Technology alone cannot fend off an attack

MS

Maximilian Seidel

Cyber Risk Specialist, Insurance, Germany & Austria

NIS2 and the Cyber Resilience Act are significantly tightening the requirements for companies. As a result, cyber compliance is finally becoming a management responsibility.

In a conversation with Sompo experts René Ehlen, Björn Fehre, and Maximilian Seidel, it becomes clear why, in an emergency, governance, supply chain management, and well-rehearsed procedures are often more important than technology alone. 

In a cyber emergency, it quickly becomes apparent whether a company is prepared. Who takes the lead? Who makes the decisions? Who communicates? In many cases, these are precisely the questions that help determine the extent of the damage in the first few hours.

“Technology alone cannot fend off an attack,” says Björn Fehre, Head of Claims, Insurance, Germany & Austria at Sompo. His statement sums up what claims experience has shown for years: even well–equipped companies come under pressure when responsibilities are unclear, crisis procedures have not been rehearsed, or decision–making stalls under time pressure. 

“The first few hours are crucial,” says Fehre. Conversely, companies with comparable technical infrastructure often withstand an incident far more resiliently when organization, communication, and recovery plans are effective. 

With NIS2 and the Cyber Resilience Act, this reality is now also being reinforced by regulation. Cybersecurity is therefore finally being moved out of the IT corner and into the realm of management. 

Expert insight

In my view, the greatest need for action lies in governance, supply chain management, and accountability

René Ehlen

Head of Financial Lines, Insurance, Germany & Austria

In the past, many companies treated cyber risks primarily as an IT or information security issue. “Regulatory requirements no longer allow for that. Today, cybersecurity is a matter of corporate governance.” 

When cyber becomes a top priority 

For board members and CEOs, this means a clear shift in roles. It is no longer enough to approve budgets and delegate operational responsibility to specialized departments. What is required is a solid understanding of which critical processes are digitally dependent, where the key threats lie, and how resilient the company – including its service providers and supply chains – actually is. 

“It’s not about absolute security,” says Ehlen. “But it is about appropriate organization and a robust monitoring system.” 

This also brings personal responsibility more sharply into focus. Not every cyber incident automatically leads to liability. However, the threshold for what constitutes appropriate corporate organization is rising. The situation becomes particularly critical when known vulnerabilities remain unaddressed for extended periods, warning signs are ignored, or incidents are not managed effectively at the organizational level. 

Added to this is a risk area that many companies still underestimate: the supply chain. A company’s own attack surface does not end at its corporate boundaries. IT service providers, software vendors, external service providers, and OT partners are often deeply integrated into operational processes. 

Expert insight

When it comes to cybersecurity, many companies still focus heavily on internal measures. Less attention is often paid to dependencies, concentration risks, and the quality of suppliers and service providers.

René Ehlen

Head of Financial Lines, Insurance, Germany & Austria

It is precisely in a crisis that the critical nature of these dependencies becomes apparent: if an external service provider is compromised, or if a production site relies on external IT services, an IT incident can quickly turn into an operational crisis. 

Insurability begins before a loss occurs 

This has tangible consequences for the insurance industry. Today, cyber insurance is far more than just financial protection in an emergency. 

“That doesn’t go far enough,” says Ehlen. “Regulatory requirements today demand not only reaction but also prevention, resilience, governance, and verifiability.” 

Insurance can only function sustainably if risks are manageable to a certain extent. That is why Sompo is increasingly translating regulatory requirements into concrete underwriting criteria. 

At its core, it comes down to three questions: How likely is a loss? How severe could it be? And how well is the risk managed overall? 

Minimum technical controls – such as multi–factor authentication, patch management, and email security – remain important. But increasingly, it is the bigger picture that matters: Is cyber governance embedded at the executive level? Are robust incident response processes in place? Have recovery plans been tested? Is third–party management structured and verifiable? 

“The market is shifting away from sporadic checks of individual controls toward an assessment of the entire cyber governance model,” says Ehlen.

Where companies remain particularly vulnerable 

During risk assessments, Maximilian Seidel, Cyber Risk Specialist, Insurance, Continental Europe at Sompo, regularly identifies areas where vulnerabilities are particularly common in practice. 

He sees a need for action primarily in business continuity management and third–party risk management. 

“NIS2 requires more comprehensive risk management of suppliers,” says Seidel. While security requirements were often considered only in new contracts or during one–off audits in the past, today the focus is on continuous assessments and robust contractual standards. 

Vulnerability and patch management also remain key issues – precisely because the threat landscape is constantly evolving and artificial intelligence can further accelerate attacks. At the same time, many companies operate in IT and production environments that have evolved over time. The challenge, therefore, does not lie in an idealized “clean slate,” but in realistically hardening existing structures. 

Seidel also observes that companies with locations in Germany or the EU but headquarters abroad still sometimes underestimate the relevance of NIS2. 

In an emergency, it’s all about teamwork 

The extent to which organizational shortcomings affect a crisis is reflected in the resulting damage. 

“It’s rarely the technology that causes cyber resilience to fail,” says Fehre. “More often, a robust strategy is missing – or it exists only on paper.” 

The crucial questions in an incident are often surprisingly basic: Who convenes the crisis management team? Who decides whether to halt production? Who communicates with customers, authorities, IT forensic experts, or the insurer? Unclear responsibilities and inappropriate responses can further exacerbate the consequences of a cyberattack and significantly increase the damage. 

After all, a cyberattack is almost never just an IT issue. It also involves business interruption, regulatory deadlines, communication capabilities, liability issues, and reputational risks. 

For example, if a plant is shut down as a precaution because it is unclear whether systems can continue to operate securely, delivery deadlines are missed, and customers do not receive reliable information, a technical attack can turn into a company–wide crisis within hours. 

Just how stressful and protracted such situations can be for companies is evident time and again: after a severe attack, it often takes a long time for businesses to fully recover, both organizationally and operationally. 

This is precisely why response capabilities must be trained just as consistently as prevention. Fehre’s recommendation is accordingly clear: practice responding to incidents, test backups under realistic conditions, do not merely document incident response plans – know them inside and out – and identify external contacts in advance. 

Expert insight

Don’t just invest in prevention; invest at least as consistently in response capabilities

Björn Fehre

Head of Claims, Insurance, Germany & Austria

How Sompo integrates underwriting, risk engineering, and claims 

The key message is clear: cyber compliance is no longer just an IT department project. It is part of effective corporate governance. Any organization that wants to be regulatorily sound, insurable, and capable of taking action in an emergency needs more than good technology: clear responsibilities, robust processes, transparency around dependencies, and proof that all of this works even under pressure. 

Sompo relies on a model in which underwriting, risk engineering, and claims work closely together. Insights from real–world incidents feed back into risk assessment and prevention, while technical analyses help identify operational vulnerabilities at an early stage. 

Expert insight

As claims experts, we’re usually present right from the first meeting with the client, it’s important to us to be there in person and to bring our expertise into play right from the start of a partnership.

Björn Fehre

Head of Claims, Insurance, Germany & Austria

This close integration also matters in the event of a claim – from forensic analysis and legal advice to crisis communication. 

This brings us full circle: resilience does not arise in technical silos, nor does it emerge only once a loss has occurred. It arises where people, functions, and decisions interlock – both within the company itself and in collaboration with the insurer. 

 

First published by Handelsblatt