Why Swiss SMEs are exposed

Digitalization has made small and medium-sized businesses dependent on their IT: messaging, cash register, ERP, online store, customer data, payments, backups, cloud and suppliers. Ransomware, payment fraud, data breach or post-hack outage can shut down business, create emergency costs and lasting reputational damage.

Cyber insurance does not replace IT prevention, but it provides financial and operational resources when it is necessary to react quickly: hotline, specialists, forensics, restoration, legal advice, crisis communication and compensation for certain losses.

What cyber insurance can cover

  • Ransomware: emergency assistance, analysis of the attack, data restoration, negotiation and costs related to cyberextortion according to the police.
  • Reconstruction of the systems: disinfection, reinstallation, data recovery, configuration and external IT costs.
  • Operational interruption: loss of income and additional costs when the activity is partially or totally paralyzed.
  • Data breach: legal advice, identification of data subjects, notifications, communication and crisis management.
  • Cyber liability: claims from customers, partners or third parties following a data protection breach or loss of data.
  • Digital fraud: social engineering, e-banking manipulation, false invoice or payment diversion depending on the options.

Swiss rules to know

Since the entry into force of the new Federal Data Protection Act, a company must notify the PFPDT of data security violations which likely result in a high risk to the personality or fundamental rights of the persons concerned. The announcement must be made as soon as possible and indicate in particular the nature of the violation, its consequences and the measures taken or envisaged.

The persons concerned must also be informed when this is necessary for their protection or when the PFPDT requires it. If your business processes data from EU residents, GDPR may add obligations. For certain critical infrastructures, specific reporting obligations may also apply.

Prevention requirements to check

  • Regular backups, tested and isolated from the main network.
  • Multi-factor authentication for sensitive access, messaging, cloud and administration.
  • Security updates, antivirus/EDR and user rights management.
  • Incident response plan: who to call, what to cut, what to document, who communicates.
  • Raising team awareness of phishing, false invoices and urgent payment requests.
  • Clear contracts with IT, cloud providers, hosts and data subcontractors.

What companies underestimate

The main cost is not always the ransom. It may come from several days of downtime, data impossible to restore, hours of experts, a legal firm, customers to notify, a loss of trust or a critical supplier itself compromised. Good cyber insurance must therefore cover own damage, liability towards third parties and crisis support.

How to choose guarantees

  • Sum insured: consistent with your turnover, data volume and IT dependence.
  • Waiting period: moment from which the operating loss is compensated.
  • Duration of compensation: covered period if restart takes several weeks or months.
  • Notification fees: authorities, data subjects, customer support, legal advice and communication.
  • Fraud : check if social engineering, e-banking and fake payment orders are included or optional.
  • Exclusions: lack of backups, outdated systems, known events, cyber warfare or non-compliance with declared measures.

Our support

Finwise analyzes your cyber exposure, your data, your tools, your backups, your IT providers and your dependence on online activity. We compare Swiss offers to obtain usable coverage, aligned with your security measures and legal obligations.

Assess my cyber risk See technical insurance

Let’s talk about your needs

Tell us about your situation in a few lines. A Finwise adviser will contact you to clarify your options and compare suitable solutions.