Skip to main content



9,5/ Reviews

Cyber insurance for self-employed professionals

For a sole trader, cyber insurance is above all the purchase of help: the obligations under the GDPR apply in full, while there is no IT department and no lawyer in-house to meet them.

  • several insurers compared objectively
  • 9.5 customer rating for a new policy
  • AFM licence 12016589
  • Personal 072 - 509 24 56, weekdays 9–17

This page in another language: Nederlands

The calculator and the quote form below are in Dutch. Prefer to do this in English? Email info@finassverzekert.nl or call 072 - 509 24 56 and we will take it from there.

Work out for yourself what it would cost.

  • We compare the offerings of several insurers
  • An adviser checks whether the cover suits your activities
  • We arrange the switch, including cancellation

Request a quote

A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.

  • Independent advice
  • Several insurers
  • Switching arranged
  • Help with claims

In brief

You are the controller for the personal data you record, whatever your size. In the event of a data breach you have to report it to the Autoriteit Persoonsgegevens (the Dutch data protection authority) within 72 hours and, where the risk to those concerned is high, inform them as well. That means establishing within three days what data has been affected, whose it is and how. Alongside your ordinary work that simply cannot be done; the incident responseteam is therefore the most important component of this policy.

The cover falls into three items that must not be confused. First party: restoring your systems and files and the turnover you lose while you are down. Third party: liability towards customers and clients whose data has leaked. And the costs of the duty to report itself: forensic investigation, legal guidance and informing those concerned. With ransomware an extortion module is added, with its own conditions.

What you arrange yourself determines whether the cover holds up. In the application, insurers ask questions about multi-factor authentication, back-ups and updates, and attach conditions to them. Answers that are not correct affect the duty of disclosure under Article 7:928 of the Dutch Civil Code and the consequences of this in Article 7:930 of the Dutch Civil Code. If you supply IT services to others, professional indemnity cover belongs alongside it; see the package for self-employed professionals in IT.

Independent, personal, sorted quickly

We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.

Arranging cyber insurance through Finass VerzekertCyber insurance
Photo coming soon
Comparing cyber insurance premiums and coverCompare
Photo coming soon
Get cyber insurance sorted todayGet covered
Photo coming soon

What does cyber insurance for self-employed professionals cover?

The structure of the cover in three parts, with an overview per situation below.

Immediate help

Incident response

Specialists who look into it within hours.

  • 24/7 reporting line
  • Forensic investigation
  • Recovery and restart
Your business

Own damage

What the incident costs you yourself.

  • Data recovery and reconstruction
  • Business downtime
  • Ransom under consideration
Towards third parties

Liability

Claims from customers and data subjects.

  • Claims after a data breach
  • GDPR notification costs
  • Legal assistance

What is covered

SituationCyberAVBBAV
Ransomware brings your systems downYesNoNo
Data breach involving personal dataYesNoSometimes
Costs of notification and informing those affectedYesNoNo
Fraud through a falsified payment instructionSometimesNoNo
Administrative fine from the regulatorNoNoNo
Hardware that is physically damagedNoNoNo

This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.

What does your premium depend on?

  • Type and quantity of personal data. Contact details alone are rated differently from medical, financial or other special categories of data.
  • Your sector. Healthcare, financial services and IT attract more targeted attacks than, say, skilled trades.
  • Dependence on your systems. How quickly work stops when systems fail determines whether interruption cover is needed and how wide it should be.
  • Security measures taken. Multi-factor authentication, back-up strategy and update policy determine both acceptance and conditions.
  • Sum insured and waiting period. The limit per event and the number of hours before the interruption cover starts are separate choices.
  • Earlier incidents. An earlier data breach or ransom incident weighs heavily and often leads to additional requirements in advance.

Insurers weigh these details differently. That is where your saving is.

How we arrange it

  1. You request a quoteWe take stock of your activities, turnover and wishes.
  2. We compareseveral insurers, on premium as well as conditions.
  3. You receive a proposalWith an explanation of the differences and the exclusions.
  4. We arrange the switchIncluding cancellation, so there is no gap in cover.

Request a quote

Why arrange it through Finass Verzekert?

We look at the terms as well as the premium, and stay your point of contact when there is a claim.

Independent

We are not tied to one insurer and compare on the basis of an objective analysis of several companies.

One fixed adviser

You call or email someone who knows your file. No menu options, no changing call centres.

Switching without hassle

We cancel your old policy and align the start date, so you are never a day without cover.

Help with claims

We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.

9.5New policy
9.8Claims handling

Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.

View the reviews at NH1816 · all reviews on our site

Where things go wrong in practice

Four points that make the difference between a policy that pays out and one that does not.

The duty to report costs time you do not have

The 72-hour period starts running as soon as you become aware of the breach, not as soon as you have worked it out. In those days you have to establish the extent, draw up the report and, where necessary, inform customers, while your current work carries on. For a sole trader, access to forensic investigators and a privacy lawyer is therefore more valuable than the level of the sum insured.

Fraud is something other than hacking

A copied invoice with a changed bank account number, an email that appears to come from your client, a payment request you carry out yourself: in these cases there has been no break-in, you made the transfer. Many cyber policies cover only attacks on your systems and leave these social engineering out of account, or include them in a separate module with a lower limit. Check that point expressly in the quote.

Your security is a condition of cover

Multi-factor authentication on email and cloud storage, a back-up that is kept disconnected and has demonstrably been restored, and updates installed on time often appear as a warranty clause in the policy. If they are not in place at the time of the incident, the insurer may reduce the payout. So complete the questionnaire carefully and report any change in the way you work.

What falls outside the cover

Not covered are improvements to your security afterwards, equipment itself that is stolen or damaged, which falls under the business contents cover, fines in so far as they are not insurable under Dutch law, and intent or wilful recklessness under Article 7:952 of the Dutch Civil Code. Attacks arising from a vulnerability you knew about and left unaddressed, and damage caused by acts of war or state actors, are also excluded.

Frequently asked questions

This is what people ask us most.

Does the GDPR apply to a sole trader without staff?

Yes. The GDPR makes no exception for company size. As soon as you process personal data, from customer addresses to a membership list, you are the controller with all the duties that go with it. That means a record of processing activities, agreements with the parties that process data for you, and in the event of a data breach the report to the Autoriteit Persoonsgegevens within 72 hours.

My client requires a data processing agreement. What does that mean?

It means you process data on his instructions, and that agreement sets out what you may do with the data, what security you apply and within what period you report a breach to him. That period is usually shorter than 72 hours. Set such agreements alongside your policy, because they help determine what you can be held liable for.

Does the insurer pay a ransom after a ransomware attack?

Only if an extortion module is included, and then only after consultation and prior consent. Conditions apply under sanctions legislation and the insurer first brings in negotiators and investigators. Payment also gives no certainty that you will get your data back. A disconnected and tested back-up remains the only reliable way out.

I work entirely in the cloud. Do I still need this?

Yes. Responsibility for the data stays with you, even if a supplier provides the storage. If your account is taken over or the service is down for days, that is your problem towards your customers. The policy covers your own interruption and the duty to report; under his terms the supplier usually pays little more than part of the subscription.

Ready to compare?

Request a quote without obligation. We will look at which insurer best matches your activities and your risk.

Request a quote

Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.

About our service

Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.

You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.

This page was compiled by Finass Verzekert. Last updated on .

The information on this page is general in nature and is not personal advice.