Cyber insurance has become a fixture in the Swiss SME landscape. It is offered by brokers, sometimes bolted onto an existing contract, and often signed within minutes because the premium looks reasonable against the risk.

The problem is almost never the price. It lies elsewhere: many companies do not know precisely what they have bought, and discover the real terms on the day they need them. By then, there is no room left to manoeuvre.

This article is neither a product recommendation nor a comparison. It describes the mechanisms common to this type of contract, and above all the questions to ask before signing. Since every contract differs, only reading your own is authoritative.

What does cyber insurance generally cover?

Contrary to a common assumption, cyber insurance is not simply a cheque issued after the fact. Its main value often plays out in the first few hours, in the form of services rather than money.

Depending on the contract, four components typically appear.

Incident response costs. This is the heart of the arrangement. The insurer funds, and sometimes organises, the intervention of technical experts tasked with analysing the attack and helping restore operations, of legal counsel for notification and liability questions, and sometimes of communication support. For an SME without an in-house IT department, this immediate access to specialists is often worth more than the payout itself.

Business interruption loss. This means compensating all or part of the margin lost during the downtime. Watch the definitions closely: contracts generally set a waiting period, meaning a length of disruption below which nothing is owed, and a maximum indemnification period.

Data and system reconstruction. The costs of restoration, reinstallation and sometimes re-entry of lost data can be covered. This item obviously assumes there is something left to restore, which brings us back to your backups.

Third-party liability. Some contracts, not all, cover claims from customers or partners whose data was exposed, as well as defence costs. This is a separate component that must be checked explicitly if your business involves processing data on behalf of others.

What is often excluded or limited?

An insurance contract is read first through its exclusions. Three families come up repeatedly, and deserve an unflinching look.

Gross negligence. This is the most contested exclusion. A company with no backups at all, running systems without updates for years, or failing to act on a known warning, exposes itself to reduced or refused coverage. The threshold is not set by any universal rule, it depends on the contract and the circumstances. Keep the principle in mind: insurance covers a risk, not a renunciation.

Incidents predating the policy. An attack whose origin predates the policy’s effective date is generally excluded, even if only discovered later. An intrusion can remain silent for a long time, particularly in the case of a mailbox compromise.

Ransom payments. Depending on the contract, this may be excluded, or covered under strict conditions with prior agreement. Never assume the answer either way. This question should in any case be prepared before the attack, as we explain in our article should you pay the ransom.

Other limitations are less a matter of exclusion than of framing: deductibles, per-claim and per-year caps, sub-limits specific to certain items. These are not visible from a quick read of the brochure, they are found in the terms and conditions.

The point that costs coverage: your obligations

Here is the central message of this article. It is not the scope of the guarantee that causes the most trouble in practice, it is the obligations the contract places on you at the time of a claim.

Two obligations come up almost every time. First, report very quickly, within a deadline that is often short. Second, and this is the counterintuitive part, do not intervene technically before the insurer’s agreement, since it frequently reserves the right to appoint its own experts.

Reformat first, call later: the mistake that costs you coverage

Typical scenario: Monday morning, the files are encrypted. The IT provider does what seems most logical, reinstalling the servers to get back up and running as fast as possible. Three days later, the insurer asks for the forensic analysis. There is nothing left to analyse. The origin of the attack can no longer be established, nor the date of the compromise, nor the data actually accessed. Isolate the machines from the network, do not wipe them, and call before rebuilding.

This requirement is not administrative red tape. Analysing the evidence serves to qualify the claim, determine its date of origin, and establish which data was actually accessed, which you need anyway for your legal obligations.

In practice, this means a cyber insurance contract must reshape your emergency procedure. The insurer’s number belongs on the list of priority calls, alongside those detailed in who to contact in the event of an attack, and this list must be known to your staff before the incident, not searched for in an inaccessible mailbox.

The underwriting questionnaire is binding

Before covering you, the insurer questions you about your organisation: backups, updates, authentication, training, service providers. These answers are not a customer-satisfaction survey, they form part of the risk assessment.

Declaring that your backups are tested regularly, or that two-factor authentication is in place everywhere, when this is not the case, seriously weakens your guarantee. On the day of the claim, verification is easy, and the consequences can range from a reduced payout to the contract being voided.

Do not answer from memory

Most inaccurate answers are not lies, they are beliefs. The owner is convinced the backups are tested because the provider told them so two years ago. Have every statement verified before signing it, and keep proof of that verification. It is useful for the insurer, and even more useful for you.

This questionnaire actually has an unexpected virtue: it works as a free self-assessment. Every box you cannot honestly tick points to a security gap to close. Our cyber check-up covers the same themes and helps you prepare for the exercise.

What questions should you ask before signing?

Here are the points to have confirmed in writing, whichever insurer you use. A reassuring verbal answer is worth nothing against a clause.

TopicThe question to ask
NotificationWithin what deadline must I report, through which channel, and is that channel reachable at night and on weekends?
InterventionAm I allowed to bring in my usual provider, or does the insurer impose its own experts?
ScopeAre remote work, personal devices and my IT providers included?
ExclusionsWhich technical requirements, if not met, void the guarantee?
Business interruptionFrom how many hours of downtime, for how long, and calculated how?
Third parties and ransomIs liability towards my customers covered? Is a ransom payment covered, and under what conditions?

One last reflex: request the full general terms and conditions, not just the product sheet, and read the “policyholder obligations” section before the “benefits” section. That is where your compensation is actually decided.

Insurance does not replace prevention

Cyber insurance transfers part of the financial cost of an incident. It transfers nothing else.

It does not restore your data for you. It does not give back the weeks of disorganised activity, nor the exhaustion of teams re-entering files by hand. It does not buy back the trust of a customer who received a fraudulent invoice sent from your address, nor that of a partner who discovers their data was held on your systems. These losses cannot be compensated.

It does have one useful side effect, though. To be insurable on reasonable terms, you must demonstrate a minimum level of digital hygiene. Taking out the policy therefore pushes you to put in place what should have been in place anyway. Seen this way, insurance is less a safety net than a spur to action.

To gauge what downtime would represent for your business, our attack cost simulator gives a useful order of magnitude before any discussion with a broker. And the measures that genuinely reduce the probability of a claim are grouped in the Good practices pillar.

One limitation remains specific to this topic. Comparing cyber insurance contracts requires understanding both insurance vocabulary and the technical realities of your system at the same time. Few SMEs have both skills in house, and that is precisely why so many of them sign without knowing what they are buying. Having the contract reviewed by someone who knows what the technical requirements actually mean in practice avoids discovering the exclusions on the day of the claim. The other reflexes to prepare in advance are described in the Responding to an attack pillar and in what to do in the first 24 hours.