Industries in Focus

Cyberattacks and insolvency: When are directors personally liable?

Cyberattacks and insolvency: When are directors personally liable?

Cyberattacks and insolvency: When are directors personally liable?

Last updated:

8 min.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

Based on the research work of Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann

It is May 19, 2025, early in the morning. At the Fasana GmbH paper mill in Euskirchen, North Rhine-Westphalia, all network printers suddenly print the same document at the same time: a ransom note. All IT systems are encrypted. No computer is running, no digitally controlled machine is responsive, production is at a standstill. Within two weeks, sales losses of around two million euros occur. The May salaries of the 240 employees cannot be paid on time. On June 1, 2025 – less than two weeks after the attack – management files for insolvency.

The Fasana case is not an outlier. It is a foretaste of what Teichmann describes in several academic papers as one of the most pressing legal questions of our time: What happens to management when a ransomware attack drives the company into insolvency – and how quickly does a crime victim become a criminally accused individual?

The Fasana Case: A traditional company that stood no chance

Teichmann analyzes the Fasana case as a turning point in the perception of cyber risks in corporate law. Fasana, a paper industry company over 100 years old, had been taken over by a new investor only a few weeks before the attack and had no sufficient financial reserves to absorb such a shock (Teichmann, Cyberangriff als Insolvenzauslöser: Der Fall Fasana als Weckruf, ZRI 2026, pp. 6–13).

The scale of the devastation was immense. The provisional insolvency administrator reported that the company could not even print a delivery note after the attack. Around 190 PCs and laptops had to be forensically cleaned and reinstalled. Three weeks after the attack, the IT was still not fully restored; in individual departments, all employees worked on a single computer, while otherwise resorting to paper and pen (Teichmann, ZRI 2026, pp. 6–13).

Fasana is not an isolated case. Bicycle manufacturer Prophete had to file for insolvency at the end of 2022 after a cyberattack tipped its already tense situation. The Aachen-based precision machine manufacturer Schumag followed in autumn 2024. The list is growing (Teichmann, Vom Cyberangriff in die Insolvenz – Der Fall Fasana und Lehren für den Mittelstand, InTeR 2025, pp. 167–171).

The Underestimated Connection: Ransomware and Insolvency Law

What many managing directors do not know: A ransomware attack is not just an IT problem. Within days, it can trigger insolvency law obligations – with criminal consequences if these obligations are not met.

When a cyberattack paralyzes production, fixed costs continue to run: rent, wages, supplier liabilities. Without sales, liquidity quickly collapses. As soon as a company can no longer meet at least 90 percent of its due liabilities within three weeks, illiquidity within the meaning of § 17 InsO (Insolvency Statute) is present. At this moment, one of the strictest obligations under German corporate law takes effect: the obligation to file for insolvency under § 15a InsO (Teichmann, Cyberbedingte Insolvenzreife und § 15a InsO: Zur straf- und haftungsrechtlichen Verantwortlichkeit der Geschäftsführung, ZInsO 2025, pp. 2193–2207).

§ 15a InsO: The Deadline with No Exceptions

§ 15a InsO is uncompromising. In the event of illiquidity, the insolvency petition must be filed without culpable delay, at the latest within three weeks. In the event of over-indebtedness, the deadline is six weeks. These deadlines may only be fully exhausted if there is a realistic prospect of sustainable restructuring. If it is clear early on that no salvage route exists, immediate action must be taken.

A cyberattack as the cause of insolvency does absolutely nothing to change this obligation. The law does not distinguish between insolvency caused by management errors and one triggered by a criminal attack. The obligation to file is tied solely to the objective occurrence of illiquidity or over-indebtedness – regardless of who is responsible for it (Teichmann, Cyberkrise und Insolvenzverschleppung, ZRI 2025, pp. 877–884).

In plain terms, this means that a management team that hopes the IT systems will soon be restored after a ransomware attack and therefore waits to file for insolvency is taking a significant criminal risk.

The Punishment for Waiting Too Long

The criminal consequences of delaying insolvency filings are severe. Anyone who acts too late intentionally risks a prison sentence of up to three years or a fine. Anyone who acts negligently – meaning they should have recognized the state of insolvency but did not – still risks a prison sentence of up to one year or a fine (Teichmann, ZInsO 2025, pp. 2193–2207).

Crucially, this is an offense of omission: the wrongdoing lies in the failure to act within the deadline – not first in an active intervention. The obligation applies to all corporate executive body members, i.e., all managing directors of a GmbH or all board members of an AG, including those who factually – without a formal corporate position – exercise corporate management.

The Prohibition on Payments: Another Trap After Insolvency Maturity

In addition to the obligation to file, § 15b InsO standardizes a strict prohibition on payments from the moment of insolvency maturity. From this point onward, management may no longer make payments from corporate assets – unless they are absolutely necessary to prevent even greater damage.

What this means in practice: Anyone who still makes ransom payments to ransomware extortionists, pays supplier invoices, or transfers salaries after the onset of illiquidity can face criminal liability not only for delaying bankruptcy filings but also for bankruptcy-related crimes or favoring creditors. Good intentions do not protect against criminal liability (Teichmann, ZInsO 2025, pp. 2193–2207).

The Core Problem: Knowledge of Insolvency Maturity During IT System Failure

A particular challenge is the question: Can a management team exculpate itself by arguing that it could not have known about the occurrence of insolvency maturity due to the IT system failure?

The legal response is soberingly clear: No, not really. Although case law recognizes that a ransomware attack makes business data entry extremely difficult – accounting systems are encrypted, liquidity overviews cannot be retrieved – the management is nonetheless obligated to gain an overview by alternative means: through manual liquidity calculations, evaluation of bank account balances, estimation of ongoing costs, and retrieving open items from backups (Teichmann, ZRI 2025, pp. 877–884).

If the IT shutdown halts all sales and running costs can no longer be covered, management cannot simply hope for a quick technical solution without simultaneously reviewing insolvency maturity. Criminal courts assess the issue ex-post – based on objective figures. The good intention to save the business provides virtually no protection against investigations if the records show that the company was already illiquid (Teichmann, ZRI 2025, pp. 877–884).

Options for Exculpation: What Can Protect Managing Directors

Teichmann also examines what options for exculpation are available to business leaders during a cyber crisis.

The strongest exculpation is provided by obtaining professional external advice at an early stage. Anyone who, immediately after the attack, consults a lawyer specializing in insolvency law to assess and document the situation acts in accordance with their duties. If this consultant, after careful review, concludes that insolvency maturity has not yet occurred and that restructuring is realistic, management can rely on this expert opinion – provided that all essential facts were disclosed completely and truthfully.

A second option for exculpation lies in documentation. Anyone who keeps a complete record of all crisis management steps – what measures were taken and when, what information was available and when, what decisions were made for what reasons – establishes a basis on which, in case of doubt, it can be proven that they acted without negligence (Teichmann, ZRI 2025, pp. 877–884).

What does not protect: simply hoping for the restoration of IT. Anyone who simply waits after a cyberattack without systematically checking for insolvency maturity acts negligently.

Preventive Protective Duties: The NIS 2 Regime as an Early Warning System

Teichmann makes it clear that cyber risks in corporate law do not only become relevant once the attack has already occurred. The NIS 2 regime follows a preventive logic: it obliges companies to systematically identify and manage cyber risks before they become threat to existence (Teichmann, Cyberrisiken und Insolvenzgefahr: Präventive Schutzpflichten des NIS2-Regimes, InsA 2026, pp. 3–10).

This means: Anyone who takes the requirements of NIS 2 seriously – risk analyses, incident response plans, offline backups, network segmentation, regular training – protects not only the company from an attack but also themselves from criminal liability. Conversely, anyone who systematically cuts IT security budgets, leaves known vulnerabilities unpatched, and does not maintain emergency plans risks the accusation in an emergency that they contributed to the insolvency through grossly negligent neglect of their organizational duties.

The Corporate Law Dimension: Director's Liability Independent of Insolvency

In addition to criminal insolvency law, there is another dimension of liability: internal corporate liability of directors toward their own company.

§ 43 GmbHG and § 93 AktG oblige managing directors and board members to exercise the care of a prudent and diligent business manager. Today, this also includes appropriate IT security management. Anyone who has demonstrably acted with gross negligence – for example, by not setting up backups despite warnings, not installing necessary security updates, or ignoring available security standards – is personally liable to the company for the resulting damage (Teichmann, Steigende D&O-Haftungsrisiken durch Cyberkriminalität, Regulierung und KI, Compliance Berater 2026, pp. 117–122).

This claim can also be asserted by the insolvency administrator after the event – in the interest of the creditors. A managing director whose company has gone bankrupt after a cyberattack can therefore not only face criminal prosecution but also civil liability for the damage caused.

What Managing Directors and Board Members Should Specifically Do Today

Clear action recommendations can be derived from Teichmann's research.

First: Prepare for the worst-case scenario before it occurs. An emergency plan that defines which person will test for insolvency maturity from which point in time and which lawyer will be involved immediately belongs in every corporate organization today. This plan should exist in writing and be known – not just exist in people's minds.

Second: In an emergency, act immediately and in parallel. The IT crisis and potential insolvency maturity must be addressed simultaneously, not sequentially. While the IT team restores the systems, management must analyze the financial situation in parallel and consult an insolvency lawyer. Every day that passes without the insolvency issue being checked increases the criminal risk.

Third: Document everything. What measures were taken and when? What information was available and when? What decisions were made for what reasons? This documentation is the most important means of exculpation in the event of a dispute.

Fourth: Invest preventively in IT security. Anyone who has offline backups that are immediately ready for use after a ransomware attack has a completely different starting position than a company that loses all of its data. Segmenting systems limits the damage. These investments protect the company – and, in an emergency, also oneself (Teichmann, Cyberrisiken und Insolvenzgefahr, InsA 2026, pp. 3–10).

Conclusion: Being a victim does not shield you from punishment

The Fasana case bitterly shows that a company in Germany today can be driven from a profitable business into insolvency within two weeks – through a single criminal act that corporate management neither wanted nor caused.

Nevertheless, the law knows no exceptions for victims. The insolvency petition must be filed in a timely manner, regardless of why the illiquidity occurred. Anyone who waits too long because they are hoping for IT recovery risks personal prosecution.

The only effective response is prevention – technical, organizational, and legal preparation, long before the first ransom letter is printed.

All citations refer to published scientific contributions by Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann. The complete bibliography is documented in the list of publications (as of May 2026).

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

We use cookies to improve your experience. By continuing, you agree to our cookie policy.