Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
A web agency is rarely attacked for its own data, but for the dozens of client websites whose keys it holds.
This page in another language: Nederlands
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
Most of the sites you deliver run on a content management system with third-party plug-ins and themes. That is where the risk lies: not in your office network, but in known vulnerabilities in components you once installed and that have since taken on a life of their own. Anyone exploiting one of them places spam, redirects visitors or takes down a site that is your client's sales channel.
The legal heart of the matter is your maintenance agreement. If you promised updates and security maintenance, then after a hack the question becomes whether you demonstrably did so. A maintenance log per site is your most important document when a claim arises. Without one, the discussion turns to the standard of care in Article 6:162 of the Dutch Civil Code and to what you undertook contractually.
If you run the underlying servers yourself, also look at the cyber insurance for hosting companies; if you mainly manage office networks, the one for IT companies better.
We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.
Cyber insurance
Compare
Get coveredThe structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Insurers weigh these details differently. That is where your saving is.
We look at the terms as well as the premium, and stay your point of contact when there is a claim.
We are not tied to one insurer and compare on the basis of an objective analysis of several companies.
You call or email someone who knows your file. No menu options, no changing call centres.
We cancel your old policy and align the start date, so you are never a day without cover.
We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
Four points that make the difference between a policy that pays out and one that does not.
With a hacked client site, everything turns on what you promised and what you did. If you delivered once without maintenance, the risk lies with the client, provided you set that out in writing. If you took on maintenance, you have to be able to show when you updated which plug-in. Insurers exclude loss arising from vulnerabilities for which a patch had been available for some time; a log is therefore not paperwork but cover.
Administrator accounts in every CMS, FTP and SSH access, DNS management, hosting panels and sometimes the domain name itself: every project leaves access behind. Former staff and freelancers brought in are often still listed. Work with personal accounts and two-factor authentication, and clear up rights on completion or departure. What you state about this in the application is a disclosure within the meaning of Article 7:928 of the Dutch Civil Code; if it is not correct, the insurer may reduce the payout under Article 7:930 DCC.
If after a hack you have to rebuild a site or roll out a design again, those are costs of re-performing your own work. They fall outside the cover, as do penalty clauses and availability guarantees that you took on contractually without any basis in law. The policy pays your client's loss and the investigation into the cause, not your unpaid hours. Intent also remains excluded under Article 7:952 DCC.
Contact forms, job application forms and newsletter sign-ups store data in the database of the site you manage, often for years. After a break-in that is your client's data breach, which he has to report within 72 hours and the costs of which he puts to you. Look at each site to see what data is being kept and switch on automatic clearing out. Administrative fines cannot be insured; investigation, notification costs and claims from those concerned generally are.
This is what people ask us most.
That depends on what you agreed. If you had promised maintenance and an update had been available for some time, your position is weak and the client will hold you responsible. If the client handled maintenance himself, you have to be able to show that in writing. Insurers look at the same documents: the contract and the log showing when you updated what.
No, not your own build and repair hours. What is covered: forensic investigation into the cause, the costs of the data breach that followed from it and the claim for compensation your client brings against you. If you also want to cover your own recovery effort, that is a conversation about the own-loss section and about which costs fit within it.
It limits your availability risk, but not your liability. The hosting provider is responsible for the server. You remain responsible for the application layer, the plug-ins and the management. Most hacks of client sites come in through that application layer. It is sensible, though, to check whether your policy includes failure at a service provider and with what waiting period.
Usually yes. A site that does not do what was agreed, a missed deadline or a design the client rejects are professional errors without a security incident, and those are excluded on the cyber policy. Copyright claims about images used belong there as well. The cyber policy picks up as soon as a hack, ransomware or a data breach lies behind the loss.
Every situation is different. For these situations we have a separate page.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was compiled by Finass Verzekert (LinkedIn). Last updated on .
The information on this page is general in nature and is not personal advice.
Maandag- Vrijdag: 09:00- 17:00
We use cookies and similar technologies to improve your experience on our website.