Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
A hotel runs day and night, which means a systems incident immediately affects guests who are already in the building and not only turnover still to come.
This page in another language: Nederlands
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
The hotel system is the heart of the business: reservations, room allocation, prices, invoicing and often the control of the door locks all hang on it. The booking channels are also connected to it, so that availability and rates are passed on automatically. If the whole thing fails, you cannot check anyone in, programme a key or draw up a bill, while bookings keep coming in that you cannot see. The loss is therefore operational before it becomes financial.
On the data side, a hotel stands out through the combination of payment details, identity details and stay details. You are required to keep a guest register, so you record for every guest who they are and when they stayed where. That information about stays is sensitive in itself, quite apart from the payment details you keep for guarantees and no-shows. In the event of a breach, the report to the Autoriteit Persoonsgegevens (the Dutch data protection authority) within 72 hours applies and, where the risk is high, the duty to inform guests, including guests from years ago.
So look critically at how long guest data stays in the system. An archive going back ten years increases the size of a breach without producing any benefit. Insurers ask about retention periods, about the separation between the guest network and the business systems, and about the storage of card details. Answers that are not correct affect the duty of disclosure under Article 7:928 of the Dutch Civil Code and the consequences of this in Article 7:930 of the Dutch Civil Code.
We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.
Cyber insurance
Compare
Get coveredThe structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Insurers weigh these details differently. That is where your saving is.
We look at the terms as well as the premium, and stay your point of contact when there is a claim.
We are not tied to one insurer and compare on the basis of an objective analysis of several companies.
You call or email someone who knows your file. No menu options, no changing call centres.
We cancel your old policy and align the start date, so you are never a day without cover.
We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
Four points that make the difference between a policy that pays out and one that does not.
If the card locks hang on the same system as the administration, an outage means that guests cannot get into their rooms and that you can no longer check anyone in. Ask your supplier to set out in writing how the locks behave during an outage and whether there is an offline emergency mode. Also put a manual procedure in place, because no policy will solve this part of the loss for you.
Availability and rates are passed on automatically to external channels. If that link stops working, you may end up overbooked or, conversely, keep rooms empty that could have been sold. That loss does not automatically fall under interruption cover, because technically turnover has continued. Discuss explicitly how loss of turnover is calculated in a partial failure of the distribution chain.
The largest item after a data breach is not the recovery but establishing who has been affected and informing those people. If you keep the entire history of stays, that means guests who slept here years ago and whom you have to reach by email or letter. A retention policy that clears out old data reduces that item directly and is viewed positively at the acceptance stage.
Not covered are fines of a punitive nature, replacing or upgrading your lock system afterwards and physical damage to equipment, which belongs under the business contents cover. Loss of turnover caused by an ordinary fault at a booking channel without an attack is usually excluded as well, as are intent and wilful recklessness under Article 7:952 of the Dutch Civil Code and incidents through vulnerabilities you knew about.
This is what people ask us most.
If their data was still in the system and has been affected, and the risk to them is high, the duty to inform applies to them as well. The forensic investigation determines which data was actually accessed. This is precisely the reason to clear out old stay histories actively. It reduces both the costs and the reputational damage.
If the cause is covered and the outage lasts longer than the waiting period, the lost turnover falls under the interruption cover. Additional costs of staying open, such as agency reception staff or issuing keys by hand, fall under the additional costs item only if that is included. Ask about it separately in the quote.
That depends on the division of roles in your agreement with that channel. For the data held in your own system you are the controller and you report it yourself. Set out contractually the period within which the channel must inform you, because your own 72 hours starts running as soon as you become aware of the breach.
As a rule, no. That cover requires physical damage to insured property as the cause of the interruption, such as fire or water damage. A hotel system taken down digitally does not meet that. The interruption cover of cyber insurance is intended for that, with its own waiting period and its own indemnity period.
Every situation is different. For these situations we have a separate page.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was compiled by Finass Verzekert (LinkedIn). Last updated on .
The information on this page is general in nature and is not personal advice.
Maandag- Vrijdag: 09:00- 17:00
We use cookies and similar technologies to improve your experience on our website.