cyberversicherung.ch

Cyber Insurance Coverage: How to Check Benefits and Exclusions

Published: Updated: Reading time: 4 min Sources: 2

The short answer

Which costs cyber insurance may cover, which exclusions matter, and how Swiss SMEs can compare policy wording and quotations reliably.

Short answer: what does cyber insurance cover?

Cyber insurance may pay defined first-party costs, insured third-party claims, and emergency services following an insured cyber event. There is no uniform coverage standard. The policy definitions, limits, sublimits, deductibles, waiting periods, exclusions, and security conditions determine the actual protection.

Insurance does not replace cybersecurity or an incident plan. It transfers only the financial risks expressly covered by the contract.

The main coverage modules

ModulePossible benefitsWhat to check
Incident response and IT forensicsContainment, investigation, and evidence preservationHotline, response process, approved providers, and authorisation
Data and system recoveryCleaning, rebuilding, and restoring systemsValuation method, betterment, and sublimit
Business interruptionInsured loss of profit and extra expenseWaiting period, indemnity period, calculation, dependent providers, and non-malicious outages
Cyber extortionCrisis advice, negotiation, and recoveryWhether payments are included and under which legal and contractual conditions
Data breach responseLegal assessment and required communicationsApplicable laws, consent requirements, and notification costs
Cyber liabilityDefence and settlement of insured third-party claimsPrivacy, network security, media liability, and pure financial loss
Crisis communicationsCommunications advice and affected-person supportTrigger, duration, provider, and sublimit
Social engineering and payment fraudCertain misdirected paymentsOften optional; verification rules and lower sublimits may apply
Cloud and provider outageConsequences of an incident at an external providerNamed services, covered events, and outage types

A “24/7 hotline” does not mean every external invoice will be reimbursed. Many policies require the insured to contact the designated response service first or obtain approval where circumstances allow.

Read first-party and liability cover separately

First-party cover concerns the insured business, such as forensics, recovery, and insured interruption. Liability cover concerns insured third-party claims and legal defence.

A high aggregate limit is not enough if important modules are missing or subject to low sublimits. Compare each module separately and check whether a monetary deductible and a waiting period can both apply.

Common exclusions and conditions

The wording varies. Review provisions concerning:

  • incidents or circumstances known before inception;
  • intentional acts and inaccurate questionnaire answers;
  • stated security conditions such as MFA, backups, or patch management;
  • war, state-backed activity, systemic events, and critical infrastructure;
  • bodily injury, property damage, and environmental loss;
  • contractual penalties, warranties, and voluntarily assumed liability;
  • long-term reputational harm or future loss of customers;
  • obsolete systems, known vulnerabilities, or material risk changes;
  • ransom, fines, or sanctions where legally or contractually uninsurable.

The same label can operate differently between policies. Ask for a written explanation based on your systems, subsidiaries, and suppliers.

Eight questions for comparing quotations

  1. Trigger: Which event activates each module?
  2. Limits: What aggregate limit and sublimits apply?
  3. Retention: Which deductibles and waiting periods remain with the business?
  4. Period: How long are interruption and follow-on costs considered?
  5. Providers: Is there a panel, free choice, or prior-consent requirement?
  6. Dependencies: Are cloud, IT, payment, and supply-chain providers included?
  7. Territory: Do jurisdictions, subsidiaries, and applicable laws fit the business?
  8. Security statements: Can every questionnaire answer be evidenced and kept current?

Our guide to cyber insurance price factors explains why reliable comparison requires current quotations based on identical business information.

Do not confuse the reporting processes

Under Article 24 FADP, a controller must notify the FDPIC as quickly as possible where a data security breach is likely to result in a high risk to the personality or fundamental rights of affected people. Swiss law does not impose a general fixed-hour deadline.

The 24-hour BACS/NCSC duty has applied since 1 April 2025 only to covered operators of critical infrastructure and reportable cyberattacks. Sector, contract, or foreign-law duties may apply in addition.

Notification to the insurer is a separate contractual process. A report to an authority does not replace it. See the Swiss reporting guide for details.

During an incident

  1. Activate the incident plan and check the policy’s emergency contact.
  2. Contain affected systems carefully and preserve evidence.
  3. Record discovery, decisions, affected data, and costs.
  4. Assess legal, regulatory, contractual, and insurance notifications in parallel.
  5. Coordinate external costs in advance where this does not create additional risk.

A policy does not guarantee recovery or payment of a particular amount. Cover depends on the event, evidence, wording, and compliance with the agreed conditions.

Official sources

Content reviewed on 18 July 2026. This overview is not legal advice or a coverage confirmation; the specific contract governs.

BTAG Versicherungsbroker AG · Bern

Have questions about cyber insurance?

BTAG clarifies your risk profile and discloses any commission before conclusion. The request does not oblige you to buy.

Quote advice by BTAG Versicherungsbroker AG, Bern — FINMA-registered insurance intermediary.

Verified primary sources
Transparent compensation