Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
At a notary's office two things come together that are separate elsewhere: other people's money in the client account and an archive of deeds you have to be able to produce for decades.
This page in another language: Nederlands
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
The client account makes your office a payment institution in miniature. Around every transfer of property and mortgage redemption there are payment instructions with amounts worth a fraudster's while to read for weeks. The attack is therefore rarely noisy: no ransomware, but a silent break-in to a mailbox that waits until the moment of payment.
You are also under a duty of retention that no other service provider has in the same form. Your protocol, the register of deeds and the digital copies have to remain available and unaltered for decades. An environment that is encrypted or manipulated therefore affects not only your operations but your official duties, with supervision by the Bureau Financieel Toezicht (the Dutch financial supervision office for the legal professions) and the disciplinary tribunal in the background.
On the other side of the same transaction are the estate agent and the mortgage adviser; the supply chain risk is only covered once all three mailboxes are in order.
We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.
Cyber insurance
Compare
Get coveredThe structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Insurers weigh these details differently. That is where your saving is.
We look at the terms as well as the premium, and stay your point of contact when there is a claim.
We are not tied to one insurer and compare on the basis of an objective analysis of several companies.
You call or email someone who knows your file. No menu options, no changing call centres.
We cancel your old policy and align the start date, so you are never a day without cover.
We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
Four points that make the difference between a policy that pays out and one that does not.
If money disappears from the client account through a forged or intercepted payment instruction, that is not a data loss but financial loss. On an ordinary cyber policy that does not fall under the cover. It requires a separate section for deception in payments, with its own requirements on two-person authorisation and on telephone verification of changed account numbers. Arrange this in advance and put the working arrangement in writing, because afterwards the question is always whether someone skipped the procedure.
At most firms an incident costs time; at yours it costs evidence. Digital copies, scans and the register of deeds have to remain reconstructable, even if an attacker takes all the online back-ups with him. Insurers therefore ask about immutable copies or copies kept offline and about the last time you tested a restore. The costs of data recovery and reconstruction are a core part of the cover; having a deed executed again is not.
If an incident leads to a complaint to the chamber for the notarial profession or to measures by the Bureau Financieel Toezicht, the policy can usually fund the legal assistance, but not the consequences. Disciplinary measures are personal and not insurable, and neither are administrative fines of a punitive nature. Intent and wilful recklessness also remain outside the cover under Article 7:952 of the Dutch Civil Code, including where an employee showed that recklessness.
If a deed contains the wrong plot number or a mortgage has not been discharged, that is an official error belonging with your professional indemnity insurance (BAV). The cyber policy only starts with a security incident: a mailbox read by others, encrypted systems, a breach of the file archive. Insurers exclude each other's territory, so when taking out cover have it expressly checked that the join between the two policies is watertight.
This is what people ask us most.
Not automatically. A standard cyber policy pays for investigation, recovery, notification costs and liability, but not for the amount siphoned off. For that there is a separate section for financial loss through deception, which insurers offer only where there is demonstrable two-person authorisation and telephone verification of account numbers. Have it quoted expressly; for a notary's office this is the scenario with the largest financial outlier.
Fraud or wilful recklessness by your own employee does not fall under ordinary cyber cover. Insurers treat that as an integrity risk requiring separate fidelity insurance. You can be liable for unlawful acts of subordinates towards third parties under Article 6:170 DCC; whether that reaches the policy depends on whether a security incident lay behind it.
Yes. The volume of data and the retention period are two of the most heavily weighted factors, because they determine how many people have to be informed after a breach and how much reconstruction work there is. What helps is demonstrable protection of the old archive and back-ups that an attacker cannot reach or delete from the working environment.
Yes, and quickly. Article 7:941 DCC requires you to report the incident as soon as you become aware of it. With cyber losses that is not merely a formality: the insurer's reporting line sets the forensic specialists in motion, and traces in log files disappear within days. So do not wait until you know the extent; report first and gather the facts with them afterwards.
Every situation is different. For these situations we have a separate page.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was compiled by Finass Verzekert (LinkedIn). Last updated on .
The information on this page is general in nature and is not personal advice.
Maandag- Vrijdag: 09:00- 17:00
We use cookies and similar technologies to improve your experience on our website.