cyberversicherung.ch

Cyber Glossary

All important cyber insurance and IT security terms — explained in plain language for business owners.

55 terms Plain-language definitions

55 terms

A

Advanced Persistent Threat (APT)

A long-term, targeted cyberattack where attackers silently infiltrate a network and remain active for weeks or months. APT attacks often target companies with valuable data or critical infrastructure.

Threats in Switzerland

B

Backdoor

A hidden entry point in software or systems that allows attackers unauthorised access. Backdoors are often installed by malware, enabling hackers to bypass security measures.

Threats in Switzerland

Botnet

A network of infected computers remotely controlled by cybercriminals. Botnets are commonly used for DDoS attacks, spam distribution or cryptocurrency mining, without the device owners' knowledge.

Threats in Switzerland

Brute Force Attack

An attack method that automatically tries countless password combinations until the correct one is found. Strong passwords and multi-factor authentication provide effective protection against such attacks.

Threats in Switzerland

Business Email Compromise (BEC)

A fraud scheme where attackers compromise or forge business email accounts to trick employees into making transfers or disclosing confidential data. BEC is one of the most financially damaging cybercrimes.

Threats in Switzerland

Business Interruption

The disruption of business operations due to a cyberattack. Depending on the policy, defined revenue losses and additional costs may be covered after a time deductible.

Coverage scope

C

CEO Fraud

A form of social engineering where attackers impersonate a CEO or senior manager and instruct employees to make urgent transfers. The deception is often so convincing that amounts running into millions are transferred.

Threats in Switzerland

Cloud Security

Measures to protect data, applications and infrastructure stored or operated in cloud services. These include access controls, encryption and regular security audits of the cloud environment.

Coverage Limit

The contractual maximum an insurer will pay for covered losses. An appropriate limit depends on the specific risk profile, possible business interruption, liability exposure and any sublimits.

Understand pricing factors

Credential Stuffing

An attack method that automatically tests stolen credentials from previous data breaches on other services. Since many users reuse the same passwords, this method is often successful.

Threats in Switzerland

Crisis Communication

Professional communication following a cyber incident — towards customers, media, authorities and employees. External advice may be insured depending on the policy, sublimit and prior approval.

Coverage scope

Cyber Extortion

An attack where cybercriminals threaten data encryption, publication or a DDoS attack and demand a ransom. Cover for negotiation, restoration or a payment depends on the policy, applicable law and insurer approval.

Coverage scope

Cyber Insurance

An insurance policy that may cover specified financial consequences of cyberattacks, data loss or IT failures. Insured events, services, exclusions, deductibles and limits are set out in the specific policy.

What is cyber insurance?

Cyber Liability

A possible part of cyber insurance for third-party claims defined in the contract. Legal defence and compensation depend on the terms, exclusions and sublimits.

Coverage scope

D

Dark Web

An encrypted part of the internet not accessible through conventional search engines. On the dark web, stolen data, credentials and malicious software are traded for use in cyberattacks.

Threats in Switzerland

Data Breach

An incident where data is disclosed, stolen, lost or made unavailable without authorisation. In Switzerland, the FDPIC must be notified as soon as possible when a data-security breach is likely to result in a high risk to personality or fundamental rights.

Reporting obligation

DDoS Attack

A Distributed Denial of Service attack that overwhelms a server or website with a flood of requests, making it unreachable for customers. For SMEs, DDoS attacks can lead to significant revenue losses.

Threats in Switzerland

Deductible

The contractual amount or time period the insured company bears for a covered loss. The amount, waiting period and effect on premium vary by quotation and risk profile.

Understand pricing factors

Deepfake

Videos, images or voices faked using artificial intelligence that appear deceptively real. Deepfakes are increasingly being used for CEO fraud, for example to authorise a transfer via a faked video call.

Threats in Switzerland

Digital Forensics

The systematic analysis of a cyber incident by IT specialists to determine its cause, extent and impact. The policy determines whether these costs are insured and which providers may be used.

Coverage scope

Duty to Mitigate Damages

The obligation of the policyholder to take all reasonable steps in the event of a claim to limit the damage. This includes immediately isolating affected systems, notifying the insurer and cooperating with forensics experts.

Coverage scope

E

Encryption

The process of converting data into an unreadable format using cryptographic methods. Only those with the correct key can decrypt the data. Encryption protects sensitive business and customer data from unauthorised access.

Endpoint Security

Security solutions that protect end devices such as laptops, smartphones and tablets from malware, unauthorised access and other threats. In the modern working world with remote work, endpoint security is particularly important.

F

FDPIC (Federal Data Protection Commissioner)

The Swiss supervisory authority for data protection. It must be notified as soon as possible when a data-security breach is likely to result in a high risk to personality or fundamental rights.

Reporting obligation

Firewall

A security system that monitors data traffic between the internal network and the internet and blocks unwanted connections. Firewalls form the first line of defence against cyberattacks.

First-Party Loss

A financial loss that directly affects the insured company — such as costs for data recovery, business interruption or IT forensics after a cyberattack.

Coverage scope

H

Hacker

A person who breaks into computer systems or networks. In cybersecurity, a distinction is made between criminal hackers (black hats) who cause damage, and ethical hackers (white hats) who uncover vulnerabilities on behalf of organisations.

I

Identity Theft

The misuse of personal data to impersonate another person — for example to open accounts, place orders or commit fraud. Companies are liable if customer data is stolen due to insufficient security.

Threats in Switzerland

Incident Response

The structured process of detecting, containing and resolving a cyber incident. A policy may provide an emergency contact or named providers; scope, availability and approval requirements are policy-specific.

Coverage scope

Insider Threat

Security risks originating from employees, former staff or business partners — whether through intent, negligence or compromised credentials. Insider threats are often harder to detect than external attacks.

Threats in Switzerland

IoT Security

The protection of Internet of Things devices such as sensors, cameras, production systems or smart office equipment. IoT devices are often poorly secured and serve as an entry point for attackers into the corporate network.

M

Malware

An umbrella term for malicious software designed to damage systems, steal data or disrupt operations. Malware includes viruses, trojans, ransomware and spyware.

Threats in Switzerland

Mandatory Reporting

Obligations depend on the organisation and incident. Since 1 April 2025, covered operators of critical infrastructure must report qualifying cyberattacks to the NCSC within 24 hours. Data-security breaches must be reported to the FDPIC as soon as possible if they are likely to create a high risk to personality or fundamental rights.

Reporting details

Multi-Factor Authentication (MFA)

A security procedure that requires at least two independent proofs of identity — for example a password plus an app confirmation. MFA makes account takeover substantially harder but does not replace other security controls.

Check your risk

N

nFADP (Swiss Federal Act on Data Protection)

The revised Swiss data protection law in force since September 2023. It requires appropriate technical and organisational measures. Certain intentional breaches by natural persons can be fined up to CHF 250,000; a data breach does not automatically result in a fine.

Reporting details

P

Patch Management

The systematic process of promptly installing software updates and security patches to close known vulnerabilities. Neglected patch management is one of the most common causes of successful cyberattacks.

Check your risk

Penetration Test

An authorised, simulated cyberattack on one's own IT infrastructure to identify vulnerabilities before real attackers can exploit them. Regular penetration tests are a sign of good cybersecurity practice.

Check your risk

Phishing

A fraud scheme where attackers use fake emails, messages or websites to obtain confidential data such as passwords or credit card information. Phishing is the most common entry point for cyberattacks on SMEs.

Threats in Switzerland

Premium

The annual or monthly payment a company makes for its cyber insurance. The amount depends on the industry, company size, coverage limit and existing IT security measures.

Understand pricing factors

R

Ransomware

Malicious software that encrypts data or systems; attackers often also threaten to publish stolen data and demand a ransom. Impact varies widely and can include recovery, interruption, forensics and legal advice.

Threats in Switzerland

Recovery Costs

The costs incurred after a cyberattack to restore data, systems and normal operations. Cover for IT services, hardware or external specialists depends on the policy, sublimits and approval requirements.

Coverage scope

Risk Assessment

The systematic analysis of a company's cyber risks — what threats exist, how likely they are and what impact they would have. Risk assessment is the foundation for choosing the right cyber insurance.

Risk check

S

Smishing

Phishing via SMS — fraudsters send fake text messages leading to malicious websites or aiming to collect personal data. Smishing attacks are increasing sharply in Switzerland, often disguised as parcel delivery notifications.

Threats in Switzerland

Social Engineering

Manipulation techniques where attackers exploit human weaknesses rather than technical vulnerabilities. Through deception, trust-building or pressure, employees are tricked into revealing confidential information or performing harmful actions.

Threats in Switzerland

Spear Phishing

A targeted form of phishing where attackers tailor their messages specifically to individuals or companies. Unlike mass phishing, publicly available information is used for a credible disguise.

Threats in Switzerland

SQL Injection

An attack on web applications where malicious code is injected into database queries. This allows attackers to read, modify or delete data. SQL injections are among the most common attacks on online shops and web portals.

Threats in Switzerland

Supply Chain Attack

A cyberattack that reaches the target's systems through a supplier, service provider or software vendor. Such attacks are particularly insidious as they exploit trust in the supply chain.

Threats in Switzerland

T

Third-Party Damage

Damage that affects third parties rather than the insured company — for example customers after a data leak. Claims and legal costs may be insured depending on the liability cover, terms and exclusions.

Coverage scope

Trojan

Malicious software that disguises itself as a useful or harmless programme to gain access to a system. Once installed, a trojan can steal data, open backdoors or download further malware.

Threats in Switzerland

Two-Factor Authentication (2FA)

A security measure that requires a second factor beyond the password for login — such as an SMS code, app confirmation or physical security key. 2FA is one of the most effective measures against unauthorised access.

Check your risk

V

Vishing

Phishing by phone — fraudsters pose as a bank, authority or IT support on the phone to obtain confidential information. Vishing attacks are becoming increasingly sophisticated, particularly through the use of deepfake voices.

Threats in Switzerland

VPN (Virtual Private Network)

An encrypted connection that secures data traffic between a device and the corporate network — especially important for employees working from home. A VPN protects against data interception on public networks.

Vulnerability

A security flaw in software, hardware or processes that can be exploited by attackers. Regular vulnerability scans and timely patch management help identify and fix vulnerabilities.

Check your risk

W

Waiting Period

The period specified in a policy after which a covered business interruption is counted. Its duration, calculation and the company's own share vary by contract and must be checked in the quotation.

Coverage scope

Z

Zero-Day Exploit

An attack that exploits a previously unknown vulnerability for which no security update yet exists. Zero-day exploits are particularly dangerous because companies cannot specifically protect against them.

Threats in Switzerland

BTAG Versicherungsbroker AG · Bern

Have questions about cyber insurance?

BTAG clarifies your risk profile and discloses any commission before conclusion. The request does not oblige you to buy.

Quote advice by BTAG Versicherungsbroker AG, Bern — FINMA-registered insurance intermediary.

Verified primary sources
Transparent compensation