Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
An estate agency does not hold the purchase price itself, but it does sit in the email exchange in which the account number for that purchase price goes round.
This page in another language: Nederlands
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
An estate agent's file is unusually complete for a fraudster: under the Wwft (the Dutch anti-money laundering act) it holds identity documents and questions about the source of funds, alongside financial details, valuation data, addresses and the planning of the handover of keys. That is enough to write a convincing email to a buyer who has just arranged his finance.
The money runs through the notary's client account, but the email chain runs through you. If your mailbox is being read, the message with a changed account number is sent at exactly the right moment, in your house style and with the correct file details. The loss then falls on the client and the question becomes whether you observed the standard of care in Article 6:162 of the Dutch Civil Code.
If you work with a notary's office or a mortgage adviser, the weakest link is usually the party least well set up against being read.
We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.
Cyber insurance
Compare
Get coveredThe structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Insurers weigh these details differently. That is where your saving is.
We look at the terms as well as the premium, and stay your point of contact when there is a claim.
We are not tied to one insurer and compare on the basis of an objective analysis of several companies.
You call or email someone who knows your file. No menu options, no changing call centres.
We cancel your old policy and align the start date, so you are never a day without cover.
We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
Four points that make the difference between a policy that pays out and one that does not.
You keep copies of identity documents and records of client due diligence because the Wwft requires it. It is precisely that combination of passport details, marital status and financial position that makes a breach suitable for identity fraud, and with it the chance of claims from those concerned very real. So limit who in the office can reach that folder and delete what you no longer need to keep. Administrative fines and penalty payments imposed by regulators are not insurable; claims from those who suffer loss generally are.
In transaction fraud your system is not broken. Your correspondence is imitated. The counter-measure is procedural: confirm account numbers only by telephone on a number you already had, and warn buyers in writing at the outset that you never pass on a different number by email. Note that most cyber policies do not reimburse the sum transferred itself. Financial loss through deception is a separate cover that you have to include expressly.
Almost every office works in an estate agency package with links to property portals and exchange systems. If that package is down, you cannot arrange a viewing or open a file, but the fault lies with someone else. So check whether your policy includes an outage at a service provider and what waiting period applies to it; below that waiting period nothing is paid. Towards your client you remain the controller yourself, even if the breach arose at that supplier.
If a client complains that you conducted a bidding process incorrectly or failed to disclose a defect, that is a professional error and not a cyber loss. The cyber policy starts with a security incident: email read by others, ransomware, a breach. The two policies exclude each other's territory, so a claim that falls between them almost always arises from a gap where they meet. Your own intent or wilful recklessness also stays outside the cover under Article 7:952 DCC.
This is what people ask us most.
The investigation, recovery and legal costs on your side generally fall under the policy, as does the claim the buyer brings against you. The amount transferred itself falls under the cover only if you have included financial loss through deception; as standard that is almost never the case. Ask about it expressly when getting a quote, because for estate agents this is the most expensive scenario.
Yes. Cloud software moves the risk. It does not remove it. One stolen password is enough for an attacker to reach your files and mailbox, and if your supplier has an outage your office is at a standstill with nothing you can do about it. What shifts is the emphasis: less data recovery on your own servers, more attention to access management and to the waiting period for supplier outages.
Administrative fines of a punitive nature, for example for inadequate client due diligence or a GDPR breach, are not insurable in the Netherlands. What is covered are the costs of making the report, informing those concerned, legal assistance during an investigation, and the claims for compensation that those affected bring against you. Where identity data is involved, the last of these is often the largest part of the bill.
Usually two-factor authentication on email and on the estate agency package, up-to-date patching, and back-ups that you have tested and that cannot be deleted from the same account. If you state those measures in the application, they are disclosures within the meaning of Article 7:928 DCC. If they are missing when a loss occurs, the insurer can reduce the payout under Article 7:930 DCC.
Every situation is different. For these situations we have a separate page.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was compiled by Finass Verzekert (LinkedIn). Last updated on .
The information on this page is general in nature and is not personal advice.
Maandag- Vrijdag: 09:00- 17:00
We use cookies and similar technologies to improve your experience on our website.