Skip to main content
Laagste Prijs Garantie
Hoge Pakketkorting
Grootste Aanbod
Hulp bij Schade
Persoonlijk Contact
100% Onafhankelijk



Incident response · waiting period · application questions

Cyber insurance through Chubb

With a cyber policy you are mainly buying speed: a team that starts within a few hours. What that policy then pays out depends on the answers you gave on the application form months earlier.

  • Several insurers compared objectively
  • 9.5 customer rating for a new policy
  • AFM licence 12016589
  • Personal 072 - 509 24 56, weekdays 9–17

Deze pagina in het Nederlands: Cyberverzekering via Chubb.

The calculator and the quote form below are in Dutch. Prefer to do this in English? Email info@finassverzekert. nl or call 072 - 509 24 56 and we will take it from there.

Work out for yourself what it would cost.

  • We compare the offerings of several insurers
  • An adviser checks whether the cover suits your activities
  • We arrange the switch, including cancellation

Request a quote

A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.

In brief

Chubb is one of the parties with which Finass can place a cyber risk. We are not tied to this company and assess the offerings of more than thirty providers on their substance. The choice follows from your IT set-up and your dependence on systems. The rest of this insurer's business range is shown on the overview page. What a cyber policy arranges in essence is set out on the hub page cyber insurance.

Cyber cover falls into two halves. The damage to your own property covers forensic investigation, restoring or rebuilding data and systems, crisis communication, legal assistance with a report to the Autoriteit Persoonsgegevens (the Dutch data protection authority) and the loss of turnover caused by the interruption. The liability covers claims from customers and suppliers whose data has leaked or whose own process came to a halt. For employers and processors, the duty to report under Article 33 of the GDPR is the starting point: a data breach must be reported without undue delay and in principle within 72 hours, and that clock is running while you are still working out what has happened.

The part that is most often underestimated is the waiting period for business interruption. Unlike fire damage, it is measured in hours rather than days, and only after that period does compensation for lost turnover start to run. For a webshop or a manufacturer with a short lead time, the difference between a six-hour and a twelve-hour waiting period matters more than a difference in premium. Also compare the sub-limits: extortion, data recovery and fraudulent payments almost always have a lower limit than the main sum insured.

This page deals with one situation. The full overview is on Compare business cyber insurance.

Gewenste dekkingen
Verhuurde woningen / objecten
Object 1
Aanvullende objectgegevensOpen
Specifieke vastgoedvragen tonen we hier compact onder.
Vul dit in namens de VvE. Vragen die niet van toepassing zijn kun je overslaan.
Gewenste dekkingen
Straatnaam met huisnummerreeks, bijvoorbeeld Voorbeeldstraat 1 t/m 45.
Alle rechten samen: woningen, bedrijfsruimten, parkeerplaatsen en bergingen.
Staat in het taxatierapport of de herbouwwaardemeter. Weet je het niet, vul dan een schatting in en geef dat aan bij de opmerkingen.
Gebruik binnen het complex
Schades aan het complex in de afgelopen 5 jaar?
Is het complex nu verzekerd?
Wordt er gefrituurd of met open vuur gewerkt?
Is er een sprinkler- of blusinstallatie?
Schades afgelopen 5 jaar
Schade 1
Taxatie conform artikel 7:960 BW?
Soort verhuur
Zijn de panelen gekeurd (bijvoorbeeld SCIOS Scope 12)?
Zijn er extra maatregelen tegen brand?
Is er een onderhoudscontract?
Is er een asbestinventarisatie?
Is de tank gesaneerd of gecertificeerd?
Is er funderingsonderzoek gedaan?
Aanvullende gegevens over het complex Open
Hoe vollediger dit is, hoe minder we hoeven na te vragen.
Is er een recent taxatierapport?
Is er een meerjarenonderhoudsplan (MJOP)?
Is er een reservefonds?
Worden er appartementen verhuurd?
Staat er iets leeg?
Liggen er zonnepanelen op het complex?
Zijn er laadpunten voor elektrische auto's?
Is er een lift?
Is er asbest aanwezig?
Is er een olie- of gastank aanwezig?
Zijn er funderingsproblemen bekend?
Heeft het complex een monumentale status?
Heeft de VvE personeel in dienst?
Brandveiligheid in het complex
Beveiliging
Gemeenschappelijke installaties
Is er een kelder of souterrain?
Is er eerder wateroverlast geweest in kelder of garage?
Dakbedekking
Splitsingsakte, MJOP, taxatierapport, huidig polisblad of schadeoverzicht. Meerdere bestanden mogelijk.
Meerdere verzekerde locaties?
Aanwezige beveiliging en preventie
Doormelding naar alarmcentrale?
Blusmiddelen jaarlijks onderhouden?
Brandmelding doorgemeld?
Aanvullende gegevens Open
Relevante certificaten of vakbekwaamheid
Werk uitbesteed aan zzp'ers of onderaannemers?
Producten vervaardigen, importeren of leveren?
Werkzaamheden buiten Nederland?
Omzet of werkzaamheden in VS/Canada?
Bijzondere werkzaamheden
Lid van brancheorganisatie?
%
Aansprakelijkheidsverzekering onderaannemers verplicht?
Komt de volledige jaaromzet uit deze professionele dienstverlening?
Algemene voorwaarden met aansprakelijkheidsbeperking?
Werk door zzp'ers of onderaannemers?
Werkzaamheden of opdrachtgevers buiten Nederland?
Quality assurance / kwaliteitsmanagement toegepast?
Permanente educatie voor gekwalificeerde medewerkers?
%
Afspraken over aansprakelijkheid vastgelegd?
Houdt één persoon/familie/organisatie meer dan 15% van de aandelen?
Aandelen beursgenoteerd of anders publiek verhandelbaar?
Afgelopen 18 maanden overname, oprichting of fusie geweest?
Eerder bestuurdersaansprakelijkheidsverzekering gehad?
D&O-verzekering ooit geweigerd of opgezegd?
Dochterondernemingen buiten Nederland?
Achterstanden, convenantbreuk of herfinancieringsprobleem?
Overname, verkoop, reorganisatie of surseance voorzien?
Gewenste modules
Lopend of dreigend conflict?
Risico op vestigingsadres?
Geheel of gedeeltelijk verhuurd?
Leegstand of verbouwing?
Zonnepanelen aanwezig?
Open vuur of brandgevaarlijke werkzaamheden in pand?
Aanvullende gegevens Open
Zaken op vestigingsadres?
Diefstalgevoelige of kostbare goederen?
Brandbare of gevaarlijke stoffen opgeslagen?
Sterk afhankelijk van locatie, machine, leverancier of afnemer?
Continuïteits- of uitwijkplan aanwezig?
Onderhouds- of servicecontract?
Eigen server- of technische ruimte?
Werkmaterieel / machines
Machine 1
Zelfrijdend?
Gebruik op openbare weg?
Diefstalbeveiliging
Aanvullende machinegegevensOpen
Extra technische of acceptatievragen tonen we hier compact onder.
Gewenste dekking
Wijze van vervoer
Tijdelijke opslag tijdens transport?
Activiteiten
Gebruikte vervoersvoorwaarden
Vervoer uitbesteed aan ondervervoerders?
Opslag van goederen van derden?
%
Voertuiggegevens
Voertuig 1
Aanvullende voertuiggegevensOpen
Niet verplicht, maar hoe vollediger dit is, hoe scherper de premie-indicatie.
Soort voertuigen
Eigendomssituatie
Gebruik
Regelmatige bestuurders jonger dan 24?
Aanvullende gegevens Open
Voor scooters, bromfietsen, brommobielen en motoren op bedrijfsnaam.
Voertuiggegevens
Voertuig 1
Aanvullende voertuiggegevensOpen
Wordt er mee bezorgd of gekoerierd?
Wie rijden er?
Wat wil je meeverzekeren?
Garageactiviteiten
Komt de volledige jaaromzet uit garageactiviteiten?
Branche-aansluiting of certificering
Proefritten of voertuigen halen/brengen?
Las-, slijp- of ander brandgevaarlijk werk?
Activiteiten vanuit een bedrijfspand?
Soorten gegevens
Bedrijfskritische systemen/data in de cloud?
MFA op e-mail, beheeraccounts en externe toegang?
Gescheiden/offline back-ups aanwezig?
Back-ups periodiek getest?
Vast patch- en updatebeleid?
Cyberincidenten afgelopen 5 jaar?
Niet-ondersteunde / legacy software aanwezig?
Gedocumenteerd incident-responseplan aanwezig?
Gevaarlijke/bodembedreigende stoffen?
Boven- of ondergrondse tanks?
Benodigde vergunningen/meldingen aanwezig?
Recent bodemonderzoek beschikbaar?
Ondergrondse leidingen, putten of andere procesvoorzieningen?
Procesafvalwater of relevante luchtemissies?
%
Nu werknemers langer dan 4 weken ziek?
Contractvormen personeel
Aanvullende gegevens Open
Gewenste dekking
Huidige collectieve WIA/WGA-regeling?
Nu WGA-eigenrisicodrager?
Reisgebied
Gewenste dekkingen
Ander luchtvervoer dan reguliere lijnvluchten?
Fysiek/risicovol werk tijdens zakenreis?
Huidige collectieve zakelijke reisverzekering?
Tijdelijke krachten/zzp'ers/stagiairs meeverzekeren?
BHV'ers aanvullend meeverzekeren?
Verzekerden woonachtig in het buitenland?
Werkzaamheden zoals hoogte ≥4m, offshore, duiken of hulpdiensten?
Verzekerden met jaarsalaris boven €250.000?
Regelmatig werk in het buitenland?
Wijze van verkeersdeelname
Zakelijk verkeer in buitenland?
Komt de volledige jaaromzet uit bouw- of montagewerk?
Werk aan/in/nabij bestaande eigendommen?
Heiwerk, bronbemaling, grondwerk of leidingen?
Verantwoordelijk voor ontwerp/berekeningen?
Werk door onderaannemers?
%
Podia, tenten, tribunes of tijdelijke installaties?
Alcoholverstrekking?
Annuleringsdekking gewenst?
Aanvragen als
Staat op je KVK-uittreksel en op facturen. Acht cijfers, zonder punten of spaties.
Een VvE vult hier de jaarlijkse begroting of het totaal aan bijdragen in.
Nu al zakelijk verzekerd?
Zakelijke schades/claims afgelopen 5 jaar?
Verzekering ooit geweigerd/opgezegd?
Mededelingsplicht
Ben jij, of iemand anders die bij deze verzekering belang heeft, in de afgelopen 8 jaar in aanraking geweest met politie of justitie?
Denk aan een verdenking, boete, transactie, taakstraf of veroordeling. Verkeersboetes tot 300 euro hoef je niet te melden.
Is er ooit een verzekering opgezegd, geweigerd of beëindigd wegens fraude, of sta je geregistreerd in het incidentenregister?
Andere bekende omstandigheden die mogelijk tot een claim leiden?
Vermeld het jaar, wat er speelde en hoe het is afgehandeld. Dit betekent niet automatisch dat je niet verzekerd kunt worden.

What to look out for

Four subjects that decide whether a cyber claim is paid or refused.

The application questionnaire is a condition of cover

Questions about multi-factor authentication, offline back-ups, patching policy and administrator rights are not a survey but the basis of acceptance. If you answer that MFA is active everywhere while that is not true for remote access, that is an incorrect statement. The duty of disclosure follows from Article 7:928 of the Dutch Civil Code and the consequences are set out in Article 7:930 of the Dutch Civil Code: where information is withheld, the payout may lapse in whole or in part. Have the answers confirmed by your IT manager.

What is not paid out

Outside the cover are administrative fines and penalty payments in so far as they are not insurable under Dutch law, damage caused by acts of war and attacks attributed to a state, exploitation of a vulnerability that was already known and for which an update was available, the cost of the improving your systems compared with the previous situation, and reputational damage or a fall in the value of your business. Intent remains excluded under Article 7:952 of the Dutch Civil Code.

Money transferred away is a separate category

If your employee is induced to make a transfer by a forged invoice or an imitated instruction from the board, that is not hacking damage but fraud involving human action. Many policies cover it only through a separate module with its own, lower limit, and sometimes only if two-person authorisation demonstrably existed. Ask what your quote calls this and what amount is set for it.

Your supplier goes down, not you

If your administration or webshop runs at an external party, an incident there hits you directly while your own network is intact. Cover for an outage at an IT service provider is not a given and is often named separately, with the failure of power and telecom networks excluded. Map out your dependence on the supply chain and set the contractual arrangements with that supplier alongside the policy.

What does your premium depend on?

  • Annual turnover and sector: the usual basis, with a loading for sensitive data
  • Nature of the data processed: payment details and health data weigh heavily
  • Measures in place. MFA, back-up strategy, detection and rights management
  • Dependence on systems: how quickly turnover stops when systems fail
  • Waiting period chosen: the number of hours before business interruption counts
  • Sum insured and sub-limits: per claim, per year and per module

Insurers weigh these details differently. That is where your saving is.

Request a quote

What is covered

SituationOwn damageLiability
Ransomware takes your order system down for four daysYesNo
Restoring a database for which only a three-week-old back-up still existsYesNo
An employee loses an unencrypted laptop with personnel files on the trainYesProvided that
A customer demands compensation because your outage caused his own delivery to failNoYes
Your webshop is down for eight hours while your policy has a twelve-hour waiting periodNoNo
The turnover you lose permanently because customers moved elsewhere after the incidentNoNo

Almost every cyber incident touches both columns at once, but the sub-limits per section differ widely.

Frequently asked questions

This is what people ask us most.

Does the insurer pay the ransom in a ransomware attack?

Some policies have an extortion module, always with its own limit and only after consultation with the insurer and the response team. If you pay on your own initiative, there is usually no cover. Sanctions rules also apply: payment to a sanctioned party is prohibited and therefore uninsurable. The focus of the policy is not on paying but on recovery from back-ups.

What if the attack comes in through a supplier?

Then the question is whose policy responds. You report your own loss to your own insurer, who can then seek recovery from the supplier if a mistake was made there. For claims from your customers about your services, a professional indemnity insurance may also come into play. Report an incident to both insurers as soon as you suspect it.

Are regulatory fines insured?

No. An administrative fine is a penalty and not compensation for loss, and is therefore not insurable in the Netherlands. What is covered are the costs of the investigation, the notification, the communication with those concerned and legal assistance during proceedings. Compensation to people whose data has leaked may also fall under the liability section.

We are a small organisation. Is this really necessary?

The size of a business does not determine whether it is hit; attacks are largely automated. What differs is the ability to recover: a small organisation rarely has its own IT department that can scale up overnight. It is precisely there that the response service is the most valuable component. For sole traders there is a lighter version, see cyber insurance for self-employed professionals.

Laatste nieuws, reviews en blogs:
Laatste nieuws en blogs: