Home · Blog
Risk transfer

Cyber insurance in an SME: what it covers and what it demands

30 September 2026 · 8 min read · ODCUS
Business owner weighing a thick insurance policy against a short list of ticked security basics, with a stack of unused software packages beside her

In the management meeting somebody says "we are cyber insured", and the topic is off the table for twenty minutes. Nobody in the room can say for what sum, for which event, or against which commitments. That is where cyber insurance in an SME gets expensive. Not at the premium, but on the day somebody takes the policy seriously for the first time.

A policy changes nothing about how likely an incident is. It changes who pays the bill, and up to what amount. That is a financing decision, and it belongs on the same table as capital spending and credit lines.

TLDR

Cyber insurance does not reduce risk. It turns a residual risk you have deliberately kept into a payment you can plan for. That only holds if the answers in the questionnaire match reality and you can show, after an incident, what was actually running. The questionnaire itself is short. It does not ask about your tool stack, it asks about a handful of boring things.

What a policy pays and what the company keeps

An incident does not produce one bill, it produces a pile. First the forensics, because in the early days nobody knows what happened. Then the recovery, the lawyers and the communication inside and out. On top of that the outage, because three days of standstill cost margin. And at the end possibly claims from customers whose data sat with you.

Most policies cover parts of that pile. The headline sum on the cover page is the least interesting number in it. What matters are the sub-limits underneath and the waiting period on business interruption. If a policy only responds after twelve hours of standstill, while an eight-hour production stop is the most expensive case in the building, the cover is not wrong. It just misses.

What usually stays with the company appears in no policy: the internal hours. The project that sits still for three months because the same people are working the incident. The order that does not come because a customer heard about it. And the improvements afterwards, because insurance pays for the return to the previous state, not the upgrade to a better one.

The bill after a cyber incident, split into the part the policy pays and the part that stays with the company
The headline sum on the cover page says less than the split underneath it.

When is cyber insurance worth it for an SME?

When a single incident demands more money than the company can take from its running cash flow without stopping investments or deferring payments. That is a liquidity question, not a security question. The answer comes from the finance department.

Take-up in Switzerland is modest. In August 2025 the Swiss Insurance Association (SVV, the industry body for Swiss insurers) counted around 67'000 cyber policies held by corporate customers, which corresponds to 10.8 per cent of companies domiciled in Switzerland. Among internationally active large corporations the share is well above half (Swiss Insurance Association survey on cyber insurance).

That gap is not automatically a failure. There are businesses that keep working for three days without IT and pay the damage out of the till. For them no policy is the right decision. The problem sits with the companies that never did the maths and therefore hold either no policy at all or the first one the broker put in front of them.

What does cyber insurance cost in an SME?

Any number printed here would be a guess. The premium depends on revenue, sector, cover limit and above all on the answers in the questionnaire. What can be said without looking at the quote: the item SMEs overlook most often is not the premium, it is the deductible.

The premium sits in the budget and comes round every year, so somebody notices it. The deductible lands once, in a week when everything is already on fire, and in many policies it is set so that smaller incidents stay entirely with the company. That is how a policy is built. It cuts off the peak and leaves the base where it is. That also settles the calculation management teams like to run: policy against measures. A policy finances what is left over after the measures.

What does the insurer want to know in the questionnaire?

Less than most people expect. In the questionnaires we see on mandates, it comes down to a second login step for every access from outside, separate administrator accounts, backups held off the network that have been restored at least once, a demonstrable state of updates, and a rule for who releases payments. A manageable list, not an architecture review.

That list is shorter than the tool stacks we find on mandates. The insurer is not pricing how many products are in use, it is pricing whether an attacker gets anywhere with a stolen password and whether the company comes back up. More protection, fewer tools, lower cost reads like a marketing line. In this calculation it is the line the insurer checks.

The answers in the questionnaire are a contractual statement, and that weighs more than the list itself. "On most accesses" becomes a tick in the "yes" box as soon as somebody has to finish the form, and that tick is the document a claim is later measured against. Throw the questionnaire over the fence into IT without an accountable person behind it, and you have signed a commitment about a state you do not know.

Where a claim comes apart

In our experience claims rarely fail because an insurer does not want to pay. They hang on three points.

That is why the insurer's number, and the question of who calls it when, belong in the same document as the IT provider's numbers. An incident response plan for an SME is only complete when the insurance has a named role in it, rather than existing as an appendix in the finance department's folder.

How this looks in a manufacturing business

A supplier in the Swiss Mittelland, around 260 employees, two plants. The policy renewal is six weeks out, the broker sends the questionnaire to IT, as every year. This time somebody fills it in who does not want to guess, and gets stuck on two points: three service partners reach equipment from the internet without a second login step, and the backups have never been fully restored.

The finance director learns this from a form, not from a report. Two options then sit on the management table: close both points before the renewal date, or answer "no" honestly and live with what the insurer makes of it. They choose to close them. Three weeks later remote access runs through a single path with a second step, and the IT team has taken one restore all the way through from start to finish.

The most useful thing about that round was not the premium. It was the first complete list of who reaches the network from outside. The business did not have that list before, and internally nobody had asked for it either. An insurer's questionnaire was therefore the cheapest stocktake this company ever got. That it had to come from outside says more about the leadership than about the insurer.

Who owns the policy inside the company

The most common arrangement in an SME: the finance director buys the insurance, IT fills in the questionnaire, and nobody connects the two. The policy sits in a folder alongside the building and liability contracts and gets renewed once a year. The questions that decide whether it is worth anything in a real incident get asked by nobody in that process.

Whoever leads security turns this into an ordinary piece of business. The policy is a treatment in the risk register, with a name next to it and a date. Somebody checks the sub-limits against the loss types that cost money in this particular business: standstill for a manufacturer, data loss and customer claims for a service firm. And the management team can say in one sentence which risk the company deliberately carries itself. That is the part the policy does not take over.

None of this needs a new folder. It needs a solid stocktake, so the answers in the questionnaire are evidenced rather than estimated. That is what a fixed-price Cyber Assessment delivers, and the questionnaire afterwards becomes routine work rather than a bet.

Common questions

Does an insurer require ISO 27001 certification?

In the cases we see, no. The entry point is a control list. A proof such as ISO 27001 shortens the conversation, because much of it is already documented, and it helps in sales towards customers. As a ticket of entry for a policy you do not need it.

Does cyber insurance pay a ransom?

Some policies cover extortion payments, some exclude them, and a few require the insurer's consent beforehand. That is written in the policy and nowhere else. Whether anything gets paid at all remains a business decision with legal review. The insurance does not take it off your hands, at most it finances the outcome.

Does notifying the insurer replace notifying the authorities?

No, those are two separate clocks. Anyone who has lost personal data checks whether to notify the Federal Data Protection and Information Commissioner (EDÖB, the Swiss data protection authority) once the breach of data security is likely to result in a high risk to the people affected (EDÖB guidance on reporting data security breaches). Organisations subject to the ISG (the Swiss Information Security Act) carry an additional deadline towards the federal authorities. None of those notifications is discharged by having informed your insurer.

Before the next renewal one question is more useful than the size of the cover limit: which single event would knock this business off its stride for two weeks, and has anybody ever written a number against it? As long as that number is missing, the discussion about cover limits stays an estimate on top of an estimate.

Not sure whether a fractional CISO fits your company?

In a free intro call we work out whether senior security leadership on a mandate makes sense for your company, and in what form. Honest answer included, even when it is "not yet".

Book a free intro call