The short definition
Cyber insurance transfers a contractually defined part of the financial consequences of a cyber incident to an insurer. Depending on the policy, it combines cover for the insured business, liability towards third parties and organised emergency assistance.
It does not replace cybersecurity. Whether a specific loss is covered always depends on the policy wording, limits, deductibles, waiting periods and the information provided in the application.
Why it matters in Switzerland
Official figures describe different aspects of the situation and should not be treated as interchangeable:
- The NCSC recorded 64,733 voluntary reports in 2025. These are reports from businesses and individuals, not automatically confirmed attacks or insurance claims.
- Police crime statistics recorded 57,761 offences involving a digital method in 2025.
- The 2024 Swiss SME cyber study reported that 25% of surveyed businesses had an IT security concept.
- The Swiss Insurance Association reported approximately 67,000 corporate policies in 2024, equal to 10.8% of companies, and premium volume of CHF 172 million.
These figures show the relevance of cyber risk and an insurance gap. They do not establish the likelihood of loss or suitable cover for an individual business.
Which first-party losses may be covered?
First-party cover concerns the insured business’s own costs and losses. Common modules include:
- IT forensics and incident response: investigation, containment, evidence preservation and coordination.
- Data and system restoration: rebuilding affected systems and data, where agreed.
- Business interruption: insured loss of income and additional expense after a waiting period.
- Crisis communications and legal advice: support with communications, privacy questions and notifications.
- Cyber extortion or payment fraud: only where expressly included; separate sublimits and approval processes are common.
Not every policy includes every module. Terms vary particularly for supplier outages, cloud services and social engineering.
Which third-party losses may be covered?
Third-party losses arise when customers, employees or business partners make claims. Depending on the wording, liability cover may include:
- assessing and defending insured claims
- compensation for privacy or confidentiality breaches
- claims resulting from harm to third-party networks or systems
- defence and proceeding costs within the insured scope
Fines, contractual penalties and purely contractual liability are not automatically insured. The policy and applicable law determine the outcome.
What incident response means in a policy
Many policies provide an emergency number and a defined network of forensic, legal and communications specialists. Before buying, establish:
- Who may report an incident, and is the hotline available around the clock?
- Which service providers must or may be used?
- Which costs require prior approval?
- Does assistance start on suspicion or only after a confirmed loss?
- How are privacy notifications, evidence preservation and communications coordinated?
An internal incident response plan remains necessary: the first internal actions usually begin before cover has been confirmed.
Common exclusions and sublimits
Important points to check include:
| Topic | What to check |
|---|---|
| Prior incidents | Events existing or known before policy inception are usually excluded. |
| Disclosures and security requirements | Incomplete information or breached contractual duties can affect payment. |
| Intentional acts | Deliberately caused loss is generally excluded. |
| War and state actors | Definitions and attribution standards differ between clauses. |
| Infrastructure and service providers | Power, telecoms or cloud outages may be excluded or covered only within a sublimit. |
| Fraud and extortion | Separate sublimits, deductibles and consent requirements are common. |
| Business interruption | The waiting period, valuation method and maximum indemnity period matter. |
| Bodily injury and property damage | These are often outside cyber cover or available only as extensions. |
A product-sheet heading is not enough. Compare the full wording, definitions and related exclusions.
Which requirements do insurers assess?
An application may cover, among other things:
- multi-factor authentication for critical and remote access
- tested, segregated or immutable backups
- timely patch and vulnerability management
- endpoint protection, logging and privileged access
- staff training and payment or bank-detail verification procedures
- a documented incident response and recovery plan
- dependency on IT, cloud and other suppliers
- previous incidents and known vulnerabilities
Answers must be complete and current. No single measure guarantees acceptance, a discount or claim payment.
Comparison checklist
Compare quotations based on the same risk profile and answer at least these questions:
- Which first- and third-party losses are expressly included?
- Which total limits, sublimits, deductibles and waiting periods apply?
- Are cloud, IT provider and supply-chain outages covered?
- How are ransomware, payment fraud and social engineering treated?
- Which security disclosures become contractual duties?
- Who provides incident response, and when is approval required?
- Which countries, entities, data and systems are insured?
- Which exclusions would affect the business’s most important loss scenarios?
Limitations and transparency
Cyber insurance can provide funding and specialist assistance, but it cannot prevent an attack, guarantee full reimbursement or replace backups and response exercises. A defensible recommendation requires current risk information and comparable quotations; fixed online prices or generic insurer rankings are not sufficient.
Cyberversicherung.ch provides information and arranges advice through BTAG Versicherungsbroker AG. Any brokerage is paid by the insurer. Product scope and remuneration are disclosed before purchase.