Test engagements · scope · detection promises
Professional indemnity insurance (BAV) for a cyber security company
You are hired to find weak spots. If your client is hit later anyway, the first question is whether the gap fell within your engagement.
- Several insurers compared objectively
- 9.5 customer rating for a new policy
- AFM licence 12016589
- Personal 072 - 509 24 56, weekdays 9–17
Deze pagina in het Nederlands: Beroepsaansprakelijkheidsverzekering voor een cybersecuritybedrijf.
The calculator and the quote form below are in Dutch. Prefer to do this in English? Email info@finassverzekert. nl or call 072 - 509 24 56 and we will take it from there.
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
- We compare the offerings of several insurers
- An adviser checks whether the cover suits your activities
- We arrange the switch, including cancellation
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
In brief
A cybersecurity company tests, monitors, advises and helps clear up after an incident. Each of those services has its own way of going wrong: a vulnerability that was not found, an alert left unattended overnight, a configuration that after your advice actually opens a door, or remedial work in which evidence is lost. The client's loss is business interruption, restoration costs and claims from his own customers. The basic principles of this insurance are described on the hub page on the BAV.
Your first layer of protection is not the policy but the engagement letter. Without written permission from the rightful party, intrusion into a system is a criminal offence under Article 138ab of the Dutch Criminal Code. Record for each test which systems, addresses and time windows fall within the scope, who signs on the client's behalf and who is authorised to stop. If you touch a third party's system — a hosting provider, a SaaS supplier, a supply-chain API &mdash. There is no permission and therefore no defence.
Third, pay attention to the type of loss. If your client's environment goes down because of a test, that is financial loss. If equipment is damaged or property in your care is involved, you are dealing with public and employers' liability insurance and the care, custody and control provision. And if you are hit yourself, that is your own loss and it belongs on a cyber insurance.
This page deals with one situation. The full overview is on Compare professional indemnity insurance (BAV).
What to look out for
Four subjects that shape the cover discussion in security services.
A test is a snapshot within a scope
You assess an environment at a given moment, with the rights and the time you were given. State in the report which systems remained outside the engagement, which techniques you were not allowed to use and which limitations the timescale imposed. Without that demarcation a report is read afterwards as a statement that the environment was secure, and that is precisely the promise you should not give.
Detection times in an agreement are enforceable
If you promise a response time, a coverage rate or a maximum detection time in a service agreement, that is a obligation to achieve a specific result. If it is not met, the liability is contractual, and liability under guarantees and penalty clauses falls outside the cover. Frame best efforts as best efforts and agree how performance is measured.
Remediation after an incident calls for its own arrangements
In incident response you work under time pressure in production systems. If data disappears or evidence is lost in the process, the argument is whether that was unavoidable. Record in advance who decides to shut down, restore or keep working, and that the client remains responsible for his own back-ups. Administrative fines and penalty payments imposed on your client are never insured.
What else falls outside this
Excluded are the redoing your own test or implementation and repaying your fee, liability under indemnities you take on by contract, and loss caused by intent or wilful recklessness, for which Article 7:952 of the Dutch Civil Code is the basis. Testing outside the agreed scope is assessed in that light and is a real risk to your cover.
What does your premium depend on?
- Annual turnover: split across testing, monitoring and response
- Services in the package: advising weighs less than managing
- Access to client systems: administrator rights increase the risk
- Sectors your clients work in: healthcare, financial institutions and critical processes
- Contractual service levels: promised response and recovery times
- Sum insured and excess: per claim and per insurance year
Insurers weigh these details differently. That is where your saving is.
What is covered
| Situation | AVB | BAV |
|---|---|---|
| While installing a sensor in the server room you knock over a rack and damage a switch | Yes | No |
| A phishing simulation brings your client's mail environment down for a day | No | Yes |
| An alert from your monitoring is left over the weekend and the encryption spreads further | No | Yes |
| Your scan hits an IP range belonging to the hosting provider that was not in the engagement | No | Provided that |
| Your own office network is encrypted and you cannot deliver services for days | No | No |
| Your client withholds the final instalment because he finds the report too thin | No | No |
Financial loss at the client runs through the BAV, injury and damaged equipment through the AVB, and your own loss through cyber insurance.
Frequently asked questions
This is what people ask us most.
We missed a vulnerability that was later exploited. Are we liable?
Not automatically. The standard is whether a reasonably competent and reasonably acting professional would have found the gap within the same scope and time. Your file is decisive: the description of the engagement, the method used, the log files and the report with its limitations. If the vulnerability only became known after your test, there is in principle no blame.
Our test brought a production environment down. Who bears that loss?
That depends on what was agreed. If it was recorded in advance that testing would take place in production and which risks come with that, acceptance of that risk is part of the engagement. Without that agreement, the downtime is your client's loss. So always agree a test window, a stop procedure and a contact person who is reachable during the test.
Our client received a fine and had to inform data subjects. Does that fall under our policy?
Not the fine: that is a sanction and not compensation. The costs of investigation, restoration and informing data subjects are your client's loss and belong first of all on his own cyber policy. Only if he shows that your failure caused those costs does your professional indemnity insurance come into play for the financial part.
Does NIS2 change our position?
The European NIS2 directive is being implemented in the Netherlands through the Cyberbeveiligingswet (the Dutch cybersecurity act) and requires organisations in designated sectors to manage risk and report incidents. Clients pass those requirements down to their suppliers by contract, so expect stricter provisions on demonstrability and reporting deadlines. For the personal responsibility of directors, directors' and officers' liability insurance is a separate consideration.
Read more
Within Beroepsaansprakelijkheidsverzekering
- Beroepsaansprakelijkheidsverzekeringthe main page
- Beroepsaansprakelijkheidsverzekering ai adviesbureau
- Beroepsaansprakelijkheidsverzekering cybersecurity consultant zzp
- Beroepsaansprakelijkheidsverzekering data analist zzp
- Beroepsaansprakelijkheidsverzekering ai consultant zzp
- Beroepsaansprakelijkheidsverzekering compliance adviesbureau
- Beroepsaansprakelijkheidsverzekering veiligheidsadviesbureau
Similar pages
- Professional indemnity insurance (BAV) for a cyber security consultant
- Professional indemnity insurance (BAV) for an AI consultancy
- Professional indemnity insurance (BAV) for a data analyst
- Professional indemnity insurance (BAV) for a safety consultancy
- Professional indemnity insurance (BAV) for a sustainability consultancy
- Professional indemnity insurance (BAV) for a self-employed AI consultant
- Professional indemnity insurance (BAV) for a compliance consultancy
- Professional indemnity insurance (BAV) for a self-employed compliance officer