Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
A bookkeeping firm handles the payments and payslips of other businesses, and that makes the firm more attractive as a conduit than as a victim.
This page in another language: Nederlands
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
Anyone who handles payroll administration and payment files sits close to other people's money. The systems hold salaries, citizen service numbers, employees' bank details and the payment batches you prepare for approval. An attacker who gets into your mailbox does not need to encrypt anything afterwards: it is enough to change a bank account number in a data file, or to send an amended payment instruction to the client in your name. That is a different kind of loss from ransomware and is treated differently on the policy as well.
For this type of firm, therefore, the module for fraud and social engineering is the part to watch. It covers a payment made as a result of deception, and stands apart from the cover for attacks on your systems. Insurers often include that module only if you have a documented two-person authorisation procedure for changing bank details, and they apply a separate limit to it. If your client's money is transferred away, there is also the question of whose loss it is: you carry the liability, your client the loss.
For most of your work you are the processor and not the controller. The data processing agreements you concluded with your clients determine the period within which you report an incident and which security measures you have promised. Answers to the acceptance questions that do not match those agreements affect the duty of disclosure under Article 7:928 of the Dutch Civil Code and the consequences in Article 7:930 of the Dutch Civil Code. If you also work for accountancy firms, compare this with the approach on the page about cyber insurance for accountants.
We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.
Cyber insurance
Compare
Get coveredThe structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Insurers weigh these details differently. That is where your saving is.
We look at the terms as well as the premium, and stay your point of contact when there is a claim.
We are not tied to one insurer and compare on the basis of an objective analysis of several companies.
You call or email someone who knows your file. No menu options, no changing call centres.
We cancel your old policy and align the start date, so you are never a day without cover.
We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
Four points that make the difference between a policy that pays out and one that does not.
Where a bank account number in a payroll batch has been changed or a false payment instruction has been issued, nobody has broken in; money has been transferred. Many cyber policies cover only attacks on systems and leave this out of account, or place it in a separate module with a lower limit and its own excess. Ask explicitly in the quote whether deception of your employee or of your client is included, and up to what amount.
If your system is down around the last week of the month, hundreds of your clients' employees receive no salary and the deadline for the payroll tax return keeps running. The costs of a workaround, such as pushing payments through manually or bringing in another firm, fall under the cover only if the additional costs item has been set generously enough. Ask about that before the peak arrives.
The 72 hours of the GDPR apply to your client. Your data processing agreements almost always set a shorter period within which you have to report an incident to that client, sometimes 24 hours. So the incident response team has to be able to establish within a day which sets of records have been affected. Check whether the policy gives access to such a team and whether its costs fall outside your excess.
Not covered are fines of a punitive nature, the amount your client pays its own employees voluntarily, and improvements to your security afterwards. Payments made without the control procedure set out in the policy are also refused, as are intent and wilful recklessness under Article 7:952 of the Dutch Civil Code. Damage to workstations and servers themselves belongs under the business contents cover.
This is what people ask us most.
Only if the fraud or social engineering module is included. The main cover concerns attacks on your systems, and where a bank account number has been changed there has usually been no break-in but manipulation. The insurer also checks whether your control procedure was followed. If the change was made without a second check, refusal or reduction often follows.
Your client reports it to the Autoriteit Persoonsgegevens (the Dutch data protection authority), because the client is the controller. You report the incident to the client, within the period set in your data processing agreement. That is usually shorter than 72 hours. For your own personnel and client relationship data you are responsible yourself and report directly.
The third-party section of the cyber insurance handles claims arising from a data breach. If the complaint concerns the quality of your advice or processing, that falls under the professional indemnity insurance (BAV). Always report a claim on both policies. The insurers decide between themselves which cover responds.
Responsibility for the data stays with you and your clients. If the service is down for days, you bear the consequences towards your clients, while the supplier's terms usually pay no more than part of the subscription. The interruption cover on your own policy is therefore relevant even when you work entirely in the cloud.
Every situation is different. For these situations we have a separate page.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was compiled by Finass Verzekert (LinkedIn). Last updated on .
The information on this page is general in nature and is not personal advice.
Maandag- Vrijdag: 09:00- 17:00
We use cookies and similar technologies to improve your experience on our website.