Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
Customer systems · access · supply chain risk
Anyone who manages other companies' systems is left, after a break-in, not with one loss but with the loss of every customer connected to that management access.
Deze pagina in het Nederlands: Cyberverzekering voor IT-bedrijven.
The calculator and the quote form below are in Dutch. Prefer to do this in English? Email info@finassverzekert. nl or call 072 - 509 24 56 and we will take it from there.
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
An IT company usually processes little personal data itself. The risk lies in the management layer: your RMM tooling, your password vault, the VPN connections and the administrator accounts you hold in every customer environment. Anyone who gets in there is not in one network but in dozens at once, with rights nobody has to work around.
As a result, the emphasis of your policy lies not on recovering your own data but on liability. Your customers claim their downtime, their recovery costs and their own data breach costs from you, partly under the management agreement and partly under Article 6:162 of the Dutch Civil Code. Your sum insured has to be able to carry those claims added together, not those of one customer.
If you build software yourself or manage websites rather than infrastructure, also look at the cyber insurance for software companies, the version for hosting companies or the one for web agencies.
The structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Four points that make the difference between a policy that pays out and one that does not.
At an IT company, insurers look above all at how your management environment is arranged: separate administrator accounts per customer, two-factor authentication on the password vault and on the RMM console, and management work that is not done from an ordinary office account. What you state about this on the application is a disclosure within the meaning of Article 7:928 DCC. If it turns out afterwards that the stated measure was not in place, the insurer can invoke Article 7:930 DCC and pay less or nothing.
At management companies the size of a claim is rarely determined by the attack but by your contract. If you have limited liability per event and per year, that is your ceiling. If you have not, it is up to the court. Note that liability which you took on contractually without having it in law, such as penalty clauses in an SLA and guaranteed availability percentages, is excluded on almost every cyber policy.
If after an incident you have to run a migration again, put right a wrongly configured firewall or spend hours correcting something you should have done properly yourself, those are costs of re-performing your own work. They fall outside the cover. The policy pays the customer's loss, not your own unpaid hours. Intent and wilful recklessness on your part or that of a director are also excluded, as Article 7:952 DCC allows.
For your customers you are usually the processor. If you discover an incident, you have to inform the clients concerned without undue delay, because they are the ones who have to report to the Autoriteit Persoonsgegevens (the Dutch data protection authority) within 72 hours. Towards your insurer the duty to report under Article 7:941 DCC applies: report as soon as you become aware of it. Reporting late costs the insurer evidence and scope for investigation and may affect your right to a payout.
Insurers weigh these details differently. That is where your saving is.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
This is what people ask us most.
That is exactly what the liability section is for: loss suffered by third parties because their data or their operations were affected through your systems. Your sum insured does, however, apply per insurance year for all customers together. In an incident affecting dozens of environments, that is the point at which too small a sum hurts. So set the sum against the largest simultaneous outage you can imagine, not against one customer.
Recovery at your customers that results from the incident can count as loss; hours you spend correcting your own error or your own delivery do not. Insurers separate recovery of third-party loss from re-performing your own work. So during an incident, record which hours are attributable to which customer and which cause; reconstructing that afterwards rarely works.
Your client, because he is the controller. Your obligation is to inform him without delay as soon as you know of the breach, so that he meets his deadline. When it comes to it you often carry out the reporting for him. The costs of that reporting process and of informing those concerned fall under the notification costs cover, provided you reported the incident to the insurer in good time.
Usually yes. The cyber policy works from a security incident: a break-in, ransomware, a data breach. Wrong advice, a migration you planned badly or a system you deliver in an unsound state without any attack being involved belongs with professional indemnity. When advising, we look at how the two policies join up, so that nothing falls between them.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was written and checked by an adviser at Finass Verzekert. Last updated on .
The information on this page is general in nature and is not personal advice.
Verzekeringen:
/
Huis en gezin
Opstalverzekering
Inboedelverzekering
Aansprakelijkheid
Rechtsbijstand
Gezinsongevallen
Kostbaarheden
Zorgverzekering
/
Verkeer
Autoverzekering
Klassieker
Oldtimer
Bestelauto
Scooterverzekering
Motorverzekering
Kampeerauto
Caravan
Qaud/ trike/ mp3
Aanhangwagen
Scootmobiel/ Segway
Fietsverzekering
/
Recreatie
Kortlopende reis
Doorlopende reis
Annulering
Recreatiewoning/ chalet
Pleziervaartuig
Golfverzekering
Vakantiehuis
/
Verzekeringspakket
Particulieren verzekeringspakket
Exclusief-verzekeringspakket
/
Exclusieve-verzekeringen
Autoverzekering
Jachtverzekering
Opstalverzekering
Inboedelverzekering
Kostbaarheden
Verzekeringen:
/
Aansprakelijkheid en overige varia
Bedrijfsaansprakelijkheid
Beroepsaansprakelijkheid
Bestuurdersaansprakelijkheid
CAR-verzekering
Cyberverzekering
WEGAS/ WEGAM
Rechtsbijstand
Evenementen
/
Bedrijfsmiddelen
Bedrijfsschade
Geldverzekering
Opstalverzekering
Extra kosten
Milieuschade
Machinebreuk
Inventaris
Garageverzekering
/
Transport en zakenreis
Vervoer van eigen zaken
Goederentransport
Individuele zakenreis
Collectieve zakenreis
Container/ trailer
/
Verkeer
Personenauto
Bestelauto
Motor
Werkmaterieel
Aanhangwagen
Vrachtauto
Taxiverzekering
Oldtimer
Wagenpark
/
Ziekte en arbeidsongeschiktheid
Arbeidsongeschiktheid
Verzuimverzekering
/
pakketten
MKB-pakket
Verzekeringen:
/
Aansprakelijkheid en overige varia
Aansprakelijkheidsverzekering ZZP
Beroepsaansprakelijkheid ZZP
Bouw en Montage verzekering ZZP
Rechtsbijstandverzekering ZZP
/
Bedrijfsmiddelen
Inventaris- en Goederenverzekering ZZP
Eigen Vervoerverzekering ZZP
/
Pakketten
Verzekeringspakket ZZP
Verzekeringen:
/
Aansprakelijkheid en overige varia
Aansprakelijkheid VVE
Bestuurdersaansprakelijkheid VVE
Ongevallenverzekering VVE
Rechtsbijstandverzekering VVE
/
Bedrijfsmiddelen
Gebouwenverzekering VVE
Glasverzekering VVE
Milieuschadeverzekering VVE
Eigenaarsbelang vve opstalverzekering
Slapende vve opstalverzekering
VvE verzekering eigen huis
VvE inboedelverzekering
/
pakketten
VvE-pakket
Verzekeringen:
/
Aansprakelijkheid en overige varia
Aansprakelijkheid
Bestuurdersaansprakelijkheid
/
Bedrijfsmiddelen
Bedrijfsgebouwen
Glasverzekering
Glas kantoren/ flat en woonhuis in de verhuur
Verhuurde woonhuizen
Inventaris / Goederen / Huurdersbelang
Milieuschadeverzekering
/
Special
Studentenhuis
Kamerverhuur
Hotel
Horecapand
Kantoorpand
Grachtenhuis
Tweede woning
Vakantiewoning
Rijksmonument
Bedrijfsverzamelgebouw
Fundering
Beleggingspand
Loods
Garage
Finass Verzekert is een handelsnaam van Finass Advies B.V.
KvK-nummer 37131781
Maandag - Vrijdag: 09:00 - 17:00
We use cookies and similar technologies to improve your experience on our website.