Penetration testing · scope and consent · residual risk
Professional indemnity insurance (BAV) for a cyber security consultant
You assess the security of other people's systems. If a vulnerability goes unnoticed, or something breaks during a test, you are the one held to account for what you should have seen.
- Several insurers compared objectively
- 9.5 customer rating for a new policy
- AFM licence 12016589
- Personal 072 - 509 24 56, weekdays 9–17
Deze pagina in het Nederlands: Beroepsaansprakelijkheidsverzekering voor een cybersecurity consultant.
The calculator and the quote form below are in Dutch. Prefer to do this in English? Email info@finassverzekert. nl or call 072 - 509 24 56 and we will take it from there.
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
- We compare the offerings of several insurers
- An adviser checks whether the cover suits your activities
- We arrange the switch, including cancellation
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
In brief
Professional indemnity insurance (BAV) covers pure financial loss: financial detriment to your client without injury or damage to property. For a security consultant that is the bulk of the risk. A vulnerability you missed during an audit that is later exploited, advice on segmentation or back-ups that does not hold up, an implementation plan for a standard or for the NIS2 requirements that fails the auditor's test: the bill consists of downtime, remedial work and reassessment at the client.
Pay attention to the description of business activity on the policy schedule. Advising, carrying out penetration tests and incident response are three different activities with three different risks. What is not stated there is not insured. Also ask explicitly how the policy treats damage to data and software: data is not property in law, so the loss or corruption of files usually does not fall on a public and employers' liability insurance but here.
Without a written engagement with a defined scope, gaining access to a system is a criminal offence under Article 138ab of the Dutch Criminal Code. Testing beyond the agreed scope is therefore not only a professional error but also touches the exclusion for intent in Article 7:952 of the Dutch Civil Code. Loss to your own business – your laptop, your own environment, a ransom – does not belong on a BAV but on a cyber insurance.
This page deals with one situation. The full overview is on Compare professional indemnity insurance (BAV).
What to look out for
Four points that cause more discussion in security work than the level of the sum insured does.
What you did not find: the missed vulnerability
A test is a snapshot within a defined scope. Record in the report what was and was not examined, by which method, and which residual risk remains. Avoid wording that can be read as a promise, such as stating that an environment is secure. Liability arising solely from a warranty or an indemnity falls outside the cover.
Damage during the test itself
A production environment that goes down, accounts locked out en masse, log files overwritten. Ask whether work on third-party systems is included and on what conditions: a test window outside office hours, a tested back-up beforehand and written consent from the system owner are the usual requirements.
Incident response and evidence
During a live incident, restoring things in haste can mean destroying evidence. Record who decides on shutting systems down and who notifies the regulator. If you work for an insurer or a lawyer, check who in that chain is your client. That determines who can bring a claim against you.
Fines and sanctions passed on
An administrative fine from the Autoriteit Persoonsgegevens (the Dutch data protection authority) or a sanction imposed by a regulator is not insurable, and passing it on to you by your client usually is not either. The same applies to contractual penalty clauses. What is insured is the loss your mistake caused, not the penalty imposed on someone else.
What does your premium depend on?
- Annual turnover: the usual basis for advisory work
- The balance between advice, testing and response: active testing weighs more heavily than advice alone
- The sector your clients are in: healthcare, financial services and critical infrastructure count differently
- Conditions applied: your own industry terms or the client's purchasing terms
- Area of cover: clients outside Europe call for a separate assessment
- Sum insured and excess: per claim and capped per insurance year
Insurers weigh these details differently. That is where your saving is.
What is covered
| Situation | AVB | BAV |
|---|---|---|
| You drop your client's laptop during an audit at their office | Yes | No |
| Your hardening advice blocks an interface and the webshop processes no orders for two days | No | Yes |
| A configuration you changed wipes part of the customer database | No | Yes |
| Your client's certification process fails the audit and the reassessment has to be paid for | No | Provided that |
| The ransom you pay after your own workstation is encrypted | No | No |
| Your client sets your invoice off because he is dissatisfied with the report | No | No |
Data is not property in law, which means that loss or corruption of files almost always ends up on the BAV and not on the AVB.
Frequently asked questions
This is what people ask us most.
A client was hacked through a vulnerability I did not find. Am I liable?
That depends on the scope and on your report. The test is whether you acted as a reasonably competent professional, not whether you should have found everything. A test with a recorded scope, a described method and an explicitly named residual risk is your main defence. Without that record, the discussion becomes one person's word against another's.
Is damage to the systems I test insured?
Not automatically. Many policies restrict work on third-party equipment and software. Because data is not property, loss of data is usually treated as financial loss and therefore falls under this policy, but only if testing work is within your stated professional capacity. Have this confirmed in writing before you apply, rather than finding out afterwards.
Do I also need cyber insurance as a sole trader?
That covers something else: your own loss and the cost of putting things right when you are the victim. Because you hold client data and test results, that is a real risk. Liability towards your client runs through this policy. You will find an overview of the combination on the insurance package for self-employed professionals in IT.
What if a claim only arrives after I have stopped?
This insurance almost always works on a claims-made basis: what counts is the moment the claim is made and notified, not the moment of the mistake. If cover has ended by then, you are on your own. So arrange run-off cover before you cancel, and report any suspicion of a mistake as a circumstance straight away; Article 7:941 of the Dutch Civil Code also requires you to do so.
Read more
Within Beroepsaansprakelijkheidsverzekering
- Beroepsaansprakelijkheidsverzekeringthe main page
- Beroepsaansprakelijkheidsverzekering cybersecurity bedrijf
- Beroepsaansprakelijkheidsverzekering data analist zzp
- Beroepsaansprakelijkheidsverzekering it consultancy
- Beroepsaansprakelijkheidsverzekering compliance officer zzp
- Beroepsaansprakelijkheidsverzekering it consultant zzp
- Beroepsaansprakelijkheidsverzekering data analyse bureau
Similar pages
- Professional indemnity insurance (BAV) for a cyber security company
- Professional indemnity insurance (BAV) for an IT consultancy
- Professional indemnity insurance (BAV) for a data analyst
- Professional indemnity insurance (BAV) for a self-employed compliance officer
- Professional indemnity insurance (BAV) for an IT consultant
- Professional indemnity insurance (BAV) for an educational consultancy
- Professional indemnity insurance (BAV) for a data analysis agency
- Professional indemnity insurance (BAV) through De Goudse