Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
This page explains how cyber insurance is built up and which choices you make within it. The sector pages set out what that means for a specific industry.
This page in another language: Nederlands
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
Cyber insurance consists of three blocks that you have to assess separately. The first is incident response: a reporting number, forensic investigation and specialists who establish what has happened. The second is your own loss: restoring systems and files, and the turnover you lose while you are down. The third is liability towards customers and individuals whose data has leaked, together with the costs of the duty to report. Each block has its own limit and sometimes its own excess.
Which block weighs heavily for you depends on your business model, not on your size. If your turnover runs on systems that are switched on, as at a hospitality business or a webshop, the interruption cover and above all the waiting period are decisive. If you hold a lot of data, or sensitive data, belonging to others, as at an pharmacy or a HR agency, the costs lie in investigation, notification and liability. If you supply digital services yourself, supply chain liability is added.
Two misunderstandings come up again and again. The first is that business interruption insurance does something here: usually it requires physical damage to property, and digital downtime without fire or burglary does not meet that. The second is that the insurer takes over your security. The opposite is true: in the application you set out your measures, and those become part of the contract. Incorrect answers affect the duty of disclosure under Article 7:928 of the Dutch Civil Code and the consequences of this in Article 7:930 of the Dutch Civil Code.
We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.
Cyber insurance
Compare
Get coveredThe structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Insurers weigh these details differently. That is where your saving is.
We look at the terms as well as the premium, and stay your point of contact when there is a claim.
We are not tied to one insurer and compare on the basis of an objective analysis of several companies.
You call or email someone who knows your file. No menu options, no changing call centres.
We cancel your old policy and align the start date, so you are never a day without cover.
We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
Four points that make the difference between a policy that pays out and one that does not.
The interruption cover only starts running after an agreed number of hours and stops after an agreed period. A business that is back up after eight hours gains nothing from a twenty-four-hour waiting period, while an organisation that spends weeks on recovery should be looking at the indemnity period instead. First work out how long you can manage without systems, and only then choose the limit.
Much downtime starts not with you but with a software package, a hosting provider or an administrator who looks in remotely. Check whether the policy also pays out if the cause lies with a supplier and not in your own network, because that is not a given. Also set out in the contract the period within which that party must inform you; suppliers' terms usually limit their own liability to part of the subscription.
With a forged invoice or an imitated payment instruction there has been no break-in. A payment has been made. That falls under social engineering and sits in a separate module with its own, usually lower limit and often a condition about your payment procedure. Ask explicitly in every quote whether this module is included, because the premiums of policies with and without it are not comparable.
Not covered are administrative fines of a punitive nature, improving or renewing your security after an incident, and physical damage to equipment, which belongs on the business contents insurance. Also excluded are contractual penalties you have agreed yourself, damage caused by acts of war or state actors, and intent or wilful recklessness under Article 7:952 of the Dutch Civil Code are not included.
This is what people ask us most.
As a rule, no. That cover requires physical damage to insured property as the cause of the interruption, such as fire or water damage. With ransomware there is no physical damage, so the interruption falls outside it. The interruption cover on a cyber insurance policy is made precisely for this scenario and has its own waiting period.
That depends on your dependence, not on your size. Even without large data sets, your work stops if the systems are encrypted, and the duty to report a breach applies regardless of company size. For small organisations, access to specialists is often more valuable than the level of the sum insured.
Usually multi-factor authentication on email and on access from outside, up-to-date patching, and back-ups that are kept disconnected and have demonstrably been restored. These points appear as conditions in the policy. If they are not met at the time of the incident, the insurer may reduce or refuse the payout.
Only if an extortion module is included, and then only after consultation and prior consent. Conditions apply under sanctions legislation and the insurer first brings in investigators and negotiators. Payment also gives no certainty that you will get your data back. A disconnected and tested back-up remains the most reliable way out.
Every situation is different. For these situations we have a separate page.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was compiled by Finass Verzekert (LinkedIn). Last updated on .
The information on this page is general in nature and is not personal advice.
Maandag- Vrijdag: 09:00- 17:00
We use cookies and similar technologies to improve your experience on our website.