Cyber cover begins with operational readiness
Cyber insurance can finance specialist support and defined losses after an incident, but it does not replace basic security. Before requesting quotations, document how your company uses email, cloud services, online banking, customer data and outsourced IT. Identify which systems are essential to issuing invoices, serving clients or paying salaries, and estimate how long the business could operate without them. The NCSC states that senior management retains responsibility for risk classification and business continuity even when day-to-day IT is outsourced. This first inventory makes a proposal more accurate and exposes gaps that should be corrected before cover starts.
Put the minimum controls in place
A practical baseline includes multi-factor authentication for business-critical access, prompt security updates, individual user accounts, restricted administrator rights and regular staff awareness training. Backups deserve special attention: the NCSC recommends keeping at least one copy offline and at an external location, checking that backups work and practising restoration. Record the date of the last successful restore test. Also list internet-facing systems, laptops, routers and cloud administrators. These controls reduce the chance and impact of an incident and give an insurer a clearer picture of the risk. Answer underwriting questions precisely; an inaccurate declaration can create problems when a claim is assessed.
Compare the protection, not only the premium
Typical areas to examine include access to an emergency response team, forensic investigation, removal of malware, restoration of data and systems, crisis communication, business interruption, privacy-notification costs and liability claims. Some risks may be optional or subject to special conditions, including social engineering, payment manipulation, cyber extortion, outsourced providers and pre-existing incidents. One Swiss insurer's current business product illustrates how these elements can be separated between core and supplementary cover; other contracts differ. Compare the deductible, waiting period, indemnity period, sub-limits, territorial scope, approved suppliers and exclusions. Ask exactly when lost income starts and how it must be proven.
Prepare the first 24 hours before an attack
Keep a short incident plan somewhere accessible when the network is unavailable. It should name the decision-maker, IT provider, insurer hotline, legal adviser, communications contact and substitute for each role. Include how to isolate affected equipment without destroying evidence, where clean backups are stored, who can approve emergency spending and how staff will communicate if email is down. The NCSC's emergency-planning model covers preparation, the incident itself, response and a structured debrief. A policy may give access to experts, but employees still need to know whom to call and which actions require the insurer's prior agreement.
Know the Swiss reporting duties
A report to the NCSC is voluntary for most companies and can provide an initial assessment; since 1 April 2025, specified operators of critical infrastructure have a separate mandatory reporting regime. The NCSC does not receive criminal complaints, so suspected crimes may also require contact with the police. Personal-data breaches follow another test: Article 24 of the Federal Data Protection Act requires the controller to notify the FDPIC as quickly as possible when a breach is likely to create a high risk to the personality or fundamental rights of affected people. Switzerland does not apply a blanket 72-hour rule to every SME incident. Record the facts, risk assessment and decisions, and obtain specialist advice where the impact is unclear.
A five-point file for a useful insurance review
Bring five items to the discussion: your systems and data inventory; current security controls and restore-test evidence; maximum tolerable downtime; incident contacts and decision roles; and existing IT, liability and property policies. Then select realistic scenarios—such as ransomware stopping invoicing, a fraudulent payment instruction or the loss of sensitive client data—and check each scenario against the wording. This approach helps reveal overlaps and gaps without assuming that every cyber event is insured. For help comparing business cover, review the site's cyber-insurance service page or arrange a consultation. Advice should be based on the final policy wording and the insurer's written acceptance.
Sources & further reading
NCSC — Strong cybersecurity foundations for businesses and public authorities
NCSC — Emergency planning is the key to cyber resilience
FDPIC — Guidelines on data breaches