2025-2026 landscape: an industrialized threat
Switzerland's National Cybersecurity Centre (NCSC) recorded a 38% rise in SME-reported incidents between 2024 and 2025. The underlying trend: ransomware-as-a-service (RaaS) has made attacks accessible to groups without their own technical expertise — a 12-employee SME is as targetable as a large group, sometimes more, because its defenses are weaker. The three dominant vectors: phishing email (67% of incidents), unsecured remote access (RDP, VPN without MFA), and compromised third-party suppliers (supply chain attacks).
What a cyber policy actually covers
A well-structured cyber policy covers four major blocks. 1 — Crisis management costs: digital forensics (identify the attack and its vector), data-breach notification (LPD obligation in Switzerland), press relations management. 2 — Business interruption: compensation for lost revenue during downtime (often the heaviest cost — 3 to 21 days depending on severity). 3 — Ransom: coverage or reimbursement of ransom paid, with dedicated negotiator support. 4 — Cyber liability: if your client or third-party data is compromised, coverage for claims and defense costs.
What isn't covered — common exclusions
Standard exclusions to know: intentional fault or gross negligence (unrotated default passwords), nation-state attacks on critical sectors, unpatched software (update available 6 months and ignored), coverage if backups weren't current. Some insurers require a minimum security audit (questionnaire + proof of backups, MFA on emails and remote access) before extending coverage. Cyber insurance is not a substitute for basic security — it's the safety net after good practices are in place.
How to assess your need and choose
Four sizing criteria. 1 — Data value: if you store personal client data (GDPR/LPD) or trade secrets, your exposure is high. 2 — IT dependency: if a 48-hour system outage would threaten your survival (e-commerce, SaaS, medical practice, fiduciary), your business interruption coverage must be calibrated accordingly. 3 — Revenue: below CHF 1M, a basic policy is often sufficient. Above that, aim for full coverage with forensics included. 4 — Regulated sector: finance, health, lawyers — specific legal obligations (LPD, DORA for finance) may impose minimum coverages. Polia compares the main cyber SME offerings available in Switzerland.