cyberversicherung.ch

Cyber Insurance for SMEs: Cover, Cost Factors and Comparison

Published: Updated: Reading time: 4 min

The short answer

A factual guide for Swiss SMEs: current study figures, potential cover, security questions, cost factors and criteria for comparing policies.

How large is the cyber protection gap among Swiss SMEs?

Two primary sources describe different aspects and should not be treated as an individual risk forecast:

  • The 2024 Swiss SME cyber study surveyed 515 SMEs. 4% reported a damaging cyber attack in the preceding three years, 5% an extortion attempt and 4% a financial loss caused by a fraudulent email. 25% had a security concept, 32% ran regular employee training and 33% had an incident plan.
  • The Swiss Insurance Association reported approximately 67,000 corporate cyber policies in 2024, representing 10.8% of companies domiciled in Switzerland. Premium volume was CHF 172 million, 22% higher than the previous year.

The association’s figures cover the corporate market and do not provide an SME-specific insurance rate or the price for an individual business. The survey describes its sample, not a guaranteed probability for any one SME.

Which risks should an SME assess first?

Company size alone does not determine risk. Processes, data, access and dependencies matter more:

  1. Operational dependence on IT: how long can the business operate without production, booking, finance or email systems?
  2. Personal and business data: what would loss, disclosure or manipulation cause?
  3. Payment processes: how are new accounts, invoice changes and urgent payments confirmed?
  4. External providers: which cloud, software and IT providers are critical?
  5. Recovery: are backups separated, protected and tested in practice?
  6. Law and contracts: which data protection, sector or customer duties apply?

What may cyber insurance cover?

Depending on the policy, cover may include:

  • IT forensics and incident-response coordination
  • data and system restoration
  • legal advice and support with data breach notifications
  • crisis communication
  • insured business interruption and extra expense after a waiting period
  • defence and settlement of covered third-party claims
  • payment fraud, extortion or supplier outages where expressly included

Policies differ. Definitions, sublimits and exclusions for social engineering, cyber extortion, cloud services, IT providers and purely technical outages require particular attention.

What is not automatically covered?

  • events or vulnerabilities known before the policy began
  • intentionally caused loss
  • all contractual penalties or regulatory fines
  • every form of payment fraud or extortion payment
  • every cloud or IT provider outage
  • loss outside the insured entities, countries, systems or data
  • consequences of inaccurate application statements or breached contractual security requirements

The wording and applicable law determine cover, not a product heading.

What does cyber insurance cost for an SME?

A reliable price requires a current risk profile and actual quotations. Flat online prices can mislead because insurers may assess:

  • revenue, sector, locations and business size
  • the nature and quantity of data processed
  • requested limit, sublimits and deductible
  • dependence on IT, cloud services and suppliers
  • previous incidents and known vulnerabilities
  • MFA, backups, patch management, endpoint security and response planning
  • payment approvals and social-engineering controls

Compare quotations using the same facts and requested scope. A lower price may reflect a higher deductible, lower sublimits or narrower wording.

Which security questions might insurers ask?

Questions vary by insurer and risk:

TopicUseful evidence
Multi-factor authenticationprotected remote, email and administrator access
Backupsseparation, access control and recorded restoration tests
Updatesownership and prioritisation of critical vulnerabilities
Privilegesrestricted administrator rights and regular review
Paymentsindependent confirmation of account changes and exceptions
Incident plancurrent contacts, decisions and completed exercises
Providersknown dependencies, access and notification arrangements

These are not universal minimum requirements for every insurer. Answers must be complete and current; no single control guarantees acceptance, a discount or payment of a claim.

Compare offers in seven steps

  1. Record the most important loss scenarios and tolerable outage periods.
  2. Request quotations with identical business and security information.
  3. Compare limits, sublimits, deductibles and waiting periods.
  4. Check cloud, supplier, extortion and payment-fraud provisions expressly.
  5. Read exclusions and contractual security requirements.
  6. Clarify the emergency hotline, approved providers and consent process.
  7. Record brokerage, fees and potential conflicts transparently.

Conclusion

Cyber insurance can provide expertise and liquidity for contractually defined incidents. Whether it is appropriate for a particular SME, and at what level, depends on its risks, financial resilience and the available terms. It does not replace cybersecurity or an exercised incident plan.

Cyberversicherung.ch provides information and arranges advice through BTAG Versicherungsbroker AG. Product terms and any commission paid by the insurer should be disclosed before purchase.

Sources

BTAG Versicherungsbroker AG · Bern

Have questions about cyber insurance?

BTAG clarifies your risk profile and discloses any commission before conclusion. The request does not oblige you to buy.

Quote advice by BTAG Versicherungsbroker AG, Bern — FINMA-registered insurance intermediary.

Verified primary sources
Transparent compensation