Cyber insurance for SMEs: when it pays off and what it covers

5 min read
MaxQ editorial team
Independent guide · editorially reviewed
Last checked: September 25, 2026

Key points at a glance

  • Small firms and the self-employed are attacked too, mostly in automated campaigns that ignore company size.
  • Depending on the policy, cyber insurance covers forensics, recovery, business interruption and third-party claims.
  • Insurers require minimum standards such as backups, updates and two-factor authentication. Failing to meet them can reduce payouts.
  • A policy makes most sense where a multi-day outage or a data leak would seriously threaten the business.

Why small businesses are targets

The idea that there is nothing worth stealing rarely survives a sober look. Every SME holds customer data, handles payments and relies on systems without which work stops. The Swiss Federal Office for Cyber Security (NCSC) receives tens of thousands of reports on cyber incidents every year, and phishing, fraud attempts and ransomware regularly hit micro-businesses as well.

Typical weak points in smaller firms include:

  • IT is managed on the side, with no clear responsibility for updates, backups and access rights.
  • Weak or reused passwords and no two-factor authentication.
  • Little awareness of fake invoices, phishing and CEO fraud calls.
  • Knowledge of systems sits with one person or a single external partner.
  • Backups exist but have never been tested to see whether they can actually be restored.

What cyber insurance typically covers

Products on the Swiss market are modular and differ considerably in the details. The overview below shows the usual building blocks and what to check in the contract.

ModuleWhat it coversWhat to check
First-party lossForensics, data recovery, rebuilding systemsWhether hardware replacement is included
Business interruptionLost income and extra costs after an attackWaiting period in hours and indemnity period
LiabilityThird-party claims, for example after a data leakDefence against unjustified claims, cover abroad
Assistance and crisis supportHotline, IT specialists, legal and communications advice24/7 availability, language, response time
Fraud and social engineeringMisdirected payments after fake payment instructionsOften only an add-on with a low sub-limit

Ransom payments

Whether and under which conditions ransom payments are covered varies by policy and is legally and ethically contested. Authorities generally advise against paying. Clarify this point explicitly with the insurer.

Obligations and common exclusions

Before signing, the insurer will usually ask about your security set-up. Your answers become part of the contract. Giving incorrect information or failing to maintain promised measures can lead to reduced or refused payouts when a claim occurs.

  1. Regular backups kept separate from the network, with documented restore tests.
  2. Timely security updates for operating systems, software and firewall.
  3. Two-factor authentication for email, remote access and administrator accounts.
  4. Up-to-date malware protection and clear rules for access rights.
  5. Staff awareness training at least once a year.

Common exclusions cover known but unfixed vulnerabilities, damage from outdated systems without vendor support, acts of war and widespread infrastructure failures such as power or internet outages. The exact wording decides, so read these clauses in full.

Who benefits from a policy

Cyber insurance is one element of risk management, not a substitute for protection. Its biggest practical benefit is often immediate support: if you do not know whom to call in an emergency, you lose valuable hours. It is particularly useful when:

  • orders, invoices and appointments depend entirely on IT systems;
  • you process sensitive personal data, such as health or financial information;
  • there is no in-house IT team and external emergency help is not contractually secured;
  • a one-week outage would seriously strain liquidity.

The premium depends on sector, turnover, sum insured, deductible and security level. Obtain several quotes and compare not just the price but scope, sub-limits and waiting periods. Industry associations also offer solutions; according to the provider, the Swiss managers’ association SKV, for instance, has developed a product with a specialist insurer that the self-employed and SMEs can take out online.

Legal framework

Under the revised Data Protection Act, in force since September 2023, data breaches posing a high risk must be reported to the Federal Data Protection and Information Commissioner (FDPIC). Operators of critical infrastructure must also report cyberattacks to the NCSC. Check the rules currently in force and consult a specialist if in doubt.

Frequently asked questions

Is cyber insurance enough if we change nothing else?
No. The policy cushions the financial impact and provides help in an emergency, but it assumes a minimum level of protection. Without backups, updates and trained staff the risk remains high and payouts may be cut.
Doesn’t our general liability policy already cover cyber losses?
Usually only to a very limited extent, if at all. First-party costs such as recovery and lost income are generally not covered there. Have your existing policies checked for gaps and overlaps.
How much does cyber insurance cost for an SME?
There is no reliable flat figure. The premium depends on sector, turnover, sum insured, deductible and security level. Compare several quotes based on identical parameters.
What should we do first in an incident?
Disconnect affected devices from the network without switching them off, call the insurer’s or IT partner’s emergency number and delete nothing without advice. Incidents can be reported to the NCSC; where a crime is involved, filing a police report is advisable.
Can sole traders and freelancers be insured too?
Yes, many insurers offer products for very small businesses with a simplified application. Here too, look at scope and obligations, not only at a low premium.

The key question for an SME is not whether it is too small for attackers, but how well prepared it is for an incident. A suitable policy complements that preparation but does not replace it.