Why are SMEs concerned?

Cybercriminals do not only target large groups. An SME can be affected by a phishing email, a compromised password, poorly secured remote access, an attacked service provider or ransomware that encrypts files and blocks activity.

The real cost often exceeds the IT repair: loss of turnover, expert fees, crisis communication, customer notification, legal advice, reputational damage and liability to third parties.

What cyber insurance can cover

  • Emergency assistance: hotline, IT experts, forensic, containment and recommissioning.
  • Data restoration: rebuilding, cleaning systems, reinstalling and recovering backups.
  • Operating loss: compensation for lost turnover and additional costs during the interruption.
  • Cyber liability: defense and compensation in the event of claims from customers, partners or third parties.
  • Data breach: legal costs, notification, communication and regulatory support.
  • Cyberextortion: support in the event of ransomware, according to the conditions and exclusions of the contract.

nLPD: obligations in the event of a data leak

Swiss data protection law requires data security violations that are likely to result in a high risk to the personality or fundamental rights of the data subjects to be reported to the PFPDT. The announcement must be made as soon as possible and describe at least the nature of the violation, its consequences and the measures taken or envisaged.

If this is necessary to protect the persons concerned, or if the PFPDT requires it, the company must also inform them directly. If your activity affects the European Union or critical infrastructure, other obligations and deadlines may be added.

Scenarios to anticipate

  • An employee clicks on a fake email and gives their access.
  • Ransomware blocks your ERP, cash register or billing system.
  • Customer, patient or employee data is copied or published.
  • A fraudulent transfer is triggered by identity theft.
  • A cloud or IT provider goes down and interrupts your service.
  • Human error makes confidential documents accessible to third parties.

Prerequisites often requested by insurers

Cyber ​​insurance is not a substitute for security. Insurers are increasingly checking basic measures: regular and tested backups, multi-factor authentication, updates, limited access rights, antivirus or EDR, incident response procedures and phishing awareness.

If these measures are absent or poorly documented, the premium may increase, certain guarantees may be limited or the insurer may refuse to cover certain losses.

Points to compare in a contract

  • Insured amount and sub-limits for ransomware, fraud, notification or business interruption.
  • Duration of compensation for operating losses.
  • Deductible, waiting period and triggering of the guarantee.
  • Coverage of providers, cloud and supply chain.
  • Coverage of legal and communication costs.
  • Exclusions related to unpatched systems, insufficient backups or unmet security obligations.

Common errors

  • Thinking that a small business is of no interest to attackers.
  • Insure computers but forget about digital operating losses.
  • Not knowing who to call in the first hour of an incident.
  • Keep backups connected to the same network as the primary data.
  • Forget notification obligations in the case of personal data.
  • Compare only the premium without looking at the sub-limits and exclusions.

Our support

Finwise analyzes your digital dependency, sensitive data, critical tools and security posture. We compare cyber insurance based on actual guarantees, crisis management, sub-limits, exclusions and business interruption.

Assess my cyber risk See cyber insurance See legal protection

Let’s talk about your needs

Tell us about your situation in a few lines. A Finwise adviser will contact you to clarify your options and compare suitable solutions.