How large is the cyber protection gap among Swiss SMEs?
Two primary sources describe different aspects and should not be treated as an individual risk forecast:
- The 2024 Swiss SME cyber study surveyed 515 SMEs. 4% reported a damaging cyber attack in the preceding three years, 5% an extortion attempt and 4% a financial loss caused by a fraudulent email. 25% had a security concept, 32% ran regular employee training and 33% had an incident plan.
- The Swiss Insurance Association reported approximately 67,000 corporate cyber policies in 2024, representing 10.8% of companies domiciled in Switzerland. Premium volume was CHF 172 million, 22% higher than the previous year.
The association’s figures cover the corporate market and do not provide an SME-specific insurance rate or the price for an individual business. The survey describes its sample, not a guaranteed probability for any one SME.
Which risks should an SME assess first?
Company size alone does not determine risk. Processes, data, access and dependencies matter more:
- Operational dependence on IT: how long can the business operate without production, booking, finance or email systems?
- Personal and business data: what would loss, disclosure or manipulation cause?
- Payment processes: how are new accounts, invoice changes and urgent payments confirmed?
- External providers: which cloud, software and IT providers are critical?
- Recovery: are backups separated, protected and tested in practice?
- Law and contracts: which data protection, sector or customer duties apply?
What may cyber insurance cover?
Depending on the policy, cover may include:
- IT forensics and incident-response coordination
- data and system restoration
- legal advice and support with data breach notifications
- crisis communication
- insured business interruption and extra expense after a waiting period
- defence and settlement of covered third-party claims
- payment fraud, extortion or supplier outages where expressly included
Policies differ. Definitions, sublimits and exclusions for social engineering, cyber extortion, cloud services, IT providers and purely technical outages require particular attention.
What is not automatically covered?
- events or vulnerabilities known before the policy began
- intentionally caused loss
- all contractual penalties or regulatory fines
- every form of payment fraud or extortion payment
- every cloud or IT provider outage
- loss outside the insured entities, countries, systems or data
- consequences of inaccurate application statements or breached contractual security requirements
The wording and applicable law determine cover, not a product heading.
What does cyber insurance cost for an SME?
A reliable price requires a current risk profile and actual quotations. Flat online prices can mislead because insurers may assess:
- revenue, sector, locations and business size
- the nature and quantity of data processed
- requested limit, sublimits and deductible
- dependence on IT, cloud services and suppliers
- previous incidents and known vulnerabilities
- MFA, backups, patch management, endpoint security and response planning
- payment approvals and social-engineering controls
Compare quotations using the same facts and requested scope. A lower price may reflect a higher deductible, lower sublimits or narrower wording.
Which security questions might insurers ask?
Questions vary by insurer and risk:
| Topic | Useful evidence |
|---|---|
| Multi-factor authentication | protected remote, email and administrator access |
| Backups | separation, access control and recorded restoration tests |
| Updates | ownership and prioritisation of critical vulnerabilities |
| Privileges | restricted administrator rights and regular review |
| Payments | independent confirmation of account changes and exceptions |
| Incident plan | current contacts, decisions and completed exercises |
| Providers | known dependencies, access and notification arrangements |
These are not universal minimum requirements for every insurer. Answers must be complete and current; no single control guarantees acceptance, a discount or payment of a claim.
Compare offers in seven steps
- Record the most important loss scenarios and tolerable outage periods.
- Request quotations with identical business and security information.
- Compare limits, sublimits, deductibles and waiting periods.
- Check cloud, supplier, extortion and payment-fraud provisions expressly.
- Read exclusions and contractual security requirements.
- Clarify the emergency hotline, approved providers and consent process.
- Record brokerage, fees and potential conflicts transparently.
Conclusion
Cyber insurance can provide expertise and liquidity for contractually defined incidents. Whether it is appropriate for a particular SME, and at what level, depends on its risks, financial resilience and the available terms. It does not replace cybersecurity or an exercised incident plan.
Cyberversicherung.ch provides information and arranges advice through BTAG Versicherungsbroker AG. Product terms and any commission paid by the insurer should be disclosed before purchase.