Skip to main content
Laagste Prijs Garantie
Hoge Pakketkorting
Grootste Aanbod
Hulp bij Schade
Persoonlijk Contact
100% Onafhankelijk



Customer systems · access · supply chain risk

Cyber insurance for IT companies

Anyone who manages other companies' systems is left, after a break-in, not with one loss but with the loss of every customer connected to that management access.

  • several insurers compared objectively
  • 9.5 customer rating for a new policy
  • AFM licence 12016589
  • Personal 072 - 509 24 56, weekdays 9–17

Deze pagina in het Nederlands: Cyberverzekering voor IT-bedrijven.

The calculator and the quote form below are in Dutch. Prefer to do this in English? Email info@finassverzekert. nl or call 072 - 509 24 56 and we will take it from there.

Work out for yourself what it would cost.

  • We compare the offerings of several insurers
  • An adviser checks whether the cover suits your activities
  • We arrange the switch, including cancellation

Request a quote

A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.

Gewenste dekkingen
Verhuurde woningen / objecten
Object 1
Aanvullende objectgegevensOpen
Specifieke vastgoedvragen tonen we hier compact onder.
Vul dit in namens de VvE. Vragen die niet van toepassing zijn kun je overslaan.
Gewenste dekkingen
Straatnaam met huisnummerreeks, bijvoorbeeld Voorbeeldstraat 1 t/m 45.
Alle rechten samen: woningen, bedrijfsruimten, parkeerplaatsen en bergingen.
Staat in het taxatierapport of de herbouwwaardemeter. Weet je het niet, vul dan een schatting in en geef dat aan bij de opmerkingen.
Gebruik binnen het complex
Schades aan het complex in de afgelopen 5 jaar?
Is het complex nu verzekerd?
Wordt er gefrituurd of met open vuur gewerkt?
Is er een sprinkler- of blusinstallatie?
Schades afgelopen 5 jaar
Schade 1
Taxatie conform artikel 7:960 BW?
Soort verhuur
Zijn de panelen gekeurd (bijvoorbeeld SCIOS Scope 12)?
Zijn er extra maatregelen tegen brand?
Is er een onderhoudscontract?
Is er een asbestinventarisatie?
Is de tank gesaneerd of gecertificeerd?
Is er funderingsonderzoek gedaan?
Aanvullende gegevens over het complex Open
Hoe vollediger dit is, hoe minder we hoeven na te vragen.
Is er een recent taxatierapport?
Is er een meerjarenonderhoudsplan (MJOP)?
Is er een reservefonds?
Worden er appartementen verhuurd?
Staat er iets leeg?
Liggen er zonnepanelen op het complex?
Zijn er laadpunten voor elektrische auto's?
Is er een lift?
Is er asbest aanwezig?
Is er een olie- of gastank aanwezig?
Zijn er funderingsproblemen bekend?
Heeft het complex een monumentale status?
Heeft de VvE personeel in dienst?
Brandveiligheid in het complex
Beveiliging
Gemeenschappelijke installaties
Is er een kelder of souterrain?
Is er eerder wateroverlast geweest in kelder of garage?
Dakbedekking
Splitsingsakte, MJOP, taxatierapport, huidig polisblad of schadeoverzicht. Meerdere bestanden mogelijk.
Meerdere verzekerde locaties?
Aanwezige beveiliging en preventie
Doormelding naar alarmcentrale?
Blusmiddelen jaarlijks onderhouden?
Brandmelding doorgemeld?
Aanvullende gegevens Open
Relevante certificaten of vakbekwaamheid
Werk uitbesteed aan zzp'ers of onderaannemers?
Producten vervaardigen, importeren of leveren?
Werkzaamheden buiten Nederland?
Omzet of werkzaamheden in VS/Canada?
Bijzondere werkzaamheden
Lid van brancheorganisatie?
%
Aansprakelijkheidsverzekering onderaannemers verplicht?
Komt de volledige jaaromzet uit deze professionele dienstverlening?
Algemene voorwaarden met aansprakelijkheidsbeperking?
Werk door zzp'ers of onderaannemers?
Werkzaamheden of opdrachtgevers buiten Nederland?
Quality assurance / kwaliteitsmanagement toegepast?
Permanente educatie voor gekwalificeerde medewerkers?
%
Afspraken over aansprakelijkheid vastgelegd?
Houdt één persoon/familie/organisatie meer dan 15% van de aandelen?
Aandelen beursgenoteerd of anders publiek verhandelbaar?
Afgelopen 18 maanden overname, oprichting of fusie geweest?
Eerder bestuurdersaansprakelijkheidsverzekering gehad?
D&O-verzekering ooit geweigerd of opgezegd?
Dochterondernemingen buiten Nederland?
Achterstanden, convenantbreuk of herfinancieringsprobleem?
Overname, verkoop, reorganisatie of surseance voorzien?
Gewenste modules
Lopend of dreigend conflict?
Risico op vestigingsadres?
Geheel of gedeeltelijk verhuurd?
Leegstand of verbouwing?
Zonnepanelen aanwezig?
Open vuur of brandgevaarlijke werkzaamheden in pand?
Aanvullende gegevens Open
Zaken op vestigingsadres?
Diefstalgevoelige of kostbare goederen?
Brandbare of gevaarlijke stoffen opgeslagen?
Sterk afhankelijk van locatie, machine, leverancier of afnemer?
Continuïteits- of uitwijkplan aanwezig?
Onderhouds- of servicecontract?
Eigen server- of technische ruimte?
Werkmaterieel / machines
Machine 1
Zelfrijdend?
Gebruik op openbare weg?
Diefstalbeveiliging
Aanvullende machinegegevensOpen
Extra technische of acceptatievragen tonen we hier compact onder.
Gewenste dekking
Wijze van vervoer
Tijdelijke opslag tijdens transport?
Activiteiten
Gebruikte vervoersvoorwaarden
Vervoer uitbesteed aan ondervervoerders?
Opslag van goederen van derden?
%
Voertuiggegevens
Voertuig 1
Aanvullende voertuiggegevensOpen
Niet verplicht, maar hoe vollediger dit is, hoe scherper de premie-indicatie.
Soort voertuigen
Eigendomssituatie
Gebruik
Regelmatige bestuurders jonger dan 24?
Aanvullende gegevens Open
Voor scooters, bromfietsen, brommobielen en motoren op bedrijfsnaam.
Voertuiggegevens
Voertuig 1
Aanvullende voertuiggegevensOpen
Wordt er mee bezorgd of gekoerierd?
Wie rijden er?
Wat wil je meeverzekeren?
Garageactiviteiten
Komt de volledige jaaromzet uit garageactiviteiten?
Branche-aansluiting of certificering
Proefritten of voertuigen halen/brengen?
Las-, slijp- of ander brandgevaarlijk werk?
Activiteiten vanuit een bedrijfspand?
Soorten gegevens
Bedrijfskritische systemen/data in de cloud?
MFA op e-mail, beheeraccounts en externe toegang?
Gescheiden/offline back-ups aanwezig?
Back-ups periodiek getest?
Vast patch- en updatebeleid?
Cyberincidenten afgelopen 5 jaar?
Niet-ondersteunde / legacy software aanwezig?
Gedocumenteerd incident-responseplan aanwezig?
Gevaarlijke/bodembedreigende stoffen?
Boven- of ondergrondse tanks?
Benodigde vergunningen/meldingen aanwezig?
Recent bodemonderzoek beschikbaar?
Ondergrondse leidingen, putten of andere procesvoorzieningen?
Procesafvalwater of relevante luchtemissies?
%
Nu werknemers langer dan 4 weken ziek?
Contractvormen personeel
Aanvullende gegevens Open
Gewenste dekking
Huidige collectieve WIA/WGA-regeling?
Nu WGA-eigenrisicodrager?
Reisgebied
Gewenste dekkingen
Ander luchtvervoer dan reguliere lijnvluchten?
Fysiek/risicovol werk tijdens zakenreis?
Huidige collectieve zakelijke reisverzekering?
Tijdelijke krachten/zzp'ers/stagiairs meeverzekeren?
BHV'ers aanvullend meeverzekeren?
Verzekerden woonachtig in het buitenland?
Werkzaamheden zoals hoogte ≥4m, offshore, duiken of hulpdiensten?
Verzekerden met jaarsalaris boven €250.000?
Regelmatig werk in het buitenland?
Wijze van verkeersdeelname
Zakelijk verkeer in buitenland?
Komt de volledige jaaromzet uit bouw- of montagewerk?
Werk aan/in/nabij bestaande eigendommen?
Heiwerk, bronbemaling, grondwerk of leidingen?
Verantwoordelijk voor ontwerp/berekeningen?
Werk door onderaannemers?
%
Podia, tenten, tribunes of tijdelijke installaties?
Alcoholverstrekking?
Annuleringsdekking gewenst?
Aanvragen als
Staat op je KVK-uittreksel en op facturen. Acht cijfers, zonder punten of spaties.
Een VvE vult hier de jaarlijkse begroting of het totaal aan bijdragen in.
Nu al zakelijk verzekerd?
Zakelijke schades/claims afgelopen 5 jaar?
Verzekering ooit geweigerd/opgezegd?
Mededelingsplicht
Ben jij, of iemand anders die bij deze verzekering belang heeft, in de afgelopen 8 jaar in aanraking geweest met politie of justitie?
Denk aan een verdenking, boete, transactie, taakstraf of veroordeling. Verkeersboetes tot 300 euro hoef je niet te melden.
Is er ooit een verzekering opgezegd, geweigerd of beëindigd wegens fraude, of sta je geregistreerd in het incidentenregister?
Andere bekende omstandigheden die mogelijk tot een claim leiden?
Vermeld het jaar, wat er speelde en hoe het is afgehandeld. Dit betekent niet automatisch dat je niet verzekerd kunt worden.

In brief

An IT company usually processes little personal data itself. The risk lies in the management layer: your RMM tooling, your password vault, the VPN connections and the administrator accounts you hold in every customer environment. Anyone who gets in there is not in one network but in dozens at once, with rights nobody has to work around.

As a result, the emphasis of your policy lies not on recovering your own data but on liability. Your customers claim their downtime, their recovery costs and their own data breach costs from you, partly under the management agreement and partly under Article 6:162 of the Dutch Civil Code. Your sum insured has to be able to carry those claims added together, not those of one customer.

If you build software yourself or manage websites rather than infrastructure, also look at the cyber insurance for software companies, the version for hosting companies or the one for web agencies.

Laagste prijs garantie
Grootste aanbod
Hulp bij schade
Persoonlijk contact
100% onafhankelijk


What does cyber insurance for IT companies cover?

The structure of the cover in three parts, with an overview per situation below.

Immediate help

Incident response

Specialists who look into it within hours.

  • 24/7 reporting line
  • Forensic investigation
  • Recovery and restart
Your business

Own damage

What the incident costs you yourself.

  • Data recovery and reconstruction
  • Business downtime
  • Ransom under consideration
Towards third parties

Liability

Claims from customers and data subjects.

  • Claims after a data breach
  • GDPR notification costs
  • Legal assistance

What is covered

SituationCyberAVBBAV
Ransomware brings your systems downYesNoNo
Data breach involving personal dataYesNoSometimes
Costs of notification and informing those affectedYesNoNo
Fraud through a falsified payment instructionSometimesNoNo
Administrative fine from the regulatorNoNoNo
Hardware that is physically damagedNoNoNo

This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.

Where things go wrong in practice

Four points that make the difference between a policy that pays out and one that does not.

Your management access is the real question on the policy

At an IT company, insurers look above all at how your management environment is arranged: separate administrator accounts per customer, two-factor authentication on the password vault and on the RMM console, and management work that is not done from an ordinary office account. What you state about this on the application is a disclosure within the meaning of Article 7:928 DCC. If it turns out afterwards that the stated measure was not in place, the insurer can invoke Article 7:930 DCC and pay less or nothing.

What your customers can claim is set out in your own terms

At management companies the size of a claim is rarely determined by the attack but by your contract. If you have limited liability per event and per year, that is your ceiling. If you have not, it is up to the court. Note that liability which you took on contractually without having it in law, such as penalty clauses in an SLA and guaranteed availability percentages, is excluded on almost every cyber policy.

Redoing your own work is not an insured loss

If after an incident you have to run a migration again, put right a wrongly configured firewall or spend hours correcting something you should have done properly yourself, those are costs of re-performing your own work. They fall outside the cover. The policy pays the customer's loss, not your own unpaid hours. Intent and wilful recklessness on your part or that of a director are also excluded, as Article 7:952 DCC allows.

Pass reports on in time as a processor

For your customers you are usually the processor. If you discover an incident, you have to inform the clients concerned without undue delay, because they are the ones who have to report to the Autoriteit Persoonsgegevens (the Dutch data protection authority) within 72 hours. Towards your insurer the duty to report under Article 7:941 DCC applies: report as soon as you become aware of it. Reporting late costs the insurer evidence and scope for investigation and may affect your right to a payout.

What does your premium depend on?

  • Number of customer environments managed. How many organisations are reachable through one compromised management account determines the maximum accumulation.
  • Set-up of management access. Two-factor authentication on RMM and the password vault, separate management accounts per customer, and management work kept apart from office work.
  • Turnover from management and support contracts. Recurring management turnover weighs more heavily than turnover from one-off hardware supplies.
  • Limitation of liability in your terms. A limit per event and per year caps what customers can recover from you and with it your exposure.
  • State of back-up and recovery at your customers. Offline or immutable back-ups that you demonstrably test shorten the downtime you have to compensate.
  • Dependence on underlying suppliers. If you run customer work on third-party cloud or hosting services, an outage at that party counts in your risk.

Insurers weigh these details differently. That is where your saving is.

How we arrange it

  1. You request a quoteWe take stock of your activities, turnover and wishes.
  2. We compareseveral insurers, on premium as well as conditions.
  3. You receive a proposalWith an explanation of the differences and the exclusions.
  4. We arrange the switchIncluding cancellation, so there is no gap in cover.

Request a quote

9.5New policy
9.8Claims handling

Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.

View the reviews at NH1816 · all reviews on our site

Frequently asked questions

This is what people ask us most.

Are my customers' claims covered if the attack came in through me?

That is exactly what the liability section is for: loss suffered by third parties because their data or their operations were affected through your systems. Your sum insured does, however, apply per insurance year for all customers together. In an incident affecting dozens of environments, that is the point at which too small a sum hurts. So set the sum against the largest simultaneous outage you can imagine, not against one customer.

Does the policy pay for the hours my team spends putting everything right?

Recovery at your customers that results from the incident can count as loss; hours you spend correcting your own error or your own delivery do not. Insurers separate recovery of third-party loss from re-performing your own work. So during an incident, record which hours are attributable to which customer and which cause; reconstructing that afterwards rarely works.

I am a processor. Who has to report the data breach to the Autoriteit Persoonsgegevens?

Your client, because he is the controller. Your obligation is to inform him without delay as soon as you know of the breach, so that he meets his deadline. When it comes to it you often carry out the reporting for him. The costs of that reporting process and of informing those concerned fall under the notification costs cover, provided you reported the incident to the insurer in good time.

Do I still need professional indemnity insurance alongside this?

Usually yes. The cyber policy works from a security incident: a break-in, ransomware, a data breach. Wrong advice, a migration you planned badly or a system you deliver in an unsound state without any attack being involved belongs with professional indemnity. When advising, we look at how the two policies join up, so that nothing falls between them.

Ready to compare?

Request a quote without obligation. We will look at which insurer best matches your activities and your risk.

Request a quote

Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.

About our service

Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.

You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.

This page was written and checked by an adviser at Finass Verzekert. Last updated on .

The information on this page is general in nature and is not personal advice.