Industries in Focus

Cybercrime as a business risk: What entrepreneurs need to know now

Cybercrime as a business risk: What entrepreneurs need to know now

Cybercrime as a business risk: What entrepreneurs need to know now

Last updated:

8 min.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

From the research findings of Dr. iur. Dr. rer. pol. Fabian Teichmann.

The digital transformation has fundamentally changed the economy – and with it the risk profile of every company. Ransomware attacks paralyze clinics, deepfakes prompt financial departments to make million-dollar transfers, and cyberattacks can drive entire businesses into insolvency. What sounds like a dystopian future scenario has long been a bitter reality for entrepreneurs.

Dr. Fabian Teichmann, an attorney and IT forensic expert based in Switzerland, has conducted extensive research in recent years: More than a hundred scientific articles, several monographs, and numerous contributions in leading specialist journals paint a precise, evidence-based picture of the threat landscape – and provide entrepreneurs with concrete answers to the question of what to do legally, organizationally, and technically. This article summarizes the central findings from this body of research.

1. The New Quality of the Threat: Ransomware as a Corporate Risk

Today, ransomware is no longer a marginal technical problem – it is an organized business model of criminal networks. Teichmann describes this development precisely in several articles: Highly professional cybercriminal groups operate with a division of labor and are industrially organized. So-called Initial Access Brokers first gain access to networks, sell this access on the darknet, and only then does a ransomware operator encrypt the data. Increasingly, this involves Double Extortion: Prior to encryption, the perpetrators exfiltrate confidential data and additionally threaten to publish it (Teichmann, Ransomware-Erpressung: Umgang, Rechtsfragen und Cyberversicherung, ZBJV 2025, pp. 553–578).

Particularly unsettling: No company is "too small" or professionally "uninteresting" for ransomware extortionists. The choice of target is often opportunistic – attackers scan broadly for vulnerable systems. Professional perpetrators calculate the amount of the ransom so that it is just below the expected costs of data recovery, which increases the incentive to pay (Teichmann, ZBJV 2025, pp. 553–578).

The dimension of damage is enormous. Teichmann documents the 2024 Change Healthcare attack, in which 6 terabytes of sensitive patient data were stolen and the impact affected around 100 million people (Teichmann, Ransomware-Bedrohung im Gesundheitswesen, Compliance Berater 2025, pp. 227–233). In Europe, an attack on a London diagnostics provider in 2023 showed that thousands of surgeries had to be canceled and emergency patients redirected – impressive proof that ransomware attacks can directly endanger lives (Teichmann, Compliance Berater 2025, pp. 227–233).

Medium-sized companies have also long been affected. Teichmann analyzes the Fasana case (2025), where a cyberattack led directly to the insolvency of a company, as an exemplary wake-up call for medium-sized enterprises (Teichmann, Cyberangriff als Insolvenzauslöser: Der Fall Fasana als Weckruf, ZRI 2026, pp. 6–13; id., Vom Cyberangriff in die Insolvenz – Der Fall Fasana (2025) und Lehren für den Mittelstand, InTeR 2025, pp. 167–171).

2. When Artificial Intelligence Becomes a Weapon: Deepfakes and CEO Fraud

In addition to ransomware, Teichmann’s research identifies a second, even more unsettling threat dimension: the use of generative artificial intelligence for fraud schemes.

In early 2024, a finance employee in Hong Kong transferred 25 million US dollars to fraudsters after being instructed on a video conference by alleged superiors. What she did not suspect: Neither the CFO nor the colleagues were actually connected – criminals had simulated their appearance and voice via deepfake (Teichmann, KI-gestützte Betrugsmaschen – Deepfakes als neue Herausforderung für Fraud Detection, Jusletter, June 30, 2025).

These incidents are not isolated cases. Teichmann refers to forecasts according to which fraud losses due to generative AI in the US alone could grow from 12.3 billion to 40 billion US dollars by 2027 – an annual growth rate of more than 30 percent. Deepfake incidents in the fintech sector increased by 700 percent in 2023 (Teichmann, Jusletter, June 30, 2025).

The insidious part: Deepfakes do not need to be perfect to deceive effectively. Psychologically, human tendency to trust what they see or hear acts as an amplifier. Even if subtle inconsistencies exist, context and the natural willingness to trust can mask remaining doubts (Teichmann, Jusletter, June 30, 2025). This has direct practical consequences: The standard principle "call the supervisor back in case of doubt" fails if telephone identification via voice cloning can also be bypassed.

In another experimental article, Teichmann also directly investigates the use of generative AI in the context of CEO fraud (Teichmann, CEO Fraud im Kontext (generativer) künstlicher Intelligenz – Eine experimentelle Untersuchung, ZWH 2024, pp. 1–8). The result: Classic control mechanisms such as the four-eyes principle fail when the visual and acoustic authenticity of the deceiving person is perfectly simulated.

3. The Legal Dimension: Liability of Company Directors Today

A central theme in Teichmann’s research is the personal liability of company leaders in cyber incidents. This is not an academic problem – it has immediate practical relevance for every managing director and board member.

NIS-2 Directive and its Consequences for Corporate Management

The EU NIS-2 Directive (EU 2022/2555), implemented in Germany through the NIS-2 Implementation Act (NIS2UmsuCG), requires corporate management not only to ensure appropriate technical measures but also to actively participate in training. Teichmann analyzes this duty in detail in several articles: Management boards must know and actively manage cybersecurity risks – ignorance does not protect against liability (Teichmann, NIS2-Schulungspflicht der Geschäftsleitung, Computer und Recht 2025, pp. 718–725; id., Strafbare Non-Compliance: Persönliche Haftung von Geschäftsleitern und Organen bei Verstößen gegen die NIS2-Richtlinie, CyberStR 2026, pp. 65–73).

Particularly far-reaching: For essential entities, violations of NIS-2 duties can be punished with fines of up to 10 million euros or 2 percent of global annual turnover. Some national implementation laws also make it possible to temporarily suspend management from their functions (Teichmann, Auswirkungen der EU-NIS-2-Richtlinie auf Unternehmen, ZWH 2026, pp. 6–11).

Cyber Crisis and Insolvency: An Underrated Connection

Teichmann uncovers a risk connection that is still barely noticed in practice: the connection between a cyberattack and the obligation to file for insolvency. If a ransomware attack leads to or threatens a company's insolvency, the insolvency law obligations of Section 15a InsO apply. Incapacitated or hesitant managing directors risk not only civil liability but also criminal consequences (Teichmann, Cyberbedingte Insolvenzreife und § 15a InsO: Zur straf- und haftungsrechtlichen Verantwortlichkeit der Geschäftsführung, ZInsO 2025, pp. 2193–2207; id., Cyberkrise und Insolvenzverschleppung – Strafrechtliche Risiken bei verspäteter Reaktion auf Ransomware-Angriffe, ZRI 2025, pp. 877–884).

The preventive approach of the NIS-2 regime targets precisely this issue: It obliges companies to identify and manage cyber risks before they become existential threats (Teichmann, Cyberrisiken und Insolvenzgefahr: Präventive Schutzpflichten des NIS2-Regimes, InsA 2026, pp. 3–10).

D&O Liability: When Cybercrime Hits Directors Personally

Teichmann analyzes the rising D&O (Directors & Officers) liability as an interdisciplinary consequence of cybercrime, regulation, and AI. Directors and officers who neglect basic IT security duties are increasingly held personally liable – both to the company and to third parties (Teichmann, Steigende D&O-Haftungsrisiken durch Cyberkriminalität, Regulierung und KI, Compliance Berater 2026, pp. 117–122).

4. The Cyber Resilience Act: Cybersecurity Becomes a Product Obligation

One of the most significant developments in European law is the Cyber Resilience Act (CRA), which was adopted in October 2024 and will apply bindingly to new products from December 11, 2027. Teichmann has analyzed this legal act comprehensively.

The CRA marks a paradigm shift: Cybersecurity is elevated – comparable to electrical safety – to a mandatory product property (Teichmann, Cybersicherheit als Produkteigenschaft – Der Cyber Resilience Act der Europäischen Union, NJW 2025, pp. 2577–2582). What does this mean for companies?

Manufacturers of connected products – whether smart home devices, industrial control systems, or software – must in the future:

  • Minimize security gaps at market launch (no known unpatched vulnerabilities upon delivery)

  • Implement secure default settings (no default passwords)

  • Provide security updates for at least five years

  • Create a Software Bill of Materials (SBOM) – a list of all software components used

  • Report security incidents within 24 hours

(Teichmann, NJW 2025, pp. 2577–2582; id., Der EU Cyber Resilience Act – Anforderungen aus strafrechtlicher, Compliance-, produktsicherheitsrechtlicher und Governance-Perspektive, RIW 2025, pp. 777–785)

Also, companies using connected products must understand the implications. The obligation of supply chain diligence means: Whoever integrates unsafe third-party components is liable. Teichmann emphasizes that even seemingly simple components must not be neglected, as attackers often exploit chains of vulnerabilities to access large systems through small entry points (Teichmann, The EU Cyber Resilience Act: Hybrid governance, compliance, and cybersecurity regulation in the digital ecosystem, Computer Law & Security Review 2025, p. 106209).

5. Critical Infrastructure: When a Cyberattack Becomes a Public Threat

Teichmann’s research focuses intensively on the special vulnerability of critical infrastructures – hospitals, energy suppliers, municipalities, financial institutions – and the legal consequences for their operators.

Healthcare Sector

Ransomware attacks on clinics are not only economically devastating but can be directly life-threatening. In 2020, Düsseldorf University Hospital had to temporarily suspend emergency care after a ransomware attack; the prosecution office investigated proceedings for negligent homicide (Teichmann, Ransomware-Angriffe auf Krankenhäuser – Strafrechtliche, Medizinrechtliche und Datenschutzrechtliche Herausforderungen, Zeitschrift für Lebensrecht 2025, pp. 349–366).

Teichmann also analyzes criminal law duties regarding IT security in hospitals under the IT Security Act 2.0, KRITIS Umbrella Act, and Section 391 SGB V (Teichmann, IT-Sicherheit im Krankenhaus – Neue Pflichten durch IT-SiG 2.0, KRITIS-Dachgesetz und § 391 SGB V, MedR 2025, pp. 959–968). The central message: IT security is a C-level priority – hospital managements cannot hide behind technical complexity.

Energy and Municipalities

Renewable energy plants are also increasingly becoming the target of attacks. Teichmann examines the specific cyber risks for wind farms, solar plants, and other infrastructures and develops regulatory options (Teichmann, Cyberangriffe auf Erneuerbare-Energien-Anlagen – Risikoanalyse und Regulierungsoptionen, REE 2025, pp. 143–150). For municipal utilities and energy providers, he analyzes the impact of the NIS-2 Directive, also for small and medium-sized enterprises, many of which have not yet implemented sufficient protective measures (Teichmann, NIS-2 und die Anwendung auf kleine und mittlere Stadtwerke, EnWZ 2025, pp. 400–407).

Municipal administrations face unique challenges: heterogeneous IT landscapes, legacy systems, chronic shortage of skilled staff. Teichmann points out that cyber risks are often perceived as isolated individual problems there, even though structural governance deficits are the real vulnerability (Teichmann, Cyberangriffe auf kommunale IT-Infrastrukturen, CyberStR 2025, pp. 23–32; id., Cybersicherheit in Kommunen – Regelungsdefizite und Reformbedarf, ZRP 2025, pp. 184–187).

Financial Sector

In the financial sector, Teichmann analyzes the Digital Operational Resilience Act (DORA), which mandates uniform, EU-wide IT security rules for financial institutions since January 2025. DORA goes beyond classic cybersecurity parameters: It requires ICT risk management, resilience testing, third-party monitoring, and clear governance responsibility up to board level (Teichmann, Digital Operational Resilience Act (DORA) – EU-weit einheitliche IT-Sicherheitsregeln für Finanzinstitute, BB 2025, pp. 2760–2770; id., DORA – Teil 3: Governance-Verantwortung und Compliance-Risiken, ZRFC 2025, pp. 279–283).

6. Whistleblowing, Compliance, and Corporate Culture

Teichmann’s research on compliance and whistleblowing offers entrepreneurs important guidance for designing their internal structures.

The Whistleblower Protection Act (HinSchG), which came into force in 2023, presents companies with new organizational and legal challenges. Teichmann analyzes not only the protective duties for whistleblowers but also the potential for misuse: Generative AI could be used to produce fictitious tips on a large scale and overload compliance systems (Teichmann, Das Hinweisgeberschutzgesetz im Kontext generativer künstlicher Intelligenz, NZWiSt 2023, pp. 289–296).

Also significant is his analysis of the reversal of the burden of proof under Section 36 HinSchG: In dismissal protection proceedings, the employer must prove that a dismissal was not linked to a report. This has major practical consequences for personnel decisions made after internal tips are received (Teichmann, Beweislastumkehr des § 36 HinSchG im Kündigungsschutzverfahren und ihr Konflikt mit Verschwiegenheitspflichten, ZIP 2025, pp. 2477–2482).

On the topic of compliance incentives – how can companies promote internal compliance cultures? – Teichmann has presented extensive research showing that financial incentives alone are not enough: The social and psychological reality of the environment crucially shapes the perception of compliance rules (Teichmann & Wittmann, Psychology and White Collar Crime – Compliance Recommendations Based on the Social and Psychological Reality Dictating Perception, Journal of Financial Crime 2024, pp. 408–415).

7. Concrete Recommendations for Entrepreneurs

From the synopsis of Teichmann’s research works, the following practice-relevant conclusions can be drawn for entrepreneurs:

Immediate Action Required

Make cybersecurity a priority for top management. The NIS-2 Directive requires company leaders to actively engage in cybersecurity topics – including personal training. This is not a recommendation, but a legal obligation with liability consequences (Teichmann, Cybersicherheit als Führungsaufgabe: Die BSI-Handreichung zur NIS-2-Schulungspflicht, BB 2026, pp. 74–77).

Implement Incident Response Plans. A ransomware attack is not a question of if, but when. Companies that do not have emergency plans will be forced to make improvised decisions under maximum pressure in an emergency – with corresponding liability risks (Teichmann & Boticiu, The Importance of Cybersecurity Incident Response Plans for Law Firms, Jusletter, April 3, 2023).

Know and comply with reporting obligations. Under NIS-2, a 24-hour reporting obligation applies to significant cyber incidents and must be submitted to the competent authority. Those who report too late risk heavy fines (Teichmann, Die neue 24-Stunden-Meldepflicht für Cyberangriffe nach ISG, Jusletter, September 29, 2025).

Medium-term Measures

Review supply chain security. Cyberattacks increasingly occur through third-party providers and suppliers. Companies are liable not only for their own IT security failures but also for vulnerabilities in integrated external components (Teichmann, IT-Sicherheit in der Lieferkette, Der Betriebswirt 2024, pp. 251–265).

Establish deepfake prevention. Classic authentication methods are no longer sufficient. Companies need technical and organizational measures that work even in persuasive deepfake scenarios – such as predefined code words for unusual transfer requests or a four-eyes principle with independent callbacks via known numbers (Teichmann, Deepfake-Imitation und Betrug durch KI-generierte Medien, Kriminalistik 2026, pp. 194–200).

Critically check cyber insurance. Cyber insurance can be useful – but only if the coverage conditions match actual risks and, in particular, compliance violations do not lead to non-performance (Teichmann, ZBJV 2025, pp. 553–578).

Strategic Perspective

Anticipate regulatory developments. The Cyber Resilience Act will enter into force in 2027 – those who start implementing the requirements now will avoid last-minute resource conflicts (Teichmann, The cyber resilience act as a new paradigm for product security: a compliance roadmap, International Cybersecurity Law Review 2025, pp. 1–17).

Understand compliance as a competitive advantage. Companies that can prove they maintain high cybersecurity standards enjoy advantages in acquiring customers, in insurance, and in public tenders. Compliance is not just a question of costs, but a strategic asset (Teichmann & Wittmann, Compliance Cultures and the Role of Financial Incentives, Journal of Financial Crime 2024, pp. 226–232).

Conclusion: Cybersecurity is a Priority for Management – Scientifically Proven

The research works of Dr. Fabian Teichmann paint a consistent picture: The threat of cybercrime is not an abstract danger for others, but a concrete, growing risk for every single business. At the same time, legislators have reacted – with NIS-2, DORA, the Cyber Resilience Act, and national implementation laws that put personal liability on corporate management.

What makes Teichmann’s research particularly valuable: It combines legal-technical analysis with the empirical reality of real attack cases. Deepfakes worth 25 million US dollars, ransomware-induced insolvencies, hospitals without emergency services – these are not future scenarios, but documented present realities.

For entrepreneurs, this means: Those who know the regulatory duties, understand the threat landscape, and act preventively can not only minimize liability risks, but can also turn cybersecurity into a real competitive advantage. The scientific scientific foundation for this is available.

All source references in this article refer to published scientific contributions by Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann. The complete bibliography is documented in his publication directory (status May 2026).

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

We use cookies to improve your experience. By continuing, you agree to our cookie policy.