SOC Geneva — operational 24/7 Client support Remote support +41 22 740 28 29
RISK · CYBER-INSURANCE · 2026-09 · 7 MIN

Your cyber-insurance may not pay out:
the controls Swiss insurers now require.

Cyber cover has become standard for Swiss SMEs. But a policy is not protection — and insurers increasingly reduce or refuse a payout when the security controls named on your application were never actually in place.

2026-09 · 7 MIN READ

Over the last three years, cyber-insurance in Switzerland has gone from a cheap add-on to a scrutinised, underwritten product. Premiums have risen, questionnaires have grown from half a page to several pages, and — the part too many organisations miss — insurers now verify what you declared. A signed policy in the drawer feels like protection. It isn't: it's a contract whose payout depends on conditions you have to meet before the incident, not after.

Why the market hardened

Ransomware turned cyber-insurance into a loss-making line for insurers, and they responded the way any underwriter does: by pricing risk properly and demanding evidence of controls. Today, cover for a Swiss SME is conditional. The application is no longer a formality — it is the basis on which a claim will later be accepted or contested.

What insurers now require

The specifics vary by insurer, but the same baseline appears in almost every questionnaire we see clients fill in:

  • MFA everywhere that matters — email, remote access (VPN/RDP), and privileged and administrative accounts. "Enabled for some users" is the single most common gap.
  • EDR on every endpoint — modern endpoint detection and response, not just legacy antivirus, ideally with monitoring behind it.
  • Backups that are tested and out of reach — offline or immutable copies, and — crucially — restores that have actually been rehearsed.
  • A patching cadence — known critical vulnerabilities closed within a defined window, and end-of-life systems off the network.
  • Email filtering and user awareness — the front door for most claims.
  • Network segmentation and privileged-access control — so one compromised workstation isn't the whole estate.
  • A written incident-response plan — who decides, who is called, in what order.

The dangerous assumption is "we have a policy, so we're covered." The real question an insurer asks after an incident is narrower: were the controls you declared actually operating on the day you were hit?

THE ASSUMPTION THAT COSTS CLAIMS

The warranty trap

Your answers on the proposal form are contractual. If you declared MFA on all remote access but it was enforced on only part of the estate, or you stated backups were tested when they had never been restored, the insurer can reduce the settlement or decline the claim for misrepresentation — precisely when you need it most. The gap between "we ticked yes" and "it was genuinely true across the organisation" is where cover quietly evaporates.

What we see go wrong

The pattern is consistent, and rarely malicious — just untended: MFA switched on for most staff but not on a legacy VPN or a shared admin account; backups running nightly but never restore-tested, so no one knows they exclude a critical system; an end-of-life server kept "just until the migration"; an incident-response plan that exists as a PDF nobody has read. Each looks minor until it becomes the reason a seven-figure claim is contested.

How to make your policy actually pay

Treat the insurer's questionnaire as a security to-do list, not a form to get past. Map each question to the reality of your environment, close the gaps, and — the step that matters — keep evidence: enforcement reports, restore-test logs, patch records, the signed IR plan. Review it annually, because both your environment and the insurer's requirements move. Done well, this does two things at once: it lowers your premium and it turns a contested claim into a paid one.

In short

Cyber-insurance is worth having — but it transfers residual risk, it doesn't replace the controls. The organisations that get paid are the ones whose declared security is real, operating and documented. That alignment between what you signed and what you actually run is exactly what our SOC and consulting division build and evidence for SMEs and organisations across French-speaking Switzerland.

This is a demonstration article for the mockup — to be reviewed by the InterHyve team before publication. It is general information, not insurance or legal advice; check your own policy wording.

Talk to our engineers

Would your cyber-insurance actually pay out?

Our free audit maps your controls to what insurers require — MFA, EDR, tested backups, IR plan — so a claim is paid, not contested.

GENEVA · +41 22 740 28 29 · INFO@INTERHYVE.COM
Talk to our engineers