Cyber insurance
Protection against data loss, business interruption and claims after an attack.
Why this matters
One click on the wrong e-mail attachment, and next morning your accounts, customer data and order planning are encrypted – with a ransom demand on the screen. Without preparation, three fronts open at once: restoring the systems, keeping the business running somehow, and informing affected customers. Specialists in IT forensics and data recovery quickly cost more than a year’s premium, and every day of standstill comes on top. Most SMEs have neither the expertise nor the reserves to get through that alone.
It is no longer just big industry that is at risk: attacks run automatically and preferentially hit smaller businesses, because their defences are weaker – fiduciaries, doctors, tradespeople with online booking, anyone holding customer data. There is no obligation to carry cyber insurance in Switzerland; it is voluntary and paid for by the business. The Data Protection Act, however, is binding: anyone processing personal data must protect it appropriately, and serious data breaches must be reported to the Federal Data Protection Commissioner. The insurance does not replace these duties, but it helps you meet them quickly and correctly when it matters.
What you get out of it
After an attack, every hour counts — immediate assistance is organised.
Data loss, business interruption and liability claims are covered.
SMEs are targets too — precisely because so many are unprotected.
What we take care of for you
- Risk check of your IT landscape (together with our IT service)
- Comparison of cyber policies by cover and prevention services
- Emergency plan: who does what when it really matters?
- Support in the event of a claim, including coordinating forensics
The advice is free for you — we are remunerated by the insurance companies through brokerage commissions and will disclose these on request.
Tips from our consultations
What we tell our clients time and again – free of charge, even before the first meeting.
Cyber policies presuppose minimum standards: up-to-date software, regular backups, often two-factor authentication. If you let these requirements slip in everyday operations, you risk reduced benefits in the event of a claim. Before signing, check honestly whether your business meets the conditions – and upgrade first if it doesn’t.
When the worst happens, what counts is less the cover sum than the question of who helps you at two in the morning. Compare whether the policy includes a 24-hour hotline with forensic and legal specialists, and how quickly they act on site or remotely. That is the real value of cyber insurance.
First-party losses such as data recovery and lost earnings are one thing; third-party claims over lost customer data are another. Some policies cover only part of this. Also clarify whether fraud through forged payment instructions is included – one of the most common types of loss for SMEs.
Most attacks begin with a deceptively genuine e-mail, not with a technical break-in. Short, regular training sessions measurably lower the risk and are rewarded by some insurers with better terms. Prevention and policy belong together – one does not replace the other.