A policy feels like a safety net until you pull on it. In plain language: what it pays, what it refuses, and the four clauses that decide which. General information, not insurance or legal advice. Een polis voelt als een vangnet tot u eraan trekt. In gewone taal: wat hij betaalt, wat hij weigert, en de vier bepalingen die dat bepalen. Algemene informatie, geen verzekerings- of juridisch advies.
Every cyber policy starts with a questionnaire. Is multi-factor authentication enabled on all remote access? Are backups tested? Is endpoint detection deployed? Somebody in IT ticks yes, in good faith, on a Friday afternoon. Two years later the claims adjuster arrives with the same form and a forensics report showing the VPN box that never got MFA. In many policies those answers are warranties: if one was untrue, the insurer may reduce the payout or void the cover, whether or not that gap caused the breach.
Business impact: the largest cheque you were counting on becomes a negotiation, at the worst possible moment. The fix is administrative, not technical: answer with evidence, keep the evidence, and re-read your own answers at every renewal as if you were the adjuster.
Elke cyberpolis begint met een vragenlijst. Is multifactorauthenticatie ingeschakeld op alle externe toegang? Worden back-ups getest? Is endpointdetectie uitgerold? Iemand van IT vinkt op een vrijdagmiddag te goeder trouw ‘ja’ aan. Twee jaar later staat de schade-expert voor de deur met hetzelfde formulier en een forensisch rapport waarin de VPN-server staat die nooit MFA kreeg. In veel polissen zijn die antwoorden garanties: was er één onjuist, dan mag de verzekeraar de uitkering verlagen of de dekking laten vervallen, of dat gat de inbraak nu veroorzaakte of niet.
Bedrijfsimpact: de grootste cheque waarop u rekende wordt een onderhandeling, op het slechtst denkbare moment. De oplossing is administratief, niet technisch: antwoord met bewijs, bewaar dat bewijs, en herlees uw eigen antwoorden bij elke verlenging alsof u de expert bent.
Read the exclusions before the coverage. Four turn up in most policies. War and state-sponsored attacks: after several large incidents insurers tightened this clause, and attribution to a state can now void a claim you thought was plain ransomware. Known vulnerabilities left unpatched beyond a stated window. Regulatory fines, which in many jurisdictions cannot be insured by law. And contractual penalties to customers, which are your promise, not the insurer's.
Business impact: the events that hurt most may sit entirely outside the policy. Each exclusion is uninsured exposure and belongs in the risk register with an amount next to it, so the board decides knowingly which risks it carries itself.
Lees de uitsluitingen vóór de dekking. Vier komen in de meeste polissen terug. Oorlog en statelijke aanvallen: na een aantal grote incidenten hebben verzekeraars deze bepaling aangescherpt, en toeschrijving aan een staat kan nu een claim ongeldig maken die u voor gewone ransomware hield. Bekende kwetsbaarheden die langer dan een genoemde termijn ongepatcht bleven. Boetes van toezichthouders, die in veel landen wettelijk niet verzekerbaar zijn. En contractuele boetes aan klanten, want dat is uw belofte, niet die van de verzekeraar.
Bedrijfsimpact: de gebeurtenissen die het meeste pijn doen, kunnen volledig buiten de polis vallen. Elke uitsluiting is onverzekerde blootstelling en hoort in het risicoregister met een bedrag ernaast, zodat de directie bewust beslist welke risico's zij zelf draagt.
The headline limit is not the number that matters. Beneath it sit sub-limits: a cap for forensics and legal, a separate and often lower cap for ransom payments, and a waiting period of several days before business-interruption cover starts at all. A serious incident burns through the forensics cap in the first days, when the specialists cost the most and you need them the most. Everything above the cap is yours.
Business impact: a policy with a large headline number can still leave the company paying most of a real incident. Ask for the sub-limits and the waiting period in one table, and compare them with what three weeks of standstill would actually cost. That comparison, not the premium, tells you whether the cover is adequate.
De hoofdlimiet is niet het getal dat telt. Daaronder zitten sublimieten: een plafond voor forensisch onderzoek en juridische bijstand, een apart en vaak lager plafond voor losgeld, en een wachttermijn van enkele dagen voordat de dekking voor bedrijfsschade überhaupt begint. Een serieus incident verbruikt het forensisch plafond in de eerste dagen, precies wanneer de specialisten het duurst zijn en u ze het hardst nodig hebt. Alles boven het plafond is voor u.
Bedrijfsimpact: een polis met een groot hoofdbedrag kan het bedrijf alsnog het grootste deel van een echt incident laten betalen. Vraag de sublimieten en de wachttermijn in één tabel op, en zet ze naast wat drie weken stilstand werkelijk zou kosten. Die vergelijking, niet de premie, zegt of de dekking toereikend is.
Most policies require you to notify the insurer immediately, often within a fixed number of hours, and to use the insurer's approved forensics firm, law firm and negotiator. In the panic of day one, IT calls the firm it knows, legal calls the lawyer it knows, and somebody talks to the attackers. Three days later the insurer is informed, declines the invoices already incurred, and questions whether the response contaminated the evidence.
Business impact: good instincts on day one can cost the coverage on day four. The insurer's hotline belongs on the first line of the printed contact list, and the incident plan must say who calls it before anyone else is engaged. If you want your own trusted firms, have them approved onto the panel in advance.
De meeste polissen eisen dat u de verzekeraar onmiddellijk informeert, vaak binnen een vast aantal uren, en dat u het forensisch bureau, het advocatenkantoor en de onderhandelaar van de verzekeraar gebruikt. In de paniek van dag één belt IT het bureau dat het kent, belt legal de advocaat die zij kent, en praat iemand met de aanvallers. Drie dagen later wordt de verzekeraar geïnformeerd, wijst die de al gemaakte facturen af, en betwijfelt hij of de aanpak het bewijs heeft besmet.
Bedrijfsimpact: goede reflexen op dag één kunnen op dag vier de dekking kosten. De hotline van de verzekeraar hoort op de eerste regel van de geprinte contactlijst, en het incidentplan moet zeggen wie die belt voordat iemand anders wordt ingeschakeld. Wilt u uw eigen vertrouwde partijen, laat ze dan vooraf op het panel goedkeuren.
| Control | Prevents | In one line |
|---|---|---|
| Evidence file | Surprise 01 | Answer every questionnaire item with a document behind it, and keep the file. The adjuster will ask for it. |
| Control mapping | Surprise 01 | Map each policy requirement to a real control and an owner. Re-check before every renewal, not after the breach. |
| Exclusion register | Surprise 02 | List every exclusion as uninsured exposure in the risk register with an estimated amount, and let the board accept it explicitly. |
| Limit test | Surprise 03 | Put sub-limits and waiting periods next to a costed worst case: weeks of standstill, forensics, legal, notification. Adjust the cover or accept the gap. |
| Insurer first | Surprise 04 | The insurer's hotline on line one of the printed contact list. The plan names who calls it and within how many hours. |
| Panel alignment | Surprise 04 | Get your preferred forensics and legal firms approved onto the panel in advance, or accept theirs and meet them before you need them. |
| Ransom decision | Surprises 02, 03 | Decide now whether you would ever pay, and check legality and the policy's sanctions clause. Do not discover both at 03:00. |
| Premium as signal | All four | A rising premium or shrinking cover is the market grading your security. Treat it as an audit finding, not a procurement problem. |
| Maatregel | Voorkomt | In één zin |
|---|---|---|
| Bewijsdossier | Verrassing 01 | Onderbouw elk antwoord op de vragenlijst met een document en bewaar het dossier. De expert zal ernaar vragen. |
| Maatregelen koppelen | Verrassing 01 | Koppel elke poliseis aan een echte maatregel en een eigenaar. Controleer dat vóór elke verlenging, niet na de inbraak. |
| Uitsluitingenregister | Verrassing 02 | Zet elke uitsluiting als onverzekerde blootstelling in het risicoregister met een geschat bedrag, en laat de directie dat expliciet accepteren. |
| Limietentoets | Verrassing 03 | Zet sublimieten en wachttermijnen naast een doorgerekend worstcasescenario: weken stilstand, forensisch onderzoek, juridische kosten, meldingen. Pas de dekking aan of accepteer het gat. |
| Verzekeraar eerst | Verrassing 04 | De hotline van de verzekeraar op regel één van de geprinte contactlijst. Het plan noemt wie belt en binnen hoeveel uur. |
| Panel afstemmen | Verrassing 04 | Laat uw voorkeurspartijen voor forensisch onderzoek en juridische bijstand vooraf op het panel goedkeuren, of accepteer die van de verzekeraar en maak vooraf kennis. |
| Losgeldbesluit | Verrassing 02, 03 | Beslis nu of u ooit zou betalen, en controleer de wettelijkheid en de sanctiebepaling in de polis. Ontdek beide niet om 03:00. |
| Premie als signaal | Alle vier | Een stijgende premie of krimpende dekking is de markt die uw beveiliging beoordeelt. Behandel het als auditbevinding, niet als inkoopprobleem. |
Nearly every claim is tested against the questionnaire and the exclusions. Disputes over cover are routine, not rare.Bijna elke claim wordt getoetst aan de vragenlijst en de uitsluitingen. Discussie over dekking is gewoon, geen uitzondering.
The payout you planned around shrinks or vanishes while the incident costs are already running.De uitkering waarop u rekende krimpt of verdwijnt terwijl de incidentkosten al lopen.
With evidence-backed answers, exclusions on the register and the insurer first in the plan, the policy pays what it says.Met onderbouwde antwoorden, uitsluitingen in het register en de verzekeraar vooraan in het plan betaalt de polis wat erin staat.
Owns the policy and the uninsured exposure. The CISO supplies the evidence behind every questionnaire answer.Eigenaar van de polis en de onverzekerde blootstelling. De CISO levert het bewijs achter elk antwoord op de vragenlijst.
% of questionnaire answers with evidence attached · uninsured exposure from exclusions in € · forensics sub-limit versus the cost estimate of the last exercise · hours to notify the insurer in the last exercise.% antwoorden op de vragenlijst met bewijs · onverzekerde blootstelling uit uitsluitingen in € · forensisch sublimiet tegenover de kostenraming van de laatste oefening · uren tot melding aan de verzekeraar in de laatste oefening.
“Cyber insurance fails to pay as expected because of inaccurate application answers, exclusions, sub-limits or late notification, leaving incident costs uncovered.”“De cyberverzekering betaalt niet zoals verwacht door onjuiste aanvraagantwoorden, uitsluitingen, sublimieten of te late melding, waardoor incidentkosten onverzekerd blijven.”
| Framework | What it requires of you | When a supplier hands you their report | When this incident happens |
|---|---|---|---|
| NIS2 | Insurance is not a substitute for the required risk management measures. Management must approve and oversee the measures itself and stays liable; fines under NIS2 are generally not insurable. | A supplier's insurance certificate does not prove their controls. Ask for the measures, and add their cyber cover and their duty to notify you to the contract. | The 24-hour early warning to the authority runs alongside the insurer's notification clause. Both clocks start at once, so the plan must handle both. Confirm with legal. |
| DORA | Financial entities keep an ICT risk framework and may use insurance as one risk-transfer measure within it. The framework and the residual risk must be documented and approved by the board. | An ICT third party's policy is not one of the DORA contract clauses. Check the required clauses instead: audit rights, incident support, exit strategy. | Major incident reporting to the supervisor within hours of classification, then 72 hours and one month. The insurer's forensics firm must be able to support that pace. Confirm with legal. |
| SOC 2 | If you issue a SOC 2, insurance is not a tested control. The auditor tests the same controls the questionnaire asks about, so both should tell the same story. | Their SOC 2 report is exactly the evidence you would want them to hold for their own insurer. Exceptions in the report are questions to ask about their cover. | The incident response the auditor tests is the one the insurer reviews. Contradictions between the two narratives become findings on both sides. |
| ISAE 3402 | Assurance over outsourced processes; insurance does not appear in it. Where a service organisation relies on insurance for continuity, user auditors may ask for the terms. | Ask whether the service organisation's continuity plan and its cyber cover line up with the control objectives. The report cannot say so on its own. | An incident at the service organisation touches your financial reporting controls. Their insurer's timeline and yours must not conflict with disclosure to the user auditors. |
| Kader | Wat het van u vraagt | Als een leverancier u zijn rapport geeft | Als dit incident u treft |
|---|---|---|---|
| NIS2 | Een verzekering vervangt de verplichte risicobeheersmaatregelen niet. Het bestuur moet de maatregelen zelf goedkeuren en bewaken en blijft aansprakelijk; boetes onder NIS2 zijn in de regel niet verzekerbaar. | Een verzekeringscertificaat van een leverancier bewijst zijn maatregelen niet. Vraag naar de maatregelen, en neem zijn cyberdekking en zijn plicht om u te informeren op in het contract. | De 24-uurs vroegtijdige waarschuwing aan de toezichthouder loopt naast de meldingsplicht van de polis. Beide klokken starten tegelijk, dus het plan moet beide aankunnen. Bevestig met legal. |
| DORA | Financiële instellingen houden een ICT-risicokader bij en mogen een verzekering daarin als één risico-overdrachtsmaatregel gebruiken. Het kader en het restrisico moeten gedocumenteerd en door het bestuur goedgekeurd zijn. | De polis van een ICT-derde is geen van de DORA-contractbepalingen. Controleer in plaats daarvan de verplichte bepalingen: auditrechten, ondersteuning bij incidenten, exitstrategie. | Melding van een ernstig incident aan de toezichthouder binnen enkele uren na classificatie, daarna 72 uur en een maand. Het forensisch bureau van de verzekeraar moet dat tempo kunnen volgen. Bevestig met legal. |
| SOC 2 | Geeft u zelf een SOC 2 af, dan is de verzekering geen geteste maatregel. De auditor test dezelfde maatregelen als waar de vragenlijst naar vraagt, dus beide moeten hetzelfde verhaal vertellen. | Hun SOC 2-rapport is precies het bewijs dat u zou willen dat zij voor hun eigen verzekeraar bewaren. Afwijkingen in het rapport zijn vragen over hun dekking. | De incidentrespons die de auditor test, is dezelfde die de verzekeraar beoordeelt. Tegenstrijdigheden tussen beide verhalen worden bevindingen aan beide kanten. |
| ISAE 3402 | Zekerheid over uitbestede processen; een verzekering komt er niet in voor. Waar een serviceorganisatie voor continuïteit op een verzekering vertrouwt, kunnen de auditors van klanten de voorwaarden opvragen. | Vraag of het continuïteitsplan en de cyberdekking van de serviceorganisatie aansluiten op de beheersdoelstellingen. Het rapport kan dat niet uit zichzelf zeggen. | Een incident bij de serviceorganisatie raakt uw beheersing van de financiële verslaggeving. De tijdlijn van hun verzekeraar en de uwe mogen niet botsen met de melding aan de auditors van de klanten. |