Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
For a webshop the checkout page is both your engine of turnover and the most attractive target: every hour it does not work is directly measurable loss.
This page in another language: Nederlands
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
A webshop has no alternative channel. If the site is down through ransomware, a denial-of-service attack or a failed integration, there is no counter where customers can still pay. The loss of turnover is, moreover, unusually easy to prove, because you have the turnover per hour from the same weeks last year. That makes the conversation about business interruption cover more concrete than in most sectors.
There is also a customer file with addresses, order history and account details, and payment traffic runs through your payment service provider. The most dangerous attack is not the visible one: in skimming a piece of script is added to your checkout page that reads payment details as they are entered while the shop simply carries on running, sometimes for weeks before anyone notices.
If you mainly sell in a physical shop with a webshop alongside it, also look at the cyber insurance for shops; if your shop is built and maintained by an agency, the web agency version is relevant for that party.
We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.
Cyber insurance
Compare
Get coveredThe structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Insurers weigh these details differently. That is where your saving is.
We look at the terms as well as the premium, and stay your point of contact when there is a claim.
We are not tied to one insurer and compare on the basis of an objective analysis of several companies.
You call or email someone who knows your file. No menu options, no changing call centres.
We cancel your old policy and align the start date, so you are never a day without cover.
We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
Four points that make the difference between a policy that pays out and one that does not.
An attacker who gets in through an outdated extension does not need to take your shop down: he adds code that reads payment and address details at checkout. Orders keep coming, you notice nothing, and the number of people affected grows by the day. Check the integrity of your checkout page and keep track of when you updated extensions. Insurers exclude loss arising from vulnerabilities for which a patch had been available for some time.
Business interruption cover pays for lost turnover, but almost always only after a waiting period of a number of hours or a day. Many outages last exactly that long and then produce nothing. So discuss in advance what waiting period applies, how turnover is calculated during a seasonal peak and whether additional costs of getting back online sooner are reimbursed. Also ask whether failure at your hosting provider or payment service provider is included.
Fraudulent orders using stolen payment details, chargebacks by the payment service provider and fines from the card schemes fall outside cyber cover. That is trading risk, not data loss. Stock stolen or not delivered belongs with your goods or transport insurance. And an administrative fine from the Autoriteit Persoonsgegevens (the Dutch data protection authority) is not insurable. What is covered is forensic investigation, recovery, notification costs and the claims of customers whose data has leaked.
A shop rarely stands alone: there is a stock system, a parcel carrier, an accounting link and often a sales channel on a marketplace. If one link drops out, orders keep coming in that you cannot fulfil, with complaints and cancellations as a result. Map out which links are business-critical and what manual fallback exists; that determines how much loss caused by downtime an incident actually produces.
This is what people ask us most.
Only if the cause is a covered security incident and the outage lasted longer than the waiting period in the policy. An ordinary fault at your host is usually covered only if you included that extension. When an incident occurs, keep your turnover figures for comparable days. The loss is calculated on that basis and not on an estimate made afterwards.
No. Fraudulent orders and chargebacks are trading risk and fall outside cyber insurance. That covers loss arising from a security incident in your own environment: investigation, recovery, downtime and liability after a data breach. For payment fraud on the sales side, the arrangements with your payment service provider are decisive, together with the checks you build into the ordering process.
Yes, considerably, because card details then do not pass through your own environment. The risk does not disappear: address, account and order details still sit with you and an attacker can still redirect visitors to a copied page. Insurers do reward this set-up in their assessment. State exactly how your checkout process works in the application.
As a rule, yes. With payment and identity details the risk to those concerned is high, and then the GDPR requires a message to the customer as well as the report to the regulator. The costs of that process fall under the notification costs cover. The condition is that you reported the incident to the insurer in good time, as Article 7:941 of the Dutch Civil Code requires.
Every situation is different. For these situations we have a separate page.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was compiled by Finass Verzekert (LinkedIn). Last updated on .
The information on this page is general in nature and is not personal advice.
Maandag- Vrijdag: 09:00- 17:00
We use cookies and similar technologies to improve your experience on our website.