What is it?

Protect the business when digital systems fail

Cyber risks affect invoicing, customer data, reputation and continuity. Cyber insurance organises the response and finances recovery.

Mandatory?

No, but response obligations exist

The policy is not mandatory. However, nLPD requires certain breaches to be reported to the FDPIC, and critical infrastructures have NCSC deadlines.

Key point

Security first, insurance second

Without MFA, tested backups and controlled access, the premium rises and some covers may be refused.

Cyber priorities

Critical systems, data, interruption: in that order.

  1. Crisis Assistance Experts and communication
  2. Critical Interruption Getting back online
  3. Core Data / liability Breach and claims

A policy without prevention stays fragile.

Why SMEs are concerned

Cybercriminals do not only target large groups. An SME can be hit by a phishing email, a compromised password, poorly secured remote access, an attacked provider or ransomware that encrypts files and blocks activity.

The real cost often exceeds IT repair: loss of turnover, expert fees, crisis communication, customer notification, legal advice, reputational damage and liability to third parties.

Module
What it protects
To check
Crisis managementResponse
Hotline, IT experts, forensics, legal support and communication in the first hours.
Availability of providers, inclusion in the sum insured.
Own damageContinuity
Restoration, business interruption, additional costs and cyber extortion depending on the contract.
Waiting period, indemnity duration, backup requirements.
Liability / fraudThird parties
Customer claims, data notification, fake invoice or identity theft.
Sub-limits, internal procedures, cloud and provider cover.

The path of a cyber incident

Detection + Hotline + Restoration + Notification = Recovery

La valeur d’une cyberassurance se voit surtout dans l’accès immédiat aux spécialistes, pas seulement dans le remboursement final.

nLPD and response obligations

Swiss data protection law requires reporting to the FDPIC security breaches that are likely to result in a high risk to the personality or fundamental rights of the persons concerned. The report must be made as soon as possible and describe at least the nature of the breach, its consequences and the measures taken or envisaged.

If this is necessary to protect the persons concerned, or if the FDPIC requires it, the company must also inform them. Since 2025, certain critical infrastructures must also report cyberattacks to the NCSC within 24 hours. If your activity touches the EU, other deadlines may apply.

Phishing

An employee clicks on a fake email and gives away their access. Messaging and invoicing quickly become vulnerable.

Ransomware

Encryption blocks the ERP, cash register or files. Without an isolated backup, downtime can last several days.

Data breach

Customer or employee data is copied. You must restore, notify and manage liability to third parties.

Digital fraud

A fake invoice or identity theft triggers a transfer. Internal procedures become decisive.

Common pitfalls

Mistakes are rarely paid when taking out the policy. They appear when the incident really blocks activity.

SME "too small"Attackers also target structures that depend on their digital tools.
Equipment without continuityInsuring computers without business interruption leaves cash flow exposed.
Connected backupsIf they are on the same network, ransomware can hit them too.
Premium aloneSub-limits, exclusions and security prerequisites matter as much as the price.

You already have a policy: what should you check?

Contrôlez MFA, sauvegardes testées, droits d’accès, couverture cloud, sous-limites ransomware/fraude, durée de perte d’exploitation et procédure d’appel d’urgence. Un audit rapide compare la sécurité réelle et les garanties utiles, en lien avec la protection juridique et la Professional liability.

With Finwise

We help you prepare for the crisis before it happens

We analyse your digital dependency, sensitive data, critical tools and security level. Then we compare cyber insurance according to real covers, crisis management, sub-limits and business interruption.

Finwise Assurances partner logos

Assess my cyber risk View cyber insurance View legal protection

Let’s talk about your needs

Tell us about your situation in a few lines. A Finwise adviser will contact you to clarify your options and compare suitable solutions.