Key points at a glance
- Small firms and the self-employed are attacked too, mostly in automated campaigns that ignore company size.
- Depending on the policy, cyber insurance covers forensics, recovery, business interruption and third-party claims.
- Insurers require minimum standards such as backups, updates and two-factor authentication. Failing to meet them can reduce payouts.
- A policy makes most sense where a multi-day outage or a data leak would seriously threaten the business.
Why small businesses are targets
The idea that there is nothing worth stealing rarely survives a sober look. Every SME holds customer data, handles payments and relies on systems without which work stops. The Swiss Federal Office for Cyber Security (NCSC) receives tens of thousands of reports on cyber incidents every year, and phishing, fraud attempts and ransomware regularly hit micro-businesses as well.
Typical weak points in smaller firms include:
- IT is managed on the side, with no clear responsibility for updates, backups and access rights.
- Weak or reused passwords and no two-factor authentication.
- Little awareness of fake invoices, phishing and CEO fraud calls.
- Knowledge of systems sits with one person or a single external partner.
- Backups exist but have never been tested to see whether they can actually be restored.
What cyber insurance typically covers
Products on the Swiss market are modular and differ considerably in the details. The overview below shows the usual building blocks and what to check in the contract.
| Module | What it covers | What to check |
|---|---|---|
| First-party loss | Forensics, data recovery, rebuilding systems | Whether hardware replacement is included |
| Business interruption | Lost income and extra costs after an attack | Waiting period in hours and indemnity period |
| Liability | Third-party claims, for example after a data leak | Defence against unjustified claims, cover abroad |
| Assistance and crisis support | Hotline, IT specialists, legal and communications advice | 24/7 availability, language, response time |
| Fraud and social engineering | Misdirected payments after fake payment instructions | Often only an add-on with a low sub-limit |
Ransom payments
Whether and under which conditions ransom payments are covered varies by policy and is legally and ethically contested. Authorities generally advise against paying. Clarify this point explicitly with the insurer.
Obligations and common exclusions
Before signing, the insurer will usually ask about your security set-up. Your answers become part of the contract. Giving incorrect information or failing to maintain promised measures can lead to reduced or refused payouts when a claim occurs.
- Regular backups kept separate from the network, with documented restore tests.
- Timely security updates for operating systems, software and firewall.
- Two-factor authentication for email, remote access and administrator accounts.
- Up-to-date malware protection and clear rules for access rights.
- Staff awareness training at least once a year.
Common exclusions cover known but unfixed vulnerabilities, damage from outdated systems without vendor support, acts of war and widespread infrastructure failures such as power or internet outages. The exact wording decides, so read these clauses in full.
Who benefits from a policy
Cyber insurance is one element of risk management, not a substitute for protection. Its biggest practical benefit is often immediate support: if you do not know whom to call in an emergency, you lose valuable hours. It is particularly useful when:
- orders, invoices and appointments depend entirely on IT systems;
- you process sensitive personal data, such as health or financial information;
- there is no in-house IT team and external emergency help is not contractually secured;
- a one-week outage would seriously strain liquidity.
The premium depends on sector, turnover, sum insured, deductible and security level. Obtain several quotes and compare not just the price but scope, sub-limits and waiting periods. Industry associations also offer solutions; according to the provider, the Swiss managers’ association SKV, for instance, has developed a product with a specialist insurer that the self-employed and SMEs can take out online.
Legal framework
Under the revised Data Protection Act, in force since September 2023, data breaches posing a high risk must be reported to the Federal Data Protection and Information Commissioner (FDPIC). Operators of critical infrastructure must also report cyberattacks to the NCSC. Check the rules currently in force and consult a specialist if in doubt.
Frequently asked questions
Is cyber insurance enough if we change nothing else?
Doesn’t our general liability policy already cover cyber losses?
How much does cyber insurance cost for an SME?
What should we do first in an incident?
Can sole traders and freelancers be insured too?
The key question for an SME is not whether it is too small for attackers, but how well prepared it is for an incident. A suitable policy complements that preparation but does not replace it.