of the GDPR.
Obligation to Report: What to Report
If a notification to the competent data protection authority is required, there are some content-related requirements to be observed:
According to Article 33 of the GDPR, an essential part of the notification is a description that is as precise as possible of the type of cyberattack or data breach and how many data records are affected. Furthermore, the company must provide an assessment of the consequences to be expected from this data breach.
The notification must also contain precise information on which measures have already been taken or will be taken by the data controller. The recommendations for action from Microsoft and the BSI are used as a benchmark.
It should be noted that failure to report such an incident may constitute a data protection violation and can be punished with high fines (up to 20 million euros or 4 per cent of the annual turnover).
As a multidisciplinary full-service law firm, we are happy to advise you on whether there is a reporting obligation for your company in the event of a cyberattack and how you can furthermore support the data protection authorities in prosecution. We work with experts in IT forensics who ensure that every data breach is documented accurately. With their comprehensive advice, our lawyers offer the best possible legal protection in the event of an attack.

Practice Group: Our German Criminal Defense Lawyers
Practice Group:
Our German Criminal Defense Lawyers
Contact Schlun & Elseven Rechtsanwälte
Please use our online form to outline your request to us. After receiving your request, we will make a brief initial assessment based on the facts described and provide you with a cost offer. You can then decide whether you would like to engage our services.







