MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Cyber insurance covers damage resulting from online incidents — data breaches, ransomware, phishing, business interruption, GDPR fines, and liability towards customers. Increasingly essential for SMEs: 60% of SMEs experience a cyber incident annually, with average costs of €25,000–€250,000. Premium: €50–€500/month depending on turnover, industry, and data volume. Coverage typically €100,000–€5 million. Important: ensure cyber hygiene is in order beforehand — the insurer will refuse a claim in case of gross negligence. Below: coverage, requirements, and why Saskia's startup is taking out a cyber package.
The short answer
- What: covers damage from data breaches, ransomware, cybercrime, and business interruption.
- Premium: €50-€500/month for SME BV.
- Coverage: €100,000-€5 million per incident.
- Requirements: cyber hygiene (backup, MFA, training) under policy conditions.
- Difference with General Liability Insurance: cyber covers cyber incidents, General Liability Insurance does not.
What does cyber insurance cover?
1. Own damage
- Business interruption due to a cyber incident (comparable to business interruption damage).
- Forensic investigation following the incident.
- Restore data and systems.
- Communication costs to customers.
- Ransomware payments (where legal).
2. Liability towards third parties
- Damage to customers due to data breach.
- GDPR fines (where insurable).
- Compensation for affected persons.
- Reputation repair (PR costs).
3. Cybercrime coverage
- CEO fraud (director's expired email).
- Bank details theft.
- Identity fraud against company.
- Phishing damage to employees.
Premium and scope
Premium depends on:
- Revenue and size.
- Industry (IT, financial sector riskier).
- Data volume (number of customer records).
- International aspects.
- Security level (audit result).
For SME BV:
- Small (no customer data, €500k revenue): €50-€100/month.
- Medium (B2B, customer data, €3M turnover): €150-€300/month.
- High-risk industry or large amounts of data: €300-€800/month.
Insurers demand cyber hygiene
The risk profile is assessed upon conclusion. The policy may impose requirements:
- Backup: regular backups, stored elsewhere.
- MFA (multi-factor authentication): for all critical systems.
- Patch management: update software regularly.
- Anti-phishing training: employees trained annually.
- Incident response plan: prepared in advance.
- No access via default passwords.
In case of gross negligence (no backup, no MFA against ransomware): the claim may be rejected.
GDPR aspect
In the event of a data breach involving personal data: GDPR notification obligation to the Dutch Data Protection Authority within 72 hours. Cyber insurers often cover:
- Legal assistance with GDPR notification.
- Investigate the extent of the leak.
- Communication to data subjects (right to information).
- Fines (where insurable — not all GDPR fines are).
For companies with customer data: the GDPR aspect is often the biggest cost item after an incident.
Saskia's cyber insurance
Saskia's cleantech startup has customer data from industrial clients (R&D data, machine data). A cyber incident can be serious:
- Theft of IP and R&D data: direct competitive damage.
- Customer data breach: GDPR impact + reputation.
- Ransomware on production systems: factory downtime.
Cyber policy €300/month with coverage of €2 million per incident. Investment also includes annual security audit and incident response training — both chargeable as operating expenses.
Honest recommendation
For every SME with digital activity (virtually everyone): cyber insurance is virtually indispensable in 2024. Invest in cyber hygiene (backup, MFA, training) — not only for insurance, but also for prevention. A specialized IT broker (€250-€1,500) helps with a tailored package. For companies with large amounts of customer data or international activity: pay extra attention to GDPR coverage and international validity.
For other topics: insurance for SME companies, General Liability and D&O.
Frequently Asked Questions
Insurance that covers damage from online incidents — data breach, ransomware, phishing, business interruption, GDPR fines, and liability towards customers. Three main categories: own damage, third-party liability, cybercrime coverage.
€50-€500/month for SME BV. Small (no customer data, €500k turnover): €50-€100. Medium (B2B with customer data, €3M): €150-€300. High-risk industry (IT, financial) or large amount of data: €300-€800.
Backup (stored externally), MFA for critical systems, patch management, anti-phishing training for employees, and incident response plan. In case of gross negligence (no MFA for ransomware): the claim may be rejected.
Often partially — legal assistance with reporting, investigation, communication with affected parties, and fines where insurable. Not all GDPR fines are insurable — intentional violations are usually excluded.
Compensation for lost profits and ongoing costs during downtime caused by a cyber incident (comparable to classic business interruption). Waiting period 24-72 hours, coverage duration 3-12 months depending on policy.
Policy: avoid as much as possible — do not give in to criminals. Policy may cover ransomware payments in exceptional cases (provided it is legal — excluding sanctioned countries) after consultation with the insurer and cyber experts. High deductible.
Cyber covers cyber incidents. General Liability covers physical liability. D&O covers directors' and officers' liability (including after a cyber incident). Business interruption covers physical downtime. Cyber insurance fills a specific gap left open by traditional policies.