Skip to content

Know today whether cyber insurance makes sense for your business.

Some businesses genuinely need cyber insurance. Others much less. We tell you which group you are in.

Not every business needs this

There are businesses for which cyber insurance is unnecessary, and businesses where a single incident costs months of work. The difference is not your size, but the way you work.

Think of:

  • An invoice that appears to come from your supplier, with the money ending up in the wrong account.
  • A till system down for three days.
  • A customer database out in the open.
  • Accounts locked up by someone in exchange for a ransom.

Cyber insurance can cover that loss, and with many policies more than money comes with it: IT specialists, lawyers and crisis support who help you handle the incident while it is still running.

Where exactly your risk sits depends on your activity. If you work a lot with invoices and transfers, fraud is your main exposure. If you manage personal data of customers, a data breach is your biggest worry. And some businesses work so little digitally that the premium is not worth it.

That distinction is not something you pull out of a comparison table. For that, we first need to know how you work, and that is where the conversation begins.

What you get in that one conversation

We ask the questions needed to assess your risk properly: which systems you use, how payments are handled, which data you keep. All things you can answer without any IT knowledge.

Because we are a broker and not an insurer, we have no policy of our own to sell. We compare what different insurers offer for your activity and explain where the differences lie. In cyber, that difference is mostly in the support you get during an incident, and less in the sums insured.

If we conclude that cyber insurance adds little in your situation, we say so too. You will not have lost half a day over it, and you know where you stand.

One thing is useful to know in advance: in cyber, insurers also look at the security of your business. We tell you which of those points actually carry weight in your case for your cover, so you do not start with the wrong things.

Everything runs through chat and stays in the same conversation. If something changes in your business, or something goes wrong, you pick up the thread where you left it.

How to start

  1. You send a message through the chat on this page.

  2. You answer a few targeted questions about your business. No long questionnaire.

  3. You get a tailored proposal usually within two working days, explaining what is covered, up to what amount, and what is not in the policy.

  4. If you agree, you confirm the proposal.

Do you already have a cyber policy? Send it to us and we will tell you what it does and does not include, even if the answer is that you need to change nothing.

What a conversation with Ōmata looks like

You do not need to know which policy you are looking for, and there is no form to fill in.

Start your request

Viktor is online

You are talking to an AI assistant. You can ask for a human colleague to take over at any time.

  • CustomerOur server is encrypted, we are completely down. What now?
  • ŌmataDisconnect the affected devices from the network, but do not switch them off — that erases traces. Do you hold a cyber policy?
  • CustomerNo idea. We do have public liability and a fire policy.
  • ŌmataThose do not cover this. What sector are you in, and do you hold customer data?
  • CustomerE-commerce, we keep names, addresses and order history.
  • ŌmataNoted. I will pass this on to our expert immediately, as a priority. You will hear from us today.

Try it yourself

What cyber insurance covers

Cyber insurance usually covers seven things: recovery of your systems, the revenue lost while your business is down, your liability towards customers whose data was exposed, the duty to notify the Data Protection Authority, crisis support, extortion and — usually as a separate option — fraud.

  • Recovery Rebuilding servers and workstations, restoring backups, and a forensic investigation of what happened.
  • Business interruption The revenue lost while your business is down.

    Usually the largest figure, after eight to twelve hours of waiting period.

  • Liability The loss suffered by customers or suppliers whose data was exposed through you, plus your defence costs.
  • Notification duty Reporting to the Data Protection Authority within 72 hours, and informing those concerned where required.
  • Crisis support Communication and legal guidance in the first days after an incident.
  • Extortion With ransomware, a specialist negotiator and guidance on the decision that follows.
  • Fraud A forged invoice or an impersonated instruction from the director, usually as a separate option.

What cyber insurance does not cover

Not covered are a vulnerability for which an update already existed and you did not install it, the hardware itself, and damage from war or state actors. Whether a GDPR fine or a ransom can be reimbursed differs per policy and belongs in your proposal. Lost revenue without figures cannot be calculated.

  • Known, unpatched vulnerabilities A vulnerability for which an update already existed and you did not install it.

    The most common reason for refusal.

  • Uninsurable fines Whether a GDPR fine falls into that category, and whether a ransom can be reimbursed, differs per policy.

    That belongs in your proposal.

  • The hardware itself A burnt-out server or a stolen laptop falls under your fire or electronics policy.
  • War and state actors Worded more tightly since 2023, and worth checking when you compare.
  • Unprovable lost revenue Without figures from before the incident, business interruption cannot be calculated.

Just ask

What an insurer expects from you

Insurers look at four measures that come back on almost every questionnaire. Which of them weigh most in your case depends on your activity.

  • Two-factor authentication

    On mail, on accounting and on anything reachable from outside.

  • Offline backups

    And tested at least once to confirm they can actually be restored.

  • Update policy

    Who installs them, and within how many days of release.

  • Awareness

    Most incidents start with a click, not with a breached firewall.

NIS2: do you supply a larger company?

NIS2 requires companies in a range of sectors to check the security of their suppliers too. Those requirements reach you by contract, even if you are not in scope yourself.

A customer suddenly sending a questionnaire about your security? That is usually what is going on. Mention it when you open your file.

What determines the price

A number without your details is a guess. What drives the premium we can list in full.

  • Annual turnover

    At practically every insurer, the basis of the calculation.

  • Sector

    Healthcare, e-commerce and public-sector suppliers sit higher.

  • Volume of data

    And whether it includes special categories.

  • Sum insured

    And the excess you take on yourself.

  • Waiting period

    Eight hours costs more than twenty-four.

  • Your measures

    The only factor you can still change today.

Frequently asked questions

Is cyber insurance already part of my public liability cover?

No. Public liability covers damage you cause to third parties during the normal running of the business, such as a customer falling in your shop. Damage to your own systems, the revenue lost while you are down and the notification costs after a breach are not included.

What should I do if it happens tonight?

Disconnect the affected devices from the network but do not switch them off, as that wipes traces. Do not call any ransom number and do not reply to the attacker. Notify your insurer or broker the same evening: most cyber policies have a 24-hour line, and the first hours largely determine the size of the loss.

Is paying a ransom insured?

Some policies provide assistance in case of extortion, including a specialist negotiator. Whether the payment itself is reimbursed depends on the policy and on what the law permits. That belongs explicitly in your proposal and is not a question a product page can answer for you.

How quickly must I report a data breach?

Where personal data has been exposed, the GDPR requires notification to the Data Protection Authority within 72 hours of discovery. If the consequences for the individuals are serious, you must inform them too. A cyber policy generally covers the cost of that notification and the support around it.

Am I in scope for NIS2?

NIS2 applies to companies in a number of designated sectors above a certain size. But those outside its scope often get the requirements passed down by contract, because in-scope customers have to check the security of their suppliers. A customer questionnaire is usually the first sign.

What if the attack started at my IT supplier?

Towards your own customers you are still the party that processed their data. A cyber policy covers your costs and your liability, and can then pursue the supplier. Waiting until the question of fault is settled is the most expensive order to do it in.

Who is behind Ōmata?

Ōmata Insurance is the AI-first studio of the Induver group and a sister company of Group Induver NV: two companies within the same group, not parent and subsidiary. Ōmata puts you in touch with Group Induver NV, an insurance broker with FSMA number 016880; that is where the advice and the policy come about. The full identification is on the legal notices page.

About Ōmata

Ōmata is the AI-first insurance studio of Group Induver. You tell us what you want to insure over chat; usually within two working days you receive a proposal, drawn up by an insurance broker at Group Induver NV, registered with the FSMA under number 016880.

Ready to start?

Send us a message and tell us briefly what you want to insure. You get an immediate reply and your proposal usually within two working days.