Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
An insurance broker is itself a link in the claims process: if your system goes down, your client cannot report a claim and runs up against the deadlines of his own policy.
This page in another language: Nederlands
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
Your portfolio holds a complete financial picture of every client: what risks someone runs, what sums are set against them, what claims there have been and sometimes health data from an application for an income or life cover product. That combination is attractive to an attacker, because it is usable outside your office as well. In the event of a breach, the duty to report to the Autoriteit Persoonsgegevens (the Dutch data protection authority) within 72 hours applies and, depending on the risk, the duty to inform your clients themselves.
What sets this type of firm apart is the duty of care during the outage. A policyholder has to report a claim as soon as it is reasonably possible to do so; Article 7:941 of the Dutch Civil Code attaches consequences to being late. If you are his only point of contact and that point is unreachable, the question is who bears the loss. A fallback procedure, call diversion and a documented arrangement for urgent notifications are not only business continuity here but also a way of limiting liability.
Think too of your role in the message traffic with insurers and of the premium collection you may handle yourself. If a change or collection file is manipulated, that is not a data breach but a fraud matter with its own module and its own limit. Also discuss how the cyber cover relates to your professional indemnity insurance: the complaint that cover was not arranged in time is assessed there and not on the cyber policy.
We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.
Cyber insurance
Compare
Get coveredThe structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Insurers weigh these details differently. That is where your saving is.
We look at the terms as well as the premium, and stay your point of contact when there is a claim.
We are not tied to one insurer and compare on the basis of an objective analysis of several companies.
You call or email someone who knows your file. No menu options, no changing call centres.
We cancel your old policy and align the start date, so you are never a day without cover.
We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
Four points that make the difference between a policy that pays out and one that does not.
At most businesses an outage costs turnover; at yours it costs someone else their cover. If a client cannot report a claim or pass on a change in time, he can hold you responsible for the loss he suffers with his insurer as a result. Set out how you remain reachable during an outage and how you record notifications, and keep that evidence. Without it, it becomes your word against his afterwards.
Your files hold the information the client provided when applying, including health and claims history. That is precisely the basis on which the duty of disclosure under Article 7:928 of the Dutch Civil Code and its consequences under Article 7:930 of the Dutch Civil Code are later assessed. If those records are damaged or lost beyond repair, you lose the evidence of what was asked and answered at the time. So include the reconstruction of files in the data recovery cover.
If you collect premiums or forward changes to insurers, money moves and payment instructions pass through your office. A changed bank account number or an instruction sent in your name is deception, not a break-in, and falls outside ordinary cyber cover. Ask for a separate module for fraud and social engineering, with a limit that matches the amounts that actually pass through you.
Not covered are administrative fines of a punitive nature, the amount an insurer deducts from your client because a notification came too late, and improvements to your systems afterwards. Also excluded are loss of commission income beyond the agreed indemnity period, physical damage to equipment, and intent or wilful recklessness under Article 7:952 of the Dutch Civil Code are not included.
This is what people ask us most.
If your client's insurer reduces the payout because the claim was reported late, he will hold you responsible. That is pure financial loss arising from a complaint about your service and is assessed on the professional indemnity insurance (BAV). The cyber policy pays for your own recovery, the investigation and the interruption, not for your client's reduced payout.
Alongside the report to the Autoriteit Persoonsgegevens, there are arrangements with the insurers for which you act as intermediary or hold a binding authority. Those are set out in your cooperation or binding authority agreement. If an incident runs through your system links, they expect to be told. Go through those obligations in advance with the insurer of your cyber policy.
No. Professional indemnity insurance covers claims about your advice and intermediary work. The cyber policy covers your own recovery costs, the costs of the duty to report, the business interruption and claims arising specifically from a data breach. The two respond at different moments in the same incident; have the join checked in advance.
Responsibility for the data stays with your firm. The most common incident is a compromised staff account, not a break-in at the supplier. You also carry the risk that the package is unreachable for days. The supplier's terms usually pay no more than part of the subscription for that.
Every situation is different. For these situations we have a separate page.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was compiled by Finass Verzekert (LinkedIn). Last updated on .
The information on this page is general in nature and is not personal advice.
Maandag- Vrijdag: 09:00- 17:00
We use cookies and similar technologies to improve your experience on our website.