Incident response · waiting period · application questions
Cyber insurance through Chubb
With a cyber policy you are mainly buying speed: a team that starts within a few hours. What that policy then pays out depends on the answers you gave on the application form months earlier.
- Several insurers compared objectively
- 9.5 customer rating for a new policy
- AFM licence 12016589
- Personal 072 - 509 24 56, weekdays 9–17
Deze pagina in het Nederlands: Cyberverzekering via Chubb.
The calculator and the quote form below are in Dutch. Prefer to do this in English? Email info@finassverzekert. nl or call 072 - 509 24 56 and we will take it from there.
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
- We compare the offerings of several insurers
- An adviser checks whether the cover suits your activities
- We arrange the switch, including cancellation
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
In brief
Chubb is one of the parties with which Finass can place a cyber risk. We are not tied to this company and assess the offerings of more than thirty providers on their substance. The choice follows from your IT set-up and your dependence on systems. The rest of this insurer's business range is shown on the overview page. What a cyber policy arranges in essence is set out on the hub page cyber insurance.
Cyber cover falls into two halves. The damage to your own property covers forensic investigation, restoring or rebuilding data and systems, crisis communication, legal assistance with a report to the Autoriteit Persoonsgegevens (the Dutch data protection authority) and the loss of turnover caused by the interruption. The liability covers claims from customers and suppliers whose data has leaked or whose own process came to a halt. For employers and processors, the duty to report under Article 33 of the GDPR is the starting point: a data breach must be reported without undue delay and in principle within 72 hours, and that clock is running while you are still working out what has happened.
The part that is most often underestimated is the waiting period for business interruption. Unlike fire damage, it is measured in hours rather than days, and only after that period does compensation for lost turnover start to run. For a webshop or a manufacturer with a short lead time, the difference between a six-hour and a twelve-hour waiting period matters more than a difference in premium. Also compare the sub-limits: extortion, data recovery and fraudulent payments almost always have a lower limit than the main sum insured.
This page deals with one situation. The full overview is on Compare business cyber insurance.
What to look out for
Four subjects that decide whether a cyber claim is paid or refused.
The application questionnaire is a condition of cover
Questions about multi-factor authentication, offline back-ups, patching policy and administrator rights are not a survey but the basis of acceptance. If you answer that MFA is active everywhere while that is not true for remote access, that is an incorrect statement. The duty of disclosure follows from Article 7:928 of the Dutch Civil Code and the consequences are set out in Article 7:930 of the Dutch Civil Code: where information is withheld, the payout may lapse in whole or in part. Have the answers confirmed by your IT manager.
What is not paid out
Outside the cover are administrative fines and penalty payments in so far as they are not insurable under Dutch law, damage caused by acts of war and attacks attributed to a state, exploitation of a vulnerability that was already known and for which an update was available, the cost of the improving your systems compared with the previous situation, and reputational damage or a fall in the value of your business. Intent remains excluded under Article 7:952 of the Dutch Civil Code.
Money transferred away is a separate category
If your employee is induced to make a transfer by a forged invoice or an imitated instruction from the board, that is not hacking damage but fraud involving human action. Many policies cover it only through a separate module with its own, lower limit, and sometimes only if two-person authorisation demonstrably existed. Ask what your quote calls this and what amount is set for it.
Your supplier goes down, not you
If your administration or webshop runs at an external party, an incident there hits you directly while your own network is intact. Cover for an outage at an IT service provider is not a given and is often named separately, with the failure of power and telecom networks excluded. Map out your dependence on the supply chain and set the contractual arrangements with that supplier alongside the policy.
What does your premium depend on?
- Annual turnover and sector: the usual basis, with a loading for sensitive data
- Nature of the data processed: payment details and health data weigh heavily
- Measures in place. MFA, back-up strategy, detection and rights management
- Dependence on systems: how quickly turnover stops when systems fail
- Waiting period chosen: the number of hours before business interruption counts
- Sum insured and sub-limits: per claim, per year and per module
Insurers weigh these details differently. That is where your saving is.
What is covered
| Situation | Own damage | Liability |
|---|---|---|
| Ransomware takes your order system down for four days | Yes | No |
| Restoring a database for which only a three-week-old back-up still exists | Yes | No |
| An employee loses an unencrypted laptop with personnel files on the train | Yes | Provided that |
| A customer demands compensation because your outage caused his own delivery to fail | No | Yes |
| Your webshop is down for eight hours while your policy has a twelve-hour waiting period | No | No |
| The turnover you lose permanently because customers moved elsewhere after the incident | No | No |
Almost every cyber incident touches both columns at once, but the sub-limits per section differ widely.
Frequently asked questions
This is what people ask us most.
Does the insurer pay the ransom in a ransomware attack?
Some policies have an extortion module, always with its own limit and only after consultation with the insurer and the response team. If you pay on your own initiative, there is usually no cover. Sanctions rules also apply: payment to a sanctioned party is prohibited and therefore uninsurable. The focus of the policy is not on paying but on recovery from back-ups.
What if the attack comes in through a supplier?
Then the question is whose policy responds. You report your own loss to your own insurer, who can then seek recovery from the supplier if a mistake was made there. For claims from your customers about your services, a professional indemnity insurance may also come into play. Report an incident to both insurers as soon as you suspect it.
Are regulatory fines insured?
No. An administrative fine is a penalty and not compensation for loss, and is therefore not insurable in the Netherlands. What is covered are the costs of the investigation, the notification, the communication with those concerned and legal assistance during proceedings. Compensation to people whose data has leaked may also fall under the liability section.
We are a small organisation. Is this really necessary?
The size of a business does not determine whether it is hit; attacks are largely automated. What differs is the ability to recover: a small organisation rarely has its own IT department that can scale up overnight. It is precisely there that the response service is the most valuable component. For sole traders there is a lighter version, see cyber insurance for self-employed professionals.

