Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
Source code · customer systems · supply chain risk
A software company supplies not only a product but also the channel through which an infection reaches all users at once.
Deze pagina in het Nederlands: Cyberverzekering voor softwarebedrijven.
The calculator and the quote form below are in Dutch. Prefer to do this in English? Email info@finassverzekert. nl or call 072 - 509 24 56 and we will take it from there.
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
Where other companies suffer an attack, a software company can distributeit. Anyone who reaches your build environment, your package repository or your signing keys does not need to break into your customers: your own update mechanism carries the code inside, past the firewall your customer had in place for exactly this purpose.
That shifts the emphasis to liability and to the question of what your licence and supply terms say. Users claim for downtime, data loss and their own recovery costs. Where a defective product causes loss to others, Article 6:185 of the Dutch Civil Code also comes into play, alongside the ordinary basis in tort in Article 6:162 DCC.
If you mainly manage customers' systems rather than distributing your own product, the cyber insurance for IT companies fits better; if you run the underlying infrastructure yourself, look at the one for hosting companies.
The structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Four points that make the difference between a policy that pays out and one that does not.
The questions an insurer asks a software company are rarely about your office network and almost always about the route from source code to customer: who can deploy to production, is there two-factor authentication on the repository, are builds signed and is there separation between development, test and production environments. Are third-party dependencies clearly documented? What you state about this is a disclosure within the meaning of Article 7:928 of the Dutch Civil Code and determines whether the cover holds up after an incident.
Cyber policies cover loss arising from a security incident. A functional error leading to wrong calculations is a professional error and belongs with professional indemnity. A vulnerability exploited by third parties sits in between: cover then depends on whether you took up the report and patched it in time. Known, unremedied vulnerabilities are excluded at many insurers. So document when you received a report and what you did with it.
Availability guarantees, penalty clauses for late delivery and promised repair periods increase the claim without increasing the insurance. Liability accepted contractually that goes beyond liability in law, and penalties under a contract, are excluded on almost every cyber policy. Rebuilding or re-delivering your own software after an incident is not an insured loss either. The policy pays the loss suffered by your customers, not your own development hours.
Two things leak more often at software companies than the production environment: the repository with source code and keys, and test environments holding real customer data because that made testing easier. The first is a trade secret and rarely replaceable. The second makes you, without any legal basis, the processor of data you did not need. Anonymise test data and scan your repository for keys committed by mistake; insurers ask expressly about the use of production data outside production.
Insurers weigh these details differently. That is where your saving is.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
This is what people ask us most.
If the infection results from a break-in in your environment, liability towards affected customers falls under the cover in principle, together with the forensic investigation and the crisis communication. The limiting factors are the sum insured per year, which applies to all customers together, and penalty clauses in your contracts. Developing and rolling out a clean version again is your own cost.
In principle yes, because there too there is a security incident. What matters is whether the vulnerability was already known and could have been remedied. Insurers exclude loss arising from vulnerabilities for which a patch had been available for a long time. So keep track of which external components you use and when you updated them. That overview is your most important document when a claim arises.
No. A calculation error, a missed specification or an implementation that does not do what was agreed is a professional error without a security incident. Those claims belong with professional indemnity. The cyber policy picks up where an attack, ransomware or a data breach lies behind the loss. The two policies exclude each other's territory, so the join has to be checked deliberately when taking out cover.
Yes, because you then carry the availability risk alongside the product risk and are usually the processor of your customers' data. An outage of your service then becomes business interruption at dozens of customers at once, and a breach in your environment is a breach of their data. State this expressly in the application. It determines both the premium and the sum insured you need.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was written and checked by an adviser at Finass Verzekert. Last updated on .
The information on this page is general in nature and is not personal advice.
Verzekeringen:
/
Huis en gezin
Opstalverzekering
Inboedelverzekering
Aansprakelijkheid
Rechtsbijstand
Gezinsongevallen
Kostbaarheden
Zorgverzekering
/
Verkeer
Autoverzekering
Klassieker
Oldtimer
Bestelauto
Scooterverzekering
Motorverzekering
Kampeerauto
Caravan
Qaud/ trike/ mp3
Aanhangwagen
Scootmobiel/ Segway
Fietsverzekering
/
Recreatie
Kortlopende reis
Doorlopende reis
Annulering
Recreatiewoning/ chalet
Pleziervaartuig
Golfverzekering
Vakantiehuis
/
Verzekeringspakket
Particulieren verzekeringspakket
Exclusief-verzekeringspakket
/
Exclusieve-verzekeringen
Autoverzekering
Jachtverzekering
Opstalverzekering
Inboedelverzekering
Kostbaarheden
Verzekeringen:
/
Aansprakelijkheid en overige varia
Bedrijfsaansprakelijkheid
Beroepsaansprakelijkheid
Bestuurdersaansprakelijkheid
CAR-verzekering
Cyberverzekering
WEGAS/ WEGAM
Rechtsbijstand
Evenementen
/
Bedrijfsmiddelen
Bedrijfsschade
Geldverzekering
Opstalverzekering
Extra kosten
Milieuschade
Machinebreuk
Inventaris
Garageverzekering
/
Transport en zakenreis
Vervoer van eigen zaken
Goederentransport
Individuele zakenreis
Collectieve zakenreis
Container/ trailer
/
Verkeer
Personenauto
Bestelauto
Motor
Werkmaterieel
Aanhangwagen
Vrachtauto
Taxiverzekering
Oldtimer
Wagenpark
/
Ziekte en arbeidsongeschiktheid
Arbeidsongeschiktheid
Verzuimverzekering
/
pakketten
MKB-pakket
Verzekeringen:
/
Aansprakelijkheid en overige varia
Aansprakelijkheidsverzekering ZZP
Beroepsaansprakelijkheid ZZP
Bouw en Montage verzekering ZZP
Rechtsbijstandverzekering ZZP
/
Bedrijfsmiddelen
Inventaris- en Goederenverzekering ZZP
Eigen Vervoerverzekering ZZP
/
Pakketten
Verzekeringspakket ZZP
Verzekeringen:
/
Aansprakelijkheid en overige varia
Aansprakelijkheid VVE
Bestuurdersaansprakelijkheid VVE
Ongevallenverzekering VVE
Rechtsbijstandverzekering VVE
/
Bedrijfsmiddelen
Gebouwenverzekering VVE
Glasverzekering VVE
Milieuschadeverzekering VVE
Eigenaarsbelang vve opstalverzekering
Slapende vve opstalverzekering
VvE verzekering eigen huis
VvE inboedelverzekering
/
pakketten
VvE-pakket
Verzekeringen:
/
Aansprakelijkheid en overige varia
Aansprakelijkheid
Bestuurdersaansprakelijkheid
/
Bedrijfsmiddelen
Bedrijfsgebouwen
Glasverzekering
Glas kantoren/ flat en woonhuis in de verhuur
Verhuurde woonhuizen
Inventaris / Goederen / Huurdersbelang
Milieuschadeverzekering
/
Special
Studentenhuis
Kamerverhuur
Hotel
Horecapand
Kantoorpand
Grachtenhuis
Tweede woning
Vakantiewoning
Rijksmonument
Bedrijfsverzamelgebouw
Fundering
Beleggingspand
Loods
Garage
Finass Verzekert is een handelsnaam van Finass Advies B.V.
KvK-nummer 37131781
Maandag - Vrijdag: 09:00 - 17:00
We use cookies and similar technologies to improve your experience on our website.