Corporate Governance 2025

GERMANY Trends and Developments Contributed by: Stephan Waldhausen, Moritz Pellmann, Justus Anacker and Cristina Hajek Gross, Freshfields

ing), high-risk, limited and minimal risk systems. High-risk systems, which are common in enter - prise environments, are subject to stringent obligations concerning transparency, data gov - ernance, and human oversight. Limited-risk sys - tems must meet standards for explainability and user awareness, while minimal risk systems are largely exempt from regulatory obligations. The board must ensure that the applicable regulatory obligations are embedded into the organisation’s governance architecture and are complied with. Data and Cybersecurity Risks In the digital economy, data serves as both a strategic asset and a critical point of vulnerabil - ity. As digital integration deepens, cybersecu - rity has become a top governance priority for companies. Increased interconnectivity exposes firms to threats such as data breaches, ransom - ware, industrial espionage, and hybrid attacks on critical infrastructure. Cyber threats surged in 2024, with Distributed Denial of Service (DDoS) attacks on European businesses – designed to overload systems with excessive traffic, disrupting normal operations – more than doubling. In Germany, 9% of compa - nies reported incidents of industrial espionage, most involving sophisticated hacker activity. Reflecting the growing urgency, the President of BaFin ( Bundesanstalt für Finanzdienstleistung- saufsicht ), Germany’s Federal Financial Super - visory Authority, issued a public warning in Janu - ary 2025, highlighting the escalating cyber risk facing financial institutions and insurers. The EU has implemented an enhanced regu - latory framework in response. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive) expands obligations across 18 critical sectors, introducing stricter reporting duties and

direct board accountability. Germany has yet to transpose the NIS2 Directive, after the February 2025 elections prevented the passing of a pro - posed draft implementation act. In parallel, Regulation (EU) 2022/2554 on digi - tal operational resilience for the financial sec - tor (Digital Operational Resilience Act; DORA) entered into force on 17 January 2025. It impos - es binding cybersecurity and resilience require - ments on financial entities and information and communication technology (ICT) providers. Together with the GDPR, the NIS2 Directive and the DORA form the EU’s digital risk governance regime. Cybersecurity is no longer a solely technical issue. Under the German Stock Corporation Act ( Aktiengesetz , AktG), the board is legally obliged to implement systems that detect and mitigate security risks, including cyber threats. The board, therefore, needs to implement gov - ernance structures suited to a digitalised envi - ronment. Boards should ensure that they: • enhance IT literacy among their members to ensure informed oversight of digital risks; • integrate redundancy and backup protocols to maintain operational continuity; • implement and test incident response plans to ensure preparedness; • foster co-ordination between IT, legal, com - pliance, and risk functions for a unified response. Cybersecurity must be a standing agenda item for boards, with regular updates, sustained investment, and clear accountability. Inaction risks serious legal, financial, and reputational consequences. And, again, boards must estab - lish clear responsibilities for both management and supervisory levels.

321 CHAMBERS.COM

Powered by