On Monday the computer asks for a ransom. And this week's bookings?
A cyber attack on a small business is nothing like the films. It is the computer at reception that will not open, the booking system down and a week of takings hanging in the air. Allianz Cyber Plus pays for the IT assistance, the recovery of the data and the loss of profit while the business is at a standstill, and it answers the claims of third parties. We are in Adeje and we answer the phone here.
- Unlimited remote IT assistance and IT forensic experts
- Data recovery, restoring the backups and an anti-ransomware application
- Loss of profit from business interruption, and liability towards third parties
Who this is for
Four situations. If you recognise yourself in one of them, ten minutes are worth it.
- You have a booking engine, an online shop or a card terminal, and if the system goes down the business stops
- You keep customer data: names, DNI or passport numbers, phone numbers, payment details, records
- You work from several places, with laptops and phones that are also personal
- You are self-employed, and the computer is not a tool of the business: it is the business
Here almost every small business runs on a single system. The booking engine for the apartments, the card terminal in the restaurant, the diary in the hair salon, the software in a gestoría, the spreadsheet with twenty years of customers. If that locks up on a Saturday in August, the computer is not the problem: the whole weekend is, and so are the people standing at the door. And the firm that fixes it for you is usually on the mainland, sometimes in another language and almost always with a queue.
What it covers
The product is called Allianz Cyber Plus. These are the covers and services Allianz publishes on its own website and in its press release. We put nothing on this page that we cannot point at.
- Loss of profit from business interruption — the money that does not come in while you are stopped
- Claims for a data breach — the liability towards the third parties affected
- Data protection penalties (sanciones sobre protección de datos)
- Damage arising from acts in the media
- Recovery of accounts and data and restoring the backup
And these services, which in an attack are used before any cover is:
- IT assistance by phone and remotely, with no limit on the number of times
- Cloud backups of the company's IT systems, unlimited
- Anti-ransomware application — against the software that encrypts your files and demands a ransom
- IT forensic experts and a forensic certificate after the claim
- Legal advice, regulatory adaptation and data protection compliance
The forensic certificate looks like a detail and is the opposite. It is the document that explains what happened and when: the one the Spanish data protection authority AEPD wants to see if a breach has to be notified, the one a customer making a claim asks for, and the one the bank asks for. Without it, an attack is a story told from memory.
The limit of each cover, the excesses and the time limits are those of the policy and the nota informativa. We show them to you before you sign, on paper, with the level of cover filled in.
The four levels, and who the product is for
Allianz published this itself, with names and a figure: four levels with the same covers and services, differing only in the indemnity limits of the liability cover, per claim and per year.
- Básico, Óptimo, Extra and Ampliado, with limits from €150,000 up to €600,000.
- It is designed for self-employed people and small and medium firms with a turnover of up to €25 million and up to 150 IT devices in use, among other criteria.
That turnover figure is far above almost everything in the south of Tenerife. The number that really has to be counted is the devices: computers, laptops, work phones, the card terminal, the tablets for the tables, the cameras. It usually comes to more than people say off the top of their head.
Source: Allianz Seguros press release of 2 July 2024 on Allianz Cyber Plus. We confirm the criteria and limits in force with you when we quote.
The 72 hours of the GDPR, which depend on no insurance
This is the part almost nobody knows, and the part that costs money even when the attack was small. If the personal data you hold is compromised, the law starts a clock.
- Article 33 of the GDPR (Regulation EU 2016/679): a personal data breach must be notified to the Spanish data protection authority, the AEPD, without undue delay and at the latest within 72 hours of becoming aware of it — unless it is unlikely to result in a risk to the people affected.
- Article 34: if the breach is likely to result in a high risk to those people, they have to be told as well.
- Article 83: fines go up to €20 million or 4% of total worldwide annual turnover, whichever is higher. That is the ceiling in the regulation, not a forecast for you: the amount is set by the AEPD according to the seriousness, what you did to prevent it and what you did afterwards.
Those 72 hours are the reason this policy makes sense in a business with ten people. It is not the indemnity: it is having someone to call on day one, with a forensic expert and a lawyer who knows what has to be notified and what does not.
The data protection penalties cover exists, but how far it goes — and which penalties are insurable at all under the law — is in the policy. We read that with you before you sign, not on the day the letter arrives. We promise nothing here that we cannot show you in writing.
And one thing we earn nothing from, which you should write down anyway: Spain has a free cybersecurity helpline, 017, run by INCIBE, for companies and self-employed people as well, 365 days a year from 08:00 to 23:00. On the day of an attack, call them — and call us. The first hours are the ones that count.
What this is not
We would rather say it here than after something has happened.
- It is not an IT maintenance contract. It does not replace the person who looks after your computers, and it does not take work away from them: in an attack both of them work.
- It does not replace backups, antivirus or two-factor login. Insurance pays for the damage; it does not prevent the attack. If you have no backups, no policy gives you back the data from 2014.
- It is not the general public liability of the business. A customer who slips in your shop goes through the business policy, not through this one.
- It does not cover what has already happened. An attack that started before you signed is not included — and that is not Allianz small print: article 4 of the Insurance Contract Act, Ley 50/1980, makes the contract void where the loss had already occurred when it was signed.
- It is not cybersecurity advice. The person who sets up your firewall, separates your networks and configures your backups is an IT specialist. We do insurance — and we say so, so that you do not end up missing one because you think you have it through the other.
- General legal expenses cover goes another way. Ask us and we will tell you which, with no obligation.
Is it compulsory?
No. No rule obliges a business to hold cyber insurance. What is compulsory is something else, and the two should not be confused.
- Complying with the GDPR and with the Spanish data protection act, Ley Orgánica 3/2018 (LOPDGDD): appropriate security measures, the record of processing activities, and notifying breaches. The law requires that whether you have a policy or not.
- Sometimes it is asked for by a large customer, a hotel chain or a contract with a public body. Then it is compulsory for you under a contract, not under the law. If you are asked for it, tell us: what matters then is the limit they require, not just having a policy.
And the reason that depends on no rule at all: a small business can survive losing a computer. What it cannot survive is losing ten days of takings in high season and the customer list at the same time.
How it works
- You call, write on WhatsApp or drop into the office. Tell us which programs you use, how many devices there are, whether you have backups and where they are, roughly what you turn over, and whether you store customers' payment details.
- We work out the price and give you the proposal in writing, dated, with the level and the limit on it. It costs nothing and commits you to nothing.
- If you say yes, it is signed, and you are left with two phone numbers: the IT assistance line and ours. On the day of an attack, call us too.
Keep both numbers somewhere outside the computer. In a ransomware attack, the file where the phone numbers are written down tends to be exactly the one that will not open.
Why with us
- Office in San Eugenio Alto, Adeje. Monday to Thursday, 10:00 to 17:00. A street address, not a contact form.
- We work in Spanish, German and English. In an attack you have to explain quickly what happened, and doing that in your own language saves hours.
- We are an exclusive Allianz agency. The claim is handled with us, not with a distant phone number and not with a mailbox.
- 4.8 out of 5 stars on Google, from 52 customer reviews (September 2026). See the reviews (opens in a new window)
Frequently asked questions
We are four people and a hair salon. Isn't this for big companies?
The opposite: the product is designed for self-employed people and small firms. A big company has an IT person on the payroll; you have a mobile number for someone you know. The difference between the two is not the attack, it is the first hour afterwards.
My backups are on a hard drive behind the counter.
That is better than nothing and worse than it looks. Ransomware encrypts whatever it finds connected, and a drive that is always plugged in is connected. That is exactly why cloud backups are in the policy: not a nice extra, but the copy the attack cannot reach.
What if the attack comes in through an employee's phone?
That is the most common route, and also the one to settle before you sign. Which devices and which uses are inside the cover is in the policy. Tell us how you really work — personal phones, wifi shared with customers, a laptop somebody takes home — and have it written in from day one. What is not said beforehand is argued about afterwards.
Someone changed the bank account on an invoice by email and I paid it. Is that covered?
That is the fraud we see most often, and we are not going to promise it to you from a web page. Whether it is covered, under which cover and up to what limit depends on the policy you sign. Ask us before you take it out and you will get the answer in writing. In the meantime the measure that works costs nothing: when a supplier changes their bank account by email, phone them on the old number before you transfer.
What do I do in the first hours of an attack?
Disconnect the machine from the network and from the wifi. Do not format or reinstall anything: the IT forensic experts may need the machine exactly as it is, and without that there is no forensic certificate. Do not pay any ransom without talking to anyone first. Call us, and call 017. And write down the time you noticed each thing: that piece of paper is worth a lot if the AEPD has to be notified.
Do I need a data protection officer?
Almost certainly not. The GDPR only requires one in certain cases (article 37), and the LOPDGDD extends the list of those obliged (article 34): public bodies, large-scale processing, particularly sensitive data. A restaurant or a hair salon is not normally on it. The person who says so with certainty is your gestor or a data protection specialist, not us: we do insurance.
I already have business insurance. Doesn't it cover this?
Bring us the policy you have. We read it and tell you in writing what is covered, what is not and with what limits. We are an exclusive Allianz agency: what we can offer you is an Allianz policy, not a market comparison. If what you already have covers you, we will tell you that too — and on that day we sell nothing.
This information is for guidance. The covers, limits, excesses and exclusions that apply are those of the Allianz policy and the nota informativa. We name the rules so that you can check them; this is neither legal advice nor data protection advice.
