Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
At a hosting company your own loss is rarely the problem: the bill arises on the side of the customers who all go down at the same time and all come knocking at the same time.
This page in another language: Nederlands
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
For almost all your customers you are the processor and not the controller. You do not decide what data sits in their applications, but you do carry the security of the environment in which that data lives. After an incident you report to your customers, each within the period set in his data processing agreement, and they report to the Autoriteit Persoonsgegevens (the Dutch data protection authority). That means you have to be able to say within a day, per customer, what has been affected, and that is a forensic task you have to organise in advance.
The characteristic risk is accumulation. One compromised management environment, one infected hypervisor or one error in a rollout hits not one customer but every customer in the same space. The sum insured therefore has to match not an average claim but a scenario in which a large part of your portfolio reports a loss at the same time. Look at the limit per event and at the maximum per insurance year. For this type of business those two quickly diverge.
Limit your exposure contractually as well. In your general terms and SLAs you set out what you stand behind, up to what amount and with what exclusions. Those arrangements help determine what an insurer is prepared to cover. Set against that the fact that contractual penalties and service credits you have agreed yourself are not an insured loss. If you supply development or management alongside hosting, that calls for professional indemnity cover for errors in that work.
We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.
Cyber insurance
Compare
Get coveredThe structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Insurers weigh these details differently. That is where your saving is.
We look at the terms as well as the premium, and stay your point of contact when there is a claim.
We are not tied to one insurer and compare on the basis of an objective analysis of several companies.
You call or email someone who knows your file. No menu options, no changing call centres.
We cancel your old policy and align the start date, so you are never a day without cover.
We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
Four points that make the difference between a policy that pays out and one that does not.
A large share of the outages in this sector is caused not by attackers but by a migration that goes wrong, a configuration error or failed storage. Standard cyber policies cover only malicious causes. Ask about the extension for unintentional system failure, because without it your most likely loss falls outside the cover while you pay for the less likely one.
Work out what happens if fifty or a hundred customers go down at once and then claim. The sum of their lost turnover is many times your own annual turnover, while the premium is based on that own turnover. So look closely at the limit per event, the annual maximum and the question of whether all claims from one cause are counted as one event.
Many customers assume that you will restore their data, even where that was not bought as a service. Record for each customer who makes the back-up, how often, how long it is kept and who carries out the restore. If it turns out after an incident that the back-up was encrypted along with everything else or was never tested, the discussion shifts from technology to liability and your own shortcoming becomes the subject.
Not covered are contractual penalties and service credits under your SLAs, subscription fees refunded, and rebuilding or improving your platform afterwards. Damage caused by acts of war or state actors, physical damage to hardware in the data centre and intent or wilful recklessness under Article 7:952 of the Dutch Civil Code are also excluded. Known, unpatched vulnerabilities regularly lead to a refusal.
This is what people ask us most.
No. Penalties and credits you have agreed contractually are your own choice and do not count as an insured loss. What can fall under the third-party section is the loss a customer suffers and for which you are liable in law. The distinction between the two stands or falls with the wording in your contracts.
Only if the extension for unintentional system failure is included. The basic cover of a cyber policy requires a malicious cause, such as an attack or infection. An error of your own in the rollout falls outside it. For a hosting company this is often the most important extension in the whole policy.
Your customer, because he is the controller. You report the incident to him within the period set in the data processing agreement, often shorter than 72 hours. That means you have to be able to say quickly, per customer, which systems and which data have been affected. Logging and separated environments are the condition for that.
It limits your role, not your exposure. If your platform is down, all customers suffer loss regardless of who built the application. It is important, though, to set out in the contract where your responsibility ends and the application supplier's begins; that boundary determines who is held responsible when a claim comes in.
Every situation is different. For these situations we have a separate page.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was compiled by Finass Verzekert (LinkedIn). Last updated on .
The information on this page is general in nature and is not personal advice.
Maandag- Vrijdag: 09:00- 17:00
We use cookies and similar technologies to improve your experience on our website.