Cyber Insurance
Cyber insurance covers first-party and third-party losses from information security breaches – such as business interruption after ransomware, data restoration, liability and crisis services.
Comparison profile
- Trigger
- Claims-made
- Insured interest
- The policyholder's own financial loss and third-party liability exposure arising from information security breaches and network security incidents, irrespective of whether physical property is damaged.
- Rating basis
- Revenue and data volume/sensitivity, Industry sector and regulatory exposure, Security controls in place (MFA, backups, endpoint detection, patch management), Prior claims/incident history
- Typical limits
- Limits are typically purchased in layers from a few million up to several hundred million CHF/EUR for large corporates, often shared across first-party and third-party sections with sublimits for cyber extortion and crisis services.
- Typical deductibles
- Per-claim or per-event deductible/retention, often combined with a waiting period deductible for the business interruption element.
- Target segments
- SME, Industry, Multinational
Insured events
- Ransomware and other malware attacks
- Data breaches involving personal or confidential information
- Denial-of-service and network security incidents
- Cyber extortion and ransom demands
- Human error or system failure causing a security breach
Key exclusions
- War and state-attributed attacks
- Losses from failure to maintain agreed minimum security controls
- Bodily injury and property damage (ceded to property/liability lines, subject to silent-cyber demarcation)
- Fines and penalties that are uninsurable by law
- Pre-existing, known vulnerabilities not remediated
Coverage components
First party: cyber business interruption, data restoration, cyber extortion (including negotiation services), crisis management and forensics. Third party: liability for data protection breaches and network security incidents, defence costs and regulatory proceedings where insurable.
Underwriting requirements
Insurers require minimum standards such as multi-factor authentication, tested offline backups, endpoint detection, patch management and incident response plans. Missing controls lead to exclusions, sublimits or declinature.
Market development
War and state-attributed attacks are increasingly excluded with precise wordings; ransom payments are subject to sanctions reservations. The demarcation from property and kidnap-and-ransom policies (silent cyber) should be expressly regulated within the programme.
Comparison and delineation
Cyber insurance is regularly complemented by property all risks, which insures physical damage but expressly excludes cyber losses without a resulting physical damage event, and by business interruption cover, which as a stand-alone product responds only after an insured property damage event, not after a purely digital outage. The programme boundary between the two is exactly this physical-damage trigger: cyber policies fill the gap that property and business interruption wordings leave for outages, data loss, and extortion that never touch physical assets.