The rapid increase in cyberattacks in recent years has sharply highlighted the issue of legal liability of organizations and individuals involved either as victims or, in some cases, as responsible for the inadequate protection of their systems. Cybersecurity is no longer just a technical or organizational issue; it has become a key issue of legal compliance and accountability, especially when personal data, confidential information or the smooth operation of critical infrastructures are at risk.
See also: Minnesota activates National Guard after St. Paul cyberattack

In principle, an organization that is the victim of a cyberattack is not automatically considered legally liable for the damage caused. However, legal liability may arise if it is proven that there was negligence or failure to implement appropriate security measures, as defined by the relevant legislation. The most typical case is a personal data breach, as provided for in the General Data Protection Regulation (GDPR), which imposes specific obligations to protect information concerning identifiable natural persons.
The GDPR holds data controllers accountable not only for the security of the data they collect and process, but also for promptly notifying authorities and data subjects in the event of a breach. If an organization fails to take adequate technical and organizational measures, it can be subject to heavy administrative fines, up to 20 million euros or 4% of global annual turnover, whichever is higher.
See also: Banks: Cyberattacks and ways to protect yourself
In addition to regulatory compliance, civil liability issues also arise. A person or business that has suffered damage due to a cyberattack on a third party may be able to claim compensation if they can prove that the damage was caused by the negligence or omissions of the responsible party. In addition, in some cases, legal liabilities may also arise, especially if the cyberattack caused serious impacts on national security, public health or critical infrastructure.

Cyberattacks also raise third-party liability issues. For example, a supplier that failed to implement required security standards, leading to a breach of its customer’s data, could face legal claims. The same applies to cloud service providers or external partners who have access to critical systems. The contracts that govern these relationships are critical, as they define in advance the limits of liability, obligations and indemnification clauses.
Finally, it is important to note that the legal response to cyberattacks is constantly evolving. New regulations, such as the NIS2 , further strengthen the obligation of organizations to ensure a high level of cybersecurity and to effectively manage incidents. The degree of compliance with these requirements is now a critical factor in assessing legal liability.
See also: Qantas: Cyberattack led to data breach
In summary, legal liability in the event of a cyberattack depends on many factors: the nature and extent of the attack, the organization's proactive preparedness, compliance with legislation and contractual obligations, as well as the response after the incident. Organizations are now called upon to invest not only in technology, but also in legal prevention, policies and procedures that will protect them from the significant risks posed by the digital world.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
