Trier studies on Digital Law Volume 3 • Prof. Dr. Benjamin Raue (ed.)

Volatility, uncertainty, complexity and ambiguity characterise current global affairs. This has an impact on digital systems, which are becoming increasingly vulnerable to threats and disruptions. With the almost universal adoption of digital technologies, risks arising from malfunctions and data manipulation are on the rise. The result is ransomware and other cyberattacks. The aim is therefore to increase digital resilience. This brings with it technical and legal challenges, particularly regarding how security vulnerabilities can be closed and the overall security of software enhanced.

This volume addresses the following topics:

  • Security and security vulnerabilities
  • Contractual claims for security updates
  • State responsibility for secure software
  • The role of the BSI in combating security vulnerabilities
  • Enforcement of private claims for security updates
  • Compliance incentives through cyber insurance

(This publication is currently only available in German)

List of articles:

  • Introduction – Digital resilience: An effective right to secure software? | Benjamin Raue | p. 1
  • Contractual claims to security updates? | Thomas Riehm, Malte Leithäuser and Raphael Brenner | p. 5
  • State responsibility for secure software | Christian Ernst | p. 39
  • State exploitation of IT security vulnerabilities – Key features of state vulnerability management | Thomas Wischmeyer | p. 57
  • What powers does the BSI need to combat IT security vulnerabilities? | Steve Ritter | p. 79
  • Law with no chance of implementation? On the (collective) enforcement of private claims for security updates | Wiebke Voß | p. 97
  • Compliance incentives through cyber insurance: Obligations to prevent information security breaches | Christian Armbrüster | p. 115

DOI: 10.25353/ubtr-42d2-df9e-f813

Biographies:

Benjamin Raue
Professor of Civil Law, Information Society Law and Intellectual Property Law at the University of Trier, and Executive Director of the IRDT.

Christian Armbrüster
Professor of Civil Law, Commercial and Company Law, Private Insurance Law and Private International Law at Freie Universität Berlin.

Christian Ernst
Professor of Public Law and Business Law, including Public Procurement Law, Helmut Schmidt University, Hamburg.

Thomas Riehm
Professor of German and European Private Law, Civil Procedure Law and Legal Theory, University of Passau.

Malte Leithäuser
Research Assistant to Prof. Dr Thomas Riehm, University of Passau.

Raphael Brenner
Research assistant to Prof. Dr Thomas Riehm, University of Passau.

Steve Ritter
Head of the IT Security and Law Division, Federal Office for Information Security, Bonn.

Wiebke Voß
Assistant Professor of Civil Law, University of Würzburg.

Thomas Wischmeyer
Professor of Public Law and Digitalisation Law, Bielefeld University.