Independent
- Several providers compared
- Advice follows your situation
- AFM licence 12016589
With cyber insurance, the part used most often is not the payout but the telephone line: an incident response team that starts containing the damage, carrying out forensic investigation and restoring systems within a few hours.
This page in another language: Nederlands
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
The cover falls into three parts. Own damage: rebuilding systems and data, the business interruption while you are down, and the costs of investigation and communication. Liability: claims from customers, patients or suppliers whose data has leaked from your systems. And the assistance: forensic IT investigation, legal assistance and press handling, from the moment you report the incident.
The GDPR turns this into an obligation with a clock attached. In principle a data breach must be reported to the Autoriteit Persoonsgegevens (the Dutch data protection authority) within 72 hours, and the people concerned must be informed where the breach poses a high risk to them. In many incidents the costs of that notification process and of informing your customer base make up the largest part of the bill.
When comparing policies, look at the waiting period for business interruption, at whether an outage at your hosting provider also counts, and at the requirements the insurer sets for your security. Background information is on our page about cyber insurance.
We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.
Cyber insurance
Compare
Get coveredThe structure of the cover in three parts, with an overview per situation below.
We are not tied to any single company.
From assessment to policy.
What really matters.
What is covered
| What we look at | Explanation |
|---|---|
| Does the cover suit your activities | Yes |
| Sum insured and excess | Yes |
| Exclusions and clauses | Yes |
| Fit with your other policies | Yes |
| Premium in relation to the conditions | Yes |
| Comparing on premium alone | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Insurers weigh these details differently. That is where your saving is.
We look at the terms as well as the premium, and stay your point of contact when there is a claim.
We are not tied to one insurer and compare on the basis of an objective analysis of several companies.
You call or email someone who knows your file. No menu options, no changing call centres.
We cancel your old policy and align the start date, so you are never a day without cover.
We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
Four points that make the difference between a policy that pays out and one that does not.
With ransomware the question is not only whether you pay, but how quickly infected systems are taken off the network and whether your back-ups have been encrypted as well. The incident responsecover gives you immediate access to specialists who direct that work. If you first call your own IT provider and only contact the insurer days later, evidence has often already been destroyed and cover for investigation and recovery may come under pressure.
The business interruption module compensates lost gross profit while you are down, but only starts running after a waiting period expressed in hours. If your webshop is down for half a day and the waiting period is longer, there is no payout. This is the point on which quotes differ most. A classic business interruption insurance does not pay out here, because there is no physical damage.
Insurers now include firm requirements: multi-factor authentication on remote access, offline or immutable back-ups, security updates installed on time, and controlled administrator rights. If you do not meet these at the time of an incident, the payout may be reduced or refused. We go through those clauses with your IT manager before you take out the policy, so that you do not discover you fell short at the moment you have to report a claim.
Excluded are the costs of improving your systems beyond their previous level, replacing outdated hardware, and damage caused by known but unremedied vulnerabilities. Fines imposed by regulators are insurable only in so far as the law allows. War, attacks by state actors, loss of turnover through long-term reputational damage and errors in software you supply yourself also fall outside the policy.
This is what people ask us most.
Some policies allow it, always with prior consent and within the limits of sanctions legislation. In reality the incident response team first works towards recovery from back-ups, because paying is no guarantee that the keys will work. More important than this question is whether your back-ups are kept separate from the network, because that determines whether paying arises at all.
No. That policy requires covered physical damage to your own property as the trigger, such as fire or burglary. In a ransomware attack nothing is physically broken: the hardware works, the data is unusable. That is why classic business interruption cover does not pay out and the interruption module of a cyber policy is the only route to compensation for that lost turnover.
Yes, because towards your customers and the Autoriteit Persoonsgegevens you remain answerable as the data controller, even if the breach arose at your supplier. Recovering your loss from that party runs through the data processing agreement and the limitation of liability in it, which often takes years. In the meantime the cyber policy pays for the notification, the communication and the interruption on your side.
That is the most common scenario and it is covered in principle: human error is exactly what this cover exists for. The position is different with invoice fraud, where an employee makes a payment after receiving a forged email. That form falls under a separate module for social engineering, with its own limit and often a requirement for two-person authorisation on changes to bank details.
Every situation is different. For these situations we have a separate page.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was compiled by Finass Verzekert (LinkedIn). Last updated on .
The information on this page is general in nature and is not personal advice.
Maandag- Vrijdag: 09:00- 17:00
We use cookies and similar technologies to improve your experience on our website.