There is no single answer to how much cyber insurance a company should have in Switzerland. Swiss law does not set a standard coverage amount for every business. The right limit depends on how much one serious cyber event could cost your company.
For many Swiss SMEs, CHF 1 million can be a useful starting point when comparing quotes. However, a data-heavy company, online retailer or financial firm may need CHF 3 million, CHF 5 million or more. The goal is to insure your largest realistic loss, not simply choose the most common limit.
Is Cyber Insurance Mandatory in Switzerland?
Cyber insurance is generally voluntary for Swiss businesses. However, companies still have legal duties when a breach occurs.
Under the Federal Act on Data Protection, a controller must notify the Federal Data Protection and Information Commissioner as soon as possible when a data security breach is likely to create a high risk to a person’s privacy or fundamental rights. The FDPIC’s data breach guidance explains how this requirement applies.
This should not be confused with the GDPR’s 72-hour rule. Swiss law uses its own risk test and notification standard.
These rules do not determine how much cyber insurance a company must buy. They do, however, increase the need for fast access to forensic, legal and crisis-response support.
How Much Cyber Insurance Does a Company Need?
A company should have enough cyber insurance to cover its maximum realistic loss from one cyber incident. This includes downtime, data recovery, legal advice, customer notification, third-party claims and crisis management.
The following ranges can provide an initial reference:
Company profile
Limit to consider
Microbusiness with limited personal data
CHF 250,000–CHF 1 million
SME using cloud systems and customer data
CHF 1–CHF 3 million
Data-heavy or highly digital business
CHF 3–CHF 10 million+
Large or critical organization
Custom or layered programme
Microbusiness with limited personal data
Limit to considerCHF 250,000–CHF 1 million
SME using cloud systems and customer data
Limit to considerCHF 1–CHF 3 million
Data-heavy or highly digital business
Limit to considerCHF 3–CHF 10 million+
Large or critical organization
Limit to considerCustom or layered programme
How much cyber insurance does a company need?
These are planning ranges, not legal requirements. Two companies with the same revenue may need very different limits. A medical practice holding sensitive patient records may face greater cyber exposure than a construction business of the same size.
A practical calculation starts with the following formula:
Formula
Required cyber limit = first-party losses + third-party losses + contractual requirements − losses the company can fund itself
Here is how to estimate each part.
1. Calculate the Cost of Business Downtime
First, estimate how much gross profit your company could lose each day if its systems stopped working.
Multiply that figure by a realistic recovery period. A short technical issue may last one day, while ransomware can disrupt operations for several weeks. Add the cost of staff overtime, temporary systems, external IT support and delayed orders.
Also check the policy’s waiting period. Some business interruption coverage only starts after systems have been unavailable for a set number of hours.
2. Estimate Data Recovery and Response Costs
A cyber incident can create expenses long before a client makes a claim. First-party cyber coverage may pay for:
IT forensic investigations
Data and system restoration
Cybersecurity specialists
Legal advice
Customer notification
Credit monitoring
Crisis communications
Emergency call-centre support
Companies with complex systems, several offices or large customer databases should allow for higher recovery costs.
3. Measure Your Third-Party Liability
A data breach may affect clients, employees or business partners. Your company could face legal defence costs and claims for financial loss or privacy violations.
Risk increases when you process health data, payment details, identity documents or confidential business files. Firms serving international clients may also face requirements under foreign data protection laws.
Make sure the policy includes both first-party protection and third-party cyber liability insurance.
4. Review Fraud and Ransomware Exposure
Consider the largest payment your team could make through online banking or an invoice approval system. Social engineering and fraudulent payment instructions can create large losses without damaging your IT network.
Check whether the policy covers:
Business email compromise
Funds-transfer fraud
Invoice manipulation
Cyber extortion
Ransomware response
Data restoration after ransomware
These risks may have separate sublimits that are much lower than the headline policy limit.
5. Check Your Contracts
Clients, investors and commercial partners may require a minimum cyber insurance amount. Enterprise customers, for example, may request CHF 1 million or CHF 2 million in coverage before signing a service agreement.
Your policy should meet the highest relevant contractual requirement. However, that number is only a minimum. It may not cover your company’s full financial exposure.
Does the Main Limit Cover Every Cyber Loss?
Not always. A policy may show an overall limit of CHF 1 million but provide only CHF 100,000 for social engineering or data restoration.
Low sublimits can leave a company underinsured even when the main coverage amount appears sufficient.
Cyber Insurance Needs by Industry
Cyber risk does not depend on company size alone. Industry, data and system dependence can be more important than revenue.
1. Professional Services
A consultancy, law firm or accounting business may have a moderate number of records but hold highly confidential information. Its main risks include email compromise, client claims and loss of access to cloud files.
2. E-Commerce
An online retailer depends on its website, payment systems and customer database. Its limit should reflect lost sales during downtime, payment fraud, data recovery and possible claims from customers.
3. Healthcare and Financial Services
Healthcare and financial businesses process sensitive personal data. They may face higher investigation, notification and legal costs after a breach. A stronger limit and higher sublimits may be necessary even when the company has relatively few employees.
Find the Right Cyber Insurance Limit
The right cyber insurance limit should match your systems, data, contracts and financial exposure. Assurance Genevoise can help you compare coverage limits, sublimits, deductibles and exclusions across suitable policies.