What insurance requirements must your security meet?
Insurers set concrete security requirements for companies before issuing a policy or making a payout. These requirements focus on physical access security, camera surveillance, alarm systems, and access control. The exact conditions vary by insurer, industry, and your company's risk profile. If you have questions about what your situation requires, you can always contact with a security specialist who helps you further.
Which security measures do insurers require?
Insurers typically require a combination of burglary detection, camera surveillance, adequate locks, and a certified alarm system connected to a monitoring center. The exact measures required are described in the policy conditions and depend on the insured value and the risk profile of your location.
In practice, the following requirements are most common:
- Certified alarm system with notification to a recognized private alarm center
- Burglar-resistant hardware that meets a minimum resistance class
- Camera surveillance that covers entrances, exits and critical areas
- Access control which prevents unauthorized access to sensitive zones
- Safe storage for valuable goods or cash above a certain threshold
Insurers base these requirements on risk classifications. A higher insured value or a location in a high-risk area almost always leads to stricter conditions. It is therefore wise to read the policy conditions thoroughly and compare them with your current security level before signing a policy.
What happens if your security does not meet the requirements?
If your security does not comply with the policy conditions, the insurer may refuse or significantly reduce the payout in the event of a claim. In serious cases, the insurer may even declare the policy void, which means that you were never insured for that damage.
The consequences are concrete and can be far-reaching:
- Partial benefit: The insurer pays only a portion of the damage based on contributory negligence or fault.
- Complete refusal: in case of gross negligence or willful failure to comply with policy conditions
- Cancellation of the policy: The insurer terminates the agreement after a claim notification.
- Higher premium: Upon renewal, an increased risk may lead to a higher annual premium.
Many companies only realize this at the moment of an actual burglary or fire. At that point, it is too late to still meet the requirements. Preventive checks of your security situation are therefore not a luxury, but a business necessity.
How does the security requirement differ by type of company?
The security requirements of insurers vary significantly by business type, depending on the nature of the activities, the value of the assets present, and the public nature of the location. A jeweler has different obligations than an office building or a manufacturing company.
Insurers typically use risk categories that determine the required level of security:
- Retail and jewelers: strict requirements for safe storage, alarm class, camera surveillance, and sometimes also security personnel outside opening hours
- Offices and service providers: focus on access control, intrusion detection, and security of server rooms or archives
- Production and logistics: emphasis on perimeter security, camera surveillance of loading and unloading zones, and vehicle security
- Hospitality and events: requirements regarding safe storage of daily turnover and security during closed hours
In addition to the industry, location also plays a role. Companies in areas with a higher risk of burglary are typically subject to additional requirements. Always ask your insurer which risk category your company falls into and what the corresponding minimum requirements are.
Which certifications or standards do insurers accept as proof?
Insurers generally accept installations and systems that comply with recognized Dutch and European standards as proof of adequate security. The most common are the SKG, KIWA, and VdS certifications for locks and alarm systems, and the NEN standards for installations.
The most relevant certifications and standards are:
- SKG certification: for hinges and locks, divided into resistance classes that indicate how long a lock resists burglary
- BORG certification: for security companies and installers who install and maintain alarm systems
- NEN 2678 and NEN 50131: standards for intrusion detection systems and their installation
- Secured Living or Working Quality Mark: an integrated quality mark that combines multiple security aspects
- ISO 27001: relevant for companies where digital security and physical access control converge
It is advisable to always ask for the accompanying certificates when purchasing or installing security systems. Keep this documentation carefully, as the insurer may request it in the event of a claim as proof that you complied with the policy conditions at the time of the damage.
How do you check if your current security is insured?
You check whether your current security meets insurance requirements by comparing the policy conditions with your actual security situation. Compare point by point which measures are required and which you have actually implemented and documented.
A practical approach consists of the following steps:
- Read the policy conditions thoroughly: Search specifically for the sections on prevention, security, and deductible for negligence
- Inventory your current measures: Make a list of all existing security systems, including brand, type, and certification.
- Check the certificates: Have all installations been carried out by a BORG-certified company and do they meet the required standards?
- Assess the access control: Is it clear who has access to which rooms, and are access rights regularly updated?
- Request a security audit: A professional security company can assess your location against standard insurance requirements.
The access control component, in particular, is underestimated by many companies. Insurers are increasingly looking not only at physical locks but also at who had access, when, and whether this is verifiable. A well-designed access management system provides the necessary logging and control for this.
Are you unsure if your security is in order, or would you like a professional assessment of your situation? Contact us contact Sellox for a no-obligation consultation.
Frequently Asked Questions
Do I need to actively inform my insurer if I change or expand my security?
Yes, it is mandatory to notify your insurer of significant changes to your security situation, including both improvements and deteriorations. For example, if you remove an alarm system or change the access structure, this may affect your coverage. Inform your insurer of every relevant change and request written confirmation that your policy remains valid under the new situation.
How often do I need to have my security systems serviced to continue meeting the insurance conditions?
Most insurers require certified security systems to be inspected and maintained by a BORG-certified company at least once a year. This applies particularly to alarm systems and access control systems. Ensure that you always keep the maintenance reports, as the insurer may request proof of regular maintenance as part of the claims process in the event of a claim.
What is the most common mistake companies make when taking out security business insurance?
The most common mistake is taking out a policy without thoroughly reading the security conditions and comparing them with the existing situation. Many companies assume that their current security is sufficient, without specifically verifying this against the policy conditions. A second common mistake is failing to maintain documentation, such as certificates and maintenance reports, which means that in the event of a claim, one cannot demonstrate that the requirements were met.
As a tenant of commercial premises, can I be held liable for security requirements, or is that the landlord's responsibility?
As a tenant, you are responsible for the security of your own business operations, inventory, and goods, regardless of who owns the premises. The landlord is generally responsible for the basic security of the building itself, but the additional requirements under your business insurance fall under your responsibility. Clearly stipulate in the lease agreement who is responsible for which security measures so that there is no ambiguity regarding liability in the event of damage.
Does the same level of security apply to my company if I operate at multiple locations?
Not necessarily: each location is assessed individually by insurers based on its own risk profile, such as the goods present, the risk of burglary in the area, and the nature of the activities at that location. It is possible that stricter requirements apply to one branch than to another. Check the policy conditions for each location and ensure that each branch individually meets the stated minimum requirements.
What can I do if my insurer sets requirements that I find difficult to meet, either technically or financially?
In that case, contact your insurer immediately to discuss which alternatives or temporary measures are acceptable. Some insurers offer the option to submit an implementation plan, in which you demonstrate that you will meet the requirements step by step. Additionally, consult an independent security specialist who can help find cost-effective solutions that still meet the set standards.
Does digital security, such as cybersecurity, count towards the security requirements of business insurance?
Increasingly so, particularly for companies where physical and digital access are intertwined, such as with cloud-based access control systems or server rooms. Some insurers impose additional requirements on digital access security and logging as part of the physical security conditions. For full cybersecurity coverage, a separate cyber insurance policy is usually required; discuss with your insurer how the two policies complement each other to avoid gaps in your coverage.