Skip to main content





9,5/ Reviews

Compare business cyber insurance

With cyber insurance you are not paying for a payout afterwards but for a team that starts within a few hours. When it comes to it that is the most valuable part of the policy, and at the same time the part that shows up in no premium comparison.

  • several insurers compared objectively
  • 9.5 customer rating for a new policy
  • AFM licence 12016589
  • Personal 072 - 509 24 56, weekdays 9–17

This page in another language: Nederlands

The calculator and the quote form below are in Dutch. Prefer to do this in English? Email info@finassverzekert.nl or call 072 - 509 24 56 and we will take it from there.

Work out for yourself what it would cost.

  • We compare the offerings of several insurers
  • An adviser checks whether the cover suits your activities
  • We arrange the switch, including cancellation

Request a quote

A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.

  • Independent advice
  • Several insurers
  • Switching arranged
  • Help with claims

In brief

Cyber insurance covers the consequences of a digital incident: a hack, a data breach, ransomware or a mistake by an employee. The cover has three parts: incident response, damage to your own property (restoring systems and data, loss of turnover through downtime) and liability towards customers whose data has been leaked.

If you process personal data, the duty to report data breaches under the GDPR applies: a data breach must be reported to the Autoriteit Persoonsgegevens (the Dutch data protection authority) without undue delay and, where possible, within 72 hours of discovery, unless it is unlikely to present a risk to the people concerned. Where the risk is high, you must also inform those people yourself.

Those 72 hours are the reason incident response is not a luxury. In the first day you have to establish which data has been affected, whether the breach is still open, and what you are going to report: while your systems may well be down. That is not something you do in-house on the side.

Independent, personal, sorted quickly

We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.

Arranging cyber insurance through Finass VerzekertCyber insurance
Photo coming soon
Comparing cyber insurance premiums and coverCompare
Photo coming soon
Get cyber insurance sorted todayGet covered
Photo coming soon

What does business cyber insurance cover?

The structure of the cover in three parts, with an overview per situation below.

Immediate help

Incident response

A 24/7 team of IT forensic specialists, lawyers and communications advisers.

  • Forensic investigation
  • Support with the notification
  • Crisis communications
Recovery and downtime

Own damage

The cost of getting up and running again, and the loss caused while you are at a standstill.

  • Restoring systems and data
  • Business downtime
  • Ransom, differing from policy to policy
Towards third parties

Liability

Claims from customers or suppliers whose data has been leaked.

  • Claims for damages after a data breach
  • Defence costs
  • Fines, in so far as they can be insured

What is covered

SituationCovered
Ransomware brings your systems downYes
A data breach involving customers' personal dataYes
Loss of turnover through days of downtimeSometimes
Invoice fraud and manipulated paymentsSometimes
Loss caused by a known, unpatched vulnerabilityNo
An administrative fine that is punitive in natureNo

This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.

What does your premium depend on?

  • Annual turnover: the main basis for calculation
  • Volume and type of personal data: medical and financial data count more heavily
  • Security level. MFA, back-up strategy and patching policy
  • Sum insured and excess
  • Dependence on IT: a webshop is in a different position from a joinery firm
  • Claims history: earlier incidents and how they were dealt with

Insurers weigh these details differently. That is where your saving is.

How we arrange it

  1. You request a quoteWe take stock of your situation, your risk and your wishes.
  2. We compareseveral insurers, on premium as well as conditions.
  3. You receive a proposalWith an explanation of the differences and the exclusions.
  4. We arrange the switchIncluding cancellation, so there is no gap in cover.

Request a quote

Why arrange it through Finass Verzekert?

We look at the terms as well as the premium, and stay your point of contact when there is a claim.

Independent

We are not tied to one insurer and compare on the basis of an objective analysis of several companies.

One fixed adviser

You call or email someone who knows your file. No menu options, no changing call centres.

Switching without hassle

We cancel your old policy and align the start date, so you are never a day without cover.

Help with claims

We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.

9.5New policy
9.8Claims handling

Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.

View the reviews at NH1816 · all reviews on our site

Where things go wrong in practice

Four points that make the difference between a policy that pays out and one that does not.

The 72 hours start at discovery, not at the incident

The GDPR requires you to report a data breach to the Autoriteit Persoonsgegevens without undue delay and, where possible, within 72 hours of becoming aware of it. If you report later, you have to give reasons. That clock also runs at weekends, and while you are still working out exactly what has happened; a policy with an emergency number that answers straight away is therefore worth more than a few tens of euros' difference in premium.

Insurers set requirements before they accept you

Multi-factor authentication on remote access, back-ups that cannot be reached from the network, and patching in good time are conditions almost everywhere. Those requirements are in the policy conditions, not in the brochure. If you do not meet them at the time of the incident, a payout can be refused: and a known, unpatched vulnerability is precisely the most common way in.

Fines: do not expect too much

Under Dutch law, administrative fines that are punitive in nature are generally regarded as uninsurable; insuring them would remove the incentive the fine is meant to create. What can be insured is the cost of legal assistance in such proceedings and the civil claims of the people affected. Do not let anyone talk you into cover for GDPR fines without reading the provision yourself.

Downtime without physical damage falls outside your business interruption policy

An ordinary business interruption insurance requires physical damage as the cause: fire, water, burglary. If you are at a standstill because of ransomware, nothing is broken and that policy does not pay. That is exactly the gap the cyber policy fills, provided you choose the waiting period carefully. It often only starts after eight or twelve hours of downtime.

Business interruption insurance

Frequently asked questions

This is what people ask us most.

How quickly do I have to report a data breach?

Without undue delay and, where possible, within 72 hours of becoming aware of the breach, to the Autoriteit Persoonsgegevens. If the breach is unlikely to present a risk to the people concerned, there is no need. Where the risk is high, you must also inform those people yourself.

Can GDPR fines be insured?

Usually not, because administrative fines that are punitive in nature are regarded as uninsurable under Dutch law. The cost of defending yourself and of legal support often can be insured, as can civil claims from the people affected.

What does an insurer require of my security?

Almost always multi-factor authentication on remote access, back-ups that cannot be reached from the network, an up-to-date patching policy and current security software. Those requirements are in the policy conditions and are not optional advice.

Does the insurer pay a ransom after a ransomware attack?

Some policies cover a ransom, others do not. Where it is covered, strict conditions apply and the insurer has a say. With virtually every insurer, the effort goes into recovering from back-ups.

Does this replace my business interruption insurance?

No, and not the other way round either. An ordinary business interruption policy requires physical damage as the cause; digital downtime does not qualify. The cyber policy covers precisely that situation, with a waiting period of its own.

Do I need this as a small business?

Attacks are largely automated and not selective. The difference lies not in the likelihood but in the consequences: a small business rarely has an IT team of its own that can stop an incident within a day.

Ready to compare?

Request a quote without obligation. We will look at which insurer best matches your activities and your risk.

Request a quote

Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.

About our service

Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.

You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.

This page was compiled by Finass Verzekert (LinkedIn). Last updated on .

The information on this page is general in nature and is not personal advice.