Blog

How Much Cyber Insurance Should Swiss Companies Have? (2027 Guide)

Learn how much cyber insurance a Swiss company needs and how to calculate the right coverage limit for 2027.

Particulier
Blog Assurance Genevoise Image

Introduction

There is no single answer to how much cyber insurance a company should have in Switzerland. Swiss law does not set a standard coverage amount for every business. The right limit depends on how much one serious cyber event could cost your company.
For many Swiss SMEs, CHF 1 million can be a useful starting point when comparing quotes. However, a data-heavy company, online retailer or financial firm may need CHF 3 million, CHF 5 million or more. The goal is to insure your largest realistic loss, not simply choose the most common limit.

Is Cyber Insurance Mandatory in Switzerland?

Cyber insurance is generally voluntary for Swiss businesses. However, companies still have legal duties when a breach occurs.
Under the Federal Act on Data Protection, a controller must notify the Federal Data Protection and Information Commissioner as soon as possible when a data security breach is likely to create a high risk to a person’s privacy or fundamental rights. The FDPIC’s data breach guidance explains how this requirement applies.
This should not be confused with the GDPR’s 72-hour rule. Swiss law uses its own risk test and notification standard.
Since 1 April 2025, certain operators of critical infrastructure must also report covered cyberattacks to the NCSC within 24 hours.
These rules do not determine how much cyber insurance a company must buy. They do, however, increase the need for fast access to forensic, legal and crisis-response support.

How Much Cyber Insurance Does a Company Need?

A company should have enough cyber insurance to cover its maximum realistic loss from one cyber incident. This includes downtime, data recovery, legal advice, customer notification, third-party claims and crisis management.
The following ranges can provide an initial reference:
Microbusiness with limited personal data
Limit to considerCHF 250,000–CHF 1 million
SME using cloud systems and customer data
Limit to considerCHF 1–CHF 3 million
Data-heavy or highly digital business
Limit to considerCHF 3–CHF 10 million+
Large or critical organization
Limit to considerCustom or layered programme
How much cyber insurance does a company need?
These are planning ranges, not legal requirements. Two companies with the same revenue may need very different limits. A medical practice holding sensitive patient records may face greater cyber exposure than a construction business of the same size.
Before selecting a limit, it helps to understand what cyber insurance covers in Switzerland and which losses remain excluded.

How to Calculate Your Cyber Insurance Limit

A practical calculation starts with the following formula:

Formula

Required cyber limit = first-party losses + third-party losses + contractual requirements − losses the company can fund itself
Here is how to estimate each part.

1. Calculate the Cost of Business Downtime

First, estimate how much gross profit your company could lose each day if its systems stopped working.
Multiply that figure by a realistic recovery period. A short technical issue may last one day, while ransomware can disrupt operations for several weeks. Add the cost of staff overtime, temporary systems, external IT support and delayed orders.
Also check the policy’s waiting period. Some business interruption coverage only starts after systems have been unavailable for a set number of hours.

2. Estimate Data Recovery and Response Costs

A cyber incident can create expenses long before a client makes a claim. First-party cyber coverage may pay for:
  • IT forensic investigations
  • Data and system restoration
  • Cybersecurity specialists
  • Legal advice
  • Customer notification
  • Credit monitoring
  • Crisis communications
  • Emergency call-centre support
Companies with complex systems, several offices or large customer databases should allow for higher recovery costs.

3. Measure Your Third-Party Liability

A data breach may affect clients, employees or business partners. Your company could face legal defence costs and claims for financial loss or privacy violations.
Risk increases when you process health data, payment details, identity documents or confidential business files. Firms serving international clients may also face requirements under foreign data protection laws.
Make sure the policy includes both first-party protection and third-party cyber liability insurance.

4. Review Fraud and Ransomware Exposure

Consider the largest payment your team could make through online banking or an invoice approval system. Social engineering and fraudulent payment instructions can create large losses without damaging your IT network.
Check whether the policy covers:
  • Business email compromise
  • Funds-transfer fraud
  • Invoice manipulation
  • Cyber extortion
  • Ransomware response
  • Data restoration after ransomware
These risks may have separate sublimits that are much lower than the headline policy limit.

5. Check Your Contracts

Clients, investors and commercial partners may require a minimum cyber insurance amount. Enterprise customers, for example, may request CHF 1 million or CHF 2 million in coverage before signing a service agreement.
Your policy should meet the highest relevant contractual requirement. However, that number is only a minimum. It may not cover your company’s full financial exposure.

Does the Main Limit Cover Every Cyber Loss?

Not always. A policy may show an overall limit of CHF 1 million but provide only CHF 100,000 for social engineering or data restoration.
Review the following points before buying business cyber insurance in Switzerland:
  • Overall limit per claim
  • Annual aggregate limit
  • Business interruption sublimit
  • Ransomware and extortion sublimit
  • Social engineering and payment fraud
  • Data recovery costs
  • Third-party liability
  • Dependent business interruption
  • Deductible
  • Waiting period
  • Geographic coverage
Low sublimits can leave a company underinsured even when the main coverage amount appears sufficient.

Cyber Insurance Needs by Industry

Cyber risk does not depend on company size alone. Industry, data and system dependence can be more important than revenue.

1. Professional Services

A consultancy, law firm or accounting business may have a moderate number of records but hold highly confidential information. Its main risks include email compromise, client claims and loss of access to cloud files.

2. E-Commerce

An online retailer depends on its website, payment systems and customer database. Its limit should reflect lost sales during downtime, payment fraud, data recovery and possible claims from customers.

3. Healthcare and Financial Services

Healthcare and financial businesses process sensitive personal data. They may face higher investigation, notification and legal costs after a breach. A stronger limit and higher sublimits may be necessary even when the company has relatively few employees.

Find the Right Cyber Insurance Limit

The right cyber insurance limit should match your systems, data, contracts and financial exposure. Assurance Genevoise can help you compare coverage limits, sublimits, deductibles and exclusions across suitable policies.