Short answer: what does cyber insurance cover?
Cyber insurance may pay defined first-party costs, insured third-party claims, and emergency services following an insured cyber event. There is no uniform coverage standard. The policy definitions, limits, sublimits, deductibles, waiting periods, exclusions, and security conditions determine the actual protection.
Insurance does not replace cybersecurity or an incident plan. It transfers only the financial risks expressly covered by the contract.
The main coverage modules
| Module | Possible benefits | What to check |
|---|---|---|
| Incident response and IT forensics | Containment, investigation, and evidence preservation | Hotline, response process, approved providers, and authorisation |
| Data and system recovery | Cleaning, rebuilding, and restoring systems | Valuation method, betterment, and sublimit |
| Business interruption | Insured loss of profit and extra expense | Waiting period, indemnity period, calculation, dependent providers, and non-malicious outages |
| Cyber extortion | Crisis advice, negotiation, and recovery | Whether payments are included and under which legal and contractual conditions |
| Data breach response | Legal assessment and required communications | Applicable laws, consent requirements, and notification costs |
| Cyber liability | Defence and settlement of insured third-party claims | Privacy, network security, media liability, and pure financial loss |
| Crisis communications | Communications advice and affected-person support | Trigger, duration, provider, and sublimit |
| Social engineering and payment fraud | Certain misdirected payments | Often optional; verification rules and lower sublimits may apply |
| Cloud and provider outage | Consequences of an incident at an external provider | Named services, covered events, and outage types |
A “24/7 hotline” does not mean every external invoice will be reimbursed. Many policies require the insured to contact the designated response service first or obtain approval where circumstances allow.
Read first-party and liability cover separately
First-party cover concerns the insured business, such as forensics, recovery, and insured interruption. Liability cover concerns insured third-party claims and legal defence.
A high aggregate limit is not enough if important modules are missing or subject to low sublimits. Compare each module separately and check whether a monetary deductible and a waiting period can both apply.
Common exclusions and conditions
The wording varies. Review provisions concerning:
- incidents or circumstances known before inception;
- intentional acts and inaccurate questionnaire answers;
- stated security conditions such as MFA, backups, or patch management;
- war, state-backed activity, systemic events, and critical infrastructure;
- bodily injury, property damage, and environmental loss;
- contractual penalties, warranties, and voluntarily assumed liability;
- long-term reputational harm or future loss of customers;
- obsolete systems, known vulnerabilities, or material risk changes;
- ransom, fines, or sanctions where legally or contractually uninsurable.
The same label can operate differently between policies. Ask for a written explanation based on your systems, subsidiaries, and suppliers.
Eight questions for comparing quotations
- Trigger: Which event activates each module?
- Limits: What aggregate limit and sublimits apply?
- Retention: Which deductibles and waiting periods remain with the business?
- Period: How long are interruption and follow-on costs considered?
- Providers: Is there a panel, free choice, or prior-consent requirement?
- Dependencies: Are cloud, IT, payment, and supply-chain providers included?
- Territory: Do jurisdictions, subsidiaries, and applicable laws fit the business?
- Security statements: Can every questionnaire answer be evidenced and kept current?
Our guide to cyber insurance price factors explains why reliable comparison requires current quotations based on identical business information.
Do not confuse the reporting processes
Under Article 24 FADP, a controller must notify the FDPIC as quickly as possible where a data security breach is likely to result in a high risk to the personality or fundamental rights of affected people. Swiss law does not impose a general fixed-hour deadline.
The 24-hour BACS/NCSC duty has applied since 1 April 2025 only to covered operators of critical infrastructure and reportable cyberattacks. Sector, contract, or foreign-law duties may apply in addition.
Notification to the insurer is a separate contractual process. A report to an authority does not replace it. See the Swiss reporting guide for details.
During an incident
- Activate the incident plan and check the policy’s emergency contact.
- Contain affected systems carefully and preserve evidence.
- Record discovery, decisions, affected data, and costs.
- Assess legal, regulatory, contractual, and insurance notifications in parallel.
- Coordinate external costs in advance where this does not create additional risk.
A policy does not guarantee recovery or payment of a particular amount. Cover depends on the event, evidence, wording, and compliance with the agreed conditions.
Official sources
- FDPIC: data breach guidance under Article 24 FADP
- BACS/NCSC: reporting obligation for cyberattacks on critical infrastructure
Content reviewed on 18 July 2026. This overview is not legal advice or a coverage confirmation; the specific contract governs.