What is it?

Concrete help when the business is attacked

It finances and organises the first response: hotline, IT experts, restoration, legal support, communication, business interruption losses and liability.

Mandatory?

No, but response obligations are increasing

Cyber insurance is not mandatory, but the Swiss Data Protection Act requires certain data breaches to be reported quickly to the FDPIC. Critical infrastructures have also had reporting obligations to the Federal Office for Cybersecurity since 2025.

What does it cover?

Crisis, losses, fraud and third parties

Ransomware, phishing, data leaks, business interruption, payment fraud, notification and third-party claims may be covered depending on the policy.

Simple cyber insurance diagram

An incident hits data, continuity and liability at once.

  1. Support Assistance and crisis Experts, comms, ransom by policy
  2. Critical Interruption and costs Getting systems back online
  3. Core Data and cyber liability Breach, notification, claims
  4. Base Critical systems What stops the business if down

Prevention matters as much as the policy.

Why Swiss SMEs are exposed

Cyberattacks do not only target large companies. A fiduciary, medical practice, shop, industrial SME or service company can be paralysed by a compromised mailbox, stolen VPN access, ransomware, a fake invoice or an affected IT provider.

The main cost is not always the ransom. It often comes from several days of downtime, experts to mobilise, data to restore, customers to inform, diverted payments and loss of trust. Good cyber insurance does not replace prevention, but it provides a team and a budget when every hour counts.

The path of a cyber claim

Detection + Hotline + Forensics + Restoration + Notification + Recovery

The value of the policy is mainly seen in immediate access to specialists: forensics, negotiation, restoration, legal support, crisis communication and coordination with your IT providers.

Module
What it can finance
Point to watch
Crisis managementImmediate response
24/7 hotline, IT experts, forensics, legal advice, communication and steering of the first decisions.
Check whether providers are imposed, available in Switzerland and included in the insured sum.
Own lossesSystems and operations
Data restoration, reinstallation, additional costs, business interruption and cyberextortion depending on conditions.
Compare the waiting period, indemnity period, required backups and ransomware exclusions.
Cyber liabilityCustomers and third parties
Defence costs and claims linked to a data protection breach, data loss or security failure.
Check limits, deductibles, territories, data entrusted to subcontractors and notification obligations.
Digital fraudDiverted payments
Fake invoice, CEO fraud, social engineering, e-banking manipulation or identity theft.
Often optional, with sub-limits and mandatory internal procedures to follow.

Swiss rules to know

Under the new Federal Act on Data Protection, a company must notify the FDPIC of data security breaches that are likely to result in a high risk to the personality or fundamental rights of the persons concerned. The affected persons must also be informed when this is necessary for their protection or when the authority requires it.

Since 1 April 2025, operators of critical infrastructure must report certain cyberattacks to the Federal Office for Cybersecurity within 24 hours of detection. If your business processes data from EU residents or operates in a regulated sector, other obligations may apply.

Common pitfalls

Cyber insurers increasingly check the measures declared. A useful policy must match your real IT maturity.

MFA declared but absentSensitive, cloud, email and administration access must match the declarations.
Untested backupsA backup connected to the network can be encrypted at the same time as the rest.
Fraud not includedSocial engineering and fake payment orders are sometimes optional or sub-limited.
Cyber and technical risks confusedUne panne matérielle relève plutôt des assurances techniques.

I already have this policy. How can I cancel or change insurer?

Before switching, compare security requirements, waiting periods, limits, sub-limits, notification costs, fraud, ransomware, cyber war and imposed providers. You also need to avoid a gap between two contracts, as an already known incident may be excluded from the new contract.

How to size cyber insurance

The right level depends on your turnover, the number of people affected by your data, your dependence on the cloud, your ability to work without IT and your exposure to payments. An online shop, fiduciary, medical practice, IT provider or industrial company will not have the same priorities.

Finwise regarde aussi les contrats avec vos prestataires IT, vos sauvegardes, votre plan de réponse à incident, votre Professional liability, votre assurance commerce et les risques techniques qui ne relèvent pas du cyber.

With Finwise

We compare the policy with your real IT situation

We do not stop at the price. We check usable cover, security prerequisites, exclusions, sub-limits, business interruption and coordination with your other business policies.

Finwise Assurances partner logos

Assess my cyber risk See technical insurance

Let’s talk about your needs

Tell us about your situation in a few lines. A Finwise adviser will contact you to clarify your options and compare suitable solutions.