// BRIEFING

Cyber insurance. Four surprises at claim time. Cyberverzekering. Vier verrassingen bij de claim.

A policy feels like a safety net until you pull on it. In plain language: what it pays, what it refuses, and the four clauses that decide which. General information, not insurance or legal advice. Een polis voelt als een vangnet tot u eraan trekt. In gewone taal: wat hij betaalt, wat hij weigert, en de vier bepalingen die dat bepalen. Algemene informatie, geen verzekerings- of juridisch advies.

// SURPRISE 01VERRASSING 01

The form said “MFA everywhere”. Op het formulier stond “MFA overal”.

application warranty / misrepresentation aanvraagformulier / onjuiste opgave
AT CLAIM TIMEBIJ DE CLAIM
🏢
Us, two years agoWij, twee jaar geleden
Claims adjusterSchade-expert
APPLICATION · SECURITY CONTROLSAANVRAAG · BEVEILIGINGSMAATREGELEN
Backups tested yearlyBack-ups jaarlijks getest
Endpoint detection deployedEndpointdetectie uitgerold
MFA on all remote accessMFA op alle externe toegang

Every cyber policy starts with a questionnaire. Is multi-factor authentication enabled on all remote access? Are backups tested? Is endpoint detection deployed? Somebody in IT ticks yes, in good faith, on a Friday afternoon. Two years later the claims adjuster arrives with the same form and a forensics report showing the VPN box that never got MFA. In many policies those answers are warranties: if one was untrue, the insurer may reduce the payout or void the cover, whether or not that gap caused the breach.

Business impact: the largest cheque you were counting on becomes a negotiation, at the worst possible moment. The fix is administrative, not technical: answer with evidence, keep the evidence, and re-read your own answers at every renewal as if you were the adjuster.

Elke cyberpolis begint met een vragenlijst. Is multifactorauthenticatie ingeschakeld op alle externe toegang? Worden back-ups getest? Is endpointdetectie uitgerold? Iemand van IT vinkt op een vrijdagmiddag te goeder trouw ‘ja’ aan. Twee jaar later staat de schade-expert voor de deur met hetzelfde formulier en een forensisch rapport waarin de VPN-server staat die nooit MFA kreeg. In veel polissen zijn die antwoorden garanties: was er één onjuist, dan mag de verzekeraar de uitkering verlagen of de dekking laten vervallen, of dat gat de inbraak nu veroorzaakte of niet.

Bedrijfsimpact: de grootste cheque waarop u rekende wordt een onderhandeling, op het slechtst denkbare moment. De oplossing is administratief, niet technisch: antwoord met bewijs, bewaar dat bewijs, en herlees uw eigen antwoorden bij elke verlenging alsof u de expert bent.

WARRANTY BREACH · CLAIM REDUCED OR VOIDGARANTIE GESCHONDEN · CLAIM VERLAAGD OF VERVALLEN FIX: ANSWER WITH EVIDENCE, RE-CHECK EVERY RENEWALOPLOSSING: ANTWOORD MET BEWIJS, CONTROLEER BIJ ELKE VERLENGING
// SURPRISE 02VERRASSING 02

Four things that are not covered. Vier dingen die niet gedekt zijn.

exclusions uitsluitingen
THE SMALL PRINTDE KLEINE LETTERTJES
POLICYPOLIS📜
WAR · STATE ACTORSOORLOG · STATELIJKE ACTOREN KNOWN, UNPATCHEDBEKEND, ONGEPATCHT REGULATORY FINESBOETES TOEZICHTHOUDER CONTRACT PENALTIESCONTRACTBOETES

Read the exclusions before the coverage. Four turn up in most policies. War and state-sponsored attacks: after several large incidents insurers tightened this clause, and attribution to a state can now void a claim you thought was plain ransomware. Known vulnerabilities left unpatched beyond a stated window. Regulatory fines, which in many jurisdictions cannot be insured by law. And contractual penalties to customers, which are your promise, not the insurer's.

Business impact: the events that hurt most may sit entirely outside the policy. Each exclusion is uninsured exposure and belongs in the risk register with an amount next to it, so the board decides knowingly which risks it carries itself.

Lees de uitsluitingen vóór de dekking. Vier komen in de meeste polissen terug. Oorlog en statelijke aanvallen: na een aantal grote incidenten hebben verzekeraars deze bepaling aangescherpt, en toeschrijving aan een staat kan nu een claim ongeldig maken die u voor gewone ransomware hield. Bekende kwetsbaarheden die langer dan een genoemde termijn ongepatcht bleven. Boetes van toezichthouders, die in veel landen wettelijk niet verzekerbaar zijn. En contractuele boetes aan klanten, want dat is uw belofte, niet die van de verzekeraar.

Bedrijfsimpact: de gebeurtenissen die het meeste pijn doen, kunnen volledig buiten de polis vallen. Elke uitsluiting is onverzekerde blootstelling en hoort in het risicoregister met een bedrag ernaast, zodat de directie bewust beslist welke risico's zij zelf draagt.

WAR · UNPATCHED · FINES · PENALTIESOORLOG · ONGEPATCHT · BOETES · CONTRACTBOETES FIX: EXCLUSIONS IN THE RISK REGISTER, WITH A NUMBEROPLOSSING: UITSLUITINGEN IN HET RISICOREGISTER, MET EEN BEDRAG
// SURPRISE 03VERRASSING 03

The money runs out on day three. Het geld is op op dag drie.

sub-limits and waiting periods sublimieten en wachttermijnen
INCIDENT COSTINCIDENTKOSTEN
FORENSICS & LEGAL SPENDUITGAVEN FORENSISCH & JURIDISCH
SUB-LIMITSUBLIMIET
DAY 1DAG 1
DAY 3DAG 3
DAY 21DAG 21

The headline limit is not the number that matters. Beneath it sit sub-limits: a cap for forensics and legal, a separate and often lower cap for ransom payments, and a waiting period of several days before business-interruption cover starts at all. A serious incident burns through the forensics cap in the first days, when the specialists cost the most and you need them the most. Everything above the cap is yours.

Business impact: a policy with a large headline number can still leave the company paying most of a real incident. Ask for the sub-limits and the waiting period in one table, and compare them with what three weeks of standstill would actually cost. That comparison, not the premium, tells you whether the cover is adequate.

De hoofdlimiet is niet het getal dat telt. Daaronder zitten sublimieten: een plafond voor forensisch onderzoek en juridische bijstand, een apart en vaak lager plafond voor losgeld, en een wachttermijn van enkele dagen voordat de dekking voor bedrijfsschade überhaupt begint. Een serieus incident verbruikt het forensisch plafond in de eerste dagen, precies wanneer de specialisten het duurst zijn en u ze het hardst nodig hebt. Alles boven het plafond is voor u.

Bedrijfsimpact: een polis met een groot hoofdbedrag kan het bedrijf alsnog het grootste deel van een echt incident laten betalen. Vraag de sublimieten en de wachttermijn in één tabel op, en zet ze naast wat drie weken stilstand werkelijk zou kosten. Die vergelijking, niet de premie, zegt of de dekking toereikend is.

SUB-LIMITS · WAITING PERIOD · THE REST IS OURSSUBLIMIETEN · WACHTTERMIJN · DE REST IS VOOR ONS FIX: LIMITS TESTED AGAINST A COSTED WORST CASEOPLOSSING: LIMIETEN GETOETST AAN EEN DOORGEREKEND WORSTCASESCENARIO
// SURPRISE 04VERRASSING 04

You called the wrong people first. U belde eerst de verkeerden.

notification clause and panel firms meldingsplicht en panelpartijen
DAY 1 → DAY 4DAG 1 → DAG 4
🏢
Us, 03:00Wij, 03:00
LATETE LAAT
InsurerVerzekeraar
🛠️OUR OWN IT FIRM · OFF-PANELONS EIGEN IT-BUREAU · BUITEN PANEL
DAY 4DAG 4

Most policies require you to notify the insurer immediately, often within a fixed number of hours, and to use the insurer's approved forensics firm, law firm and negotiator. In the panic of day one, IT calls the firm it knows, legal calls the lawyer it knows, and somebody talks to the attackers. Three days later the insurer is informed, declines the invoices already incurred, and questions whether the response contaminated the evidence.

Business impact: good instincts on day one can cost the coverage on day four. The insurer's hotline belongs on the first line of the printed contact list, and the incident plan must say who calls it before anyone else is engaged. If you want your own trusted firms, have them approved onto the panel in advance.

De meeste polissen eisen dat u de verzekeraar onmiddellijk informeert, vaak binnen een vast aantal uren, en dat u het forensisch bureau, het advocatenkantoor en de onderhandelaar van de verzekeraar gebruikt. In de paniek van dag één belt IT het bureau dat het kent, belt legal de advocaat die zij kent, en praat iemand met de aanvallers. Drie dagen later wordt de verzekeraar geïnformeerd, wijst die de al gemaakte facturen af, en betwijfelt hij of de aanpak het bewijs heeft besmet.

Bedrijfsimpact: goede reflexen op dag één kunnen op dag vier de dekking kosten. De hotline van de verzekeraar hoort op de eerste regel van de geprinte contactlijst, en het incidentplan moet zeggen wie die belt voordat iemand anders wordt ingeschakeld. Wilt u uw eigen vertrouwde partijen, laat ze dan vooraf op het panel goedkeuren.

LATE NOTICE · OFF-PANEL FIRMS · COVERAGE DISPUTEDTE LATE MELDING · PARTIJEN BUITEN HET PANEL · DEKKING BETWIST FIX: INSURER FIRST IN THE PLAN, OWN FIRMS PRE-APPROVEDOPLOSSING: VERZEKERAAR EERST IN HET PLAN, EIGEN PARTIJEN VOORAF GOEDGEKEURD
// CONTROLSMAATREGELEN

What makes the policy actually pay. Wat de polis echt laat uitbetalen.

paperwork and rehearsal — the policy is a control only if you treat it like one papierwerk en oefening — de polis is alleen een maatregel als u hem zo behandelt
DEFENCE STACKVERDEDIGINGSLAGEN
EVIDENCEBEWIJS EXCLUSIONSUITSLUITINGEN LIMITSLIMIETEN NOTIFY FIRSTEERST MELDEN RENEWALVERLENGING
ControlPreventsIn one line
Evidence fileSurprise 01Answer every questionnaire item with a document behind it, and keep the file. The adjuster will ask for it.
Control mappingSurprise 01Map each policy requirement to a real control and an owner. Re-check before every renewal, not after the breach.
Exclusion registerSurprise 02List every exclusion as uninsured exposure in the risk register with an estimated amount, and let the board accept it explicitly.
Limit testSurprise 03Put sub-limits and waiting periods next to a costed worst case: weeks of standstill, forensics, legal, notification. Adjust the cover or accept the gap.
Insurer firstSurprise 04The insurer's hotline on line one of the printed contact list. The plan names who calls it and within how many hours.
Panel alignmentSurprise 04Get your preferred forensics and legal firms approved onto the panel in advance, or accept theirs and meet them before you need them.
Ransom decisionSurprises 02, 03Decide now whether you would ever pay, and check legality and the policy's sanctions clause. Do not discover both at 03:00.
Premium as signalAll fourA rising premium or shrinking cover is the market grading your security. Treat it as an audit finding, not a procurement problem.
MaatregelVoorkomtIn één zin
BewijsdossierVerrassing 01Onderbouw elk antwoord op de vragenlijst met een document en bewaar het dossier. De expert zal ernaar vragen.
Maatregelen koppelenVerrassing 01Koppel elke poliseis aan een echte maatregel en een eigenaar. Controleer dat vóór elke verlenging, niet na de inbraak.
UitsluitingenregisterVerrassing 02Zet elke uitsluiting als onverzekerde blootstelling in het risicoregister met een geschat bedrag, en laat de directie dat expliciet accepteren.
LimietentoetsVerrassing 03Zet sublimieten en wachttermijnen naast een doorgerekend worstcasescenario: weken stilstand, forensisch onderzoek, juridische kosten, meldingen. Pas de dekking aan of accepteer het gat.
Verzekeraar eerstVerrassing 04De hotline van de verzekeraar op regel één van de geprinte contactlijst. Het plan noemt wie belt en binnen hoeveel uur.
Panel afstemmenVerrassing 04Laat uw voorkeurspartijen voor forensisch onderzoek en juridische bijstand vooraf op het panel goedkeuren, of accepteer die van de verzekeraar en maak vooraf kennis.
LosgeldbesluitVerrassing 02, 03Beslis nu of u ooit zou betalen, en controleer de wettelijkheid en de sanctiebepaling in de polis. Ontdek beide niet om 03:00.
Premie als signaalAlle vierEen stijgende premie of krimpende dekking is de markt die uw beveiliging beoordeelt. Behandel het als auditbevinding, niet als inkoopprobleem.
The board-level point: insurance transfers some of the cost, never the responsibility. Three questions for the next renewal: what exactly is excluded, how long is the waiting period, and are the questionnaire answers still true today? This briefing is general information, not insurance or legal advice; check the actual wording with your broker and counsel. De kern voor de directie: een verzekering verplaatst een deel van de kosten, nooit de verantwoordelijkheid. Drie vragen voor de volgende verlenging: wat is precies uitgesloten, hoe lang is de wachttermijn, en zijn de antwoorden op de vragenlijst vandaag nog waar? Deze briefing is algemene informatie, geen verzekerings- of juridisch advies; toets de werkelijke polistekst met uw makelaar en jurist.
// RISK & COMPLIANCERISICO & COMPLIANCE

On the register, and in the audit. In het risicoregister, en in de audit.

indicative — confirm scope and deadlines with legal and complianceindicatief — bevestig reikwijdte en termijnen met legal en compliance
LikelihoodKansHighHoog

Nearly every claim is tested against the questionnaire and the exclusions. Disputes over cover are routine, not rare.Bijna elke claim wordt getoetst aan de vragenlijst en de uitsluitingen. Discussie over dekking is gewoon, geen uitzondering.

ImpactImpactHighHoog

The payout you planned around shrinks or vanishes while the incident costs are already running.De uitkering waarop u rekende krimpt of verdwijnt terwijl de incidentkosten al lopen.

Residual after controlsRestrisico na maatregelenLowLaag

With evidence-backed answers, exclusions on the register and the insurer first in the plan, the policy pays what it says.Met onderbouwde antwoorden, uitsluitingen in het register en de verzekeraar vooraan in het plan betaalt de polis wat erin staat.

Risk ownerRisico-eigenaarCFO / CROCFO / CRO

Owns the policy and the uninsured exposure. The CISO supplies the evidence behind every questionnaire answer.Eigenaar van de polis en de onverzekerde blootstelling. De CISO levert het bewijs achter elk antwoord op de vragenlijst.

Key risk indicatorsKernrisico-indicatorenFour numbers to ask forVier getallen om naar te vragen

% of questionnaire answers with evidence attached · uninsured exposure from exclusions in € · forensics sub-limit versus the cost estimate of the last exercise · hours to notify the insurer in the last exercise.% antwoorden op de vragenlijst met bewijs · onverzekerde blootstelling uit uitsluitingen in € · forensisch sublimiet tegenover de kostenraming van de laatste oefening · uren tot melding aan de verzekeraar in de laatste oefening.

Risk register entryTekst voor het risicoregisterOne sentenceEén zin

“Cyber insurance fails to pay as expected because of inaccurate application answers, exclusions, sub-limits or late notification, leaving incident costs uncovered.”“De cyberverzekering betaalt niet zoals verwacht door onjuiste aanvraagantwoorden, uitsluitingen, sublimieten of te late melding, waardoor incidentkosten onverzekerd blijven.”

FrameworkWhat it requires of youWhen a supplier hands you their reportWhen this incident happens
NIS2Insurance is not a substitute for the required risk management measures. Management must approve and oversee the measures itself and stays liable; fines under NIS2 are generally not insurable.A supplier's insurance certificate does not prove their controls. Ask for the measures, and add their cyber cover and their duty to notify you to the contract.The 24-hour early warning to the authority runs alongside the insurer's notification clause. Both clocks start at once, so the plan must handle both. Confirm with legal.
DORAFinancial entities keep an ICT risk framework and may use insurance as one risk-transfer measure within it. The framework and the residual risk must be documented and approved by the board.An ICT third party's policy is not one of the DORA contract clauses. Check the required clauses instead: audit rights, incident support, exit strategy.Major incident reporting to the supervisor within hours of classification, then 72 hours and one month. The insurer's forensics firm must be able to support that pace. Confirm with legal.
SOC 2If you issue a SOC 2, insurance is not a tested control. The auditor tests the same controls the questionnaire asks about, so both should tell the same story.Their SOC 2 report is exactly the evidence you would want them to hold for their own insurer. Exceptions in the report are questions to ask about their cover.The incident response the auditor tests is the one the insurer reviews. Contradictions between the two narratives become findings on both sides.
ISAE 3402Assurance over outsourced processes; insurance does not appear in it. Where a service organisation relies on insurance for continuity, user auditors may ask for the terms.Ask whether the service organisation's continuity plan and its cyber cover line up with the control objectives. The report cannot say so on its own.An incident at the service organisation touches your financial reporting controls. Their insurer's timeline and yours must not conflict with disclosure to the user auditors.
KaderWat het van u vraagtAls een leverancier u zijn rapport geeftAls dit incident u treft
NIS2Een verzekering vervangt de verplichte risicobeheersmaatregelen niet. Het bestuur moet de maatregelen zelf goedkeuren en bewaken en blijft aansprakelijk; boetes onder NIS2 zijn in de regel niet verzekerbaar.Een verzekeringscertificaat van een leverancier bewijst zijn maatregelen niet. Vraag naar de maatregelen, en neem zijn cyberdekking en zijn plicht om u te informeren op in het contract.De 24-uurs vroegtijdige waarschuwing aan de toezichthouder loopt naast de meldingsplicht van de polis. Beide klokken starten tegelijk, dus het plan moet beide aankunnen. Bevestig met legal.
DORAFinanciële instellingen houden een ICT-risicokader bij en mogen een verzekering daarin als één risico-overdrachtsmaatregel gebruiken. Het kader en het restrisico moeten gedocumenteerd en door het bestuur goedgekeurd zijn.De polis van een ICT-derde is geen van de DORA-contractbepalingen. Controleer in plaats daarvan de verplichte bepalingen: auditrechten, ondersteuning bij incidenten, exitstrategie.Melding van een ernstig incident aan de toezichthouder binnen enkele uren na classificatie, daarna 72 uur en een maand. Het forensisch bureau van de verzekeraar moet dat tempo kunnen volgen. Bevestig met legal.
SOC 2Geeft u zelf een SOC 2 af, dan is de verzekering geen geteste maatregel. De auditor test dezelfde maatregelen als waar de vragenlijst naar vraagt, dus beide moeten hetzelfde verhaal vertellen.Hun SOC 2-rapport is precies het bewijs dat u zou willen dat zij voor hun eigen verzekeraar bewaren. Afwijkingen in het rapport zijn vragen over hun dekking.De incidentrespons die de auditor test, is dezelfde die de verzekeraar beoordeelt. Tegenstrijdigheden tussen beide verhalen worden bevindingen aan beide kanten.
ISAE 3402Zekerheid over uitbestede processen; een verzekering komt er niet in voor. Waar een serviceorganisatie voor continuïteit op een verzekering vertrouwt, kunnen de auditors van klanten de voorwaarden opvragen.Vraag of het continuïteitsplan en de cyberdekking van de serviceorganisatie aansluiten op de beheersdoelstellingen. Het rapport kan dat niet uit zichzelf zeggen.Een incident bij de serviceorganisatie raakt uw beheersing van de financiële verslaggeving. De tijdlijn van hun verzekeraar en de uwe mogen niet botsen met de melding aan de auditors van de klanten.