Skip to main content
All guides
11 min read·Last updated: 2026-07-08

Cyber insurance for SMEs: coverage, claims management and accounting for IT costs in Switzerland

From digital risk assessment to the accounting treatment of premiums, indemnities and security investments: everything entrepreneurs and trustees need to know in 2026.

Why cyber insurance has become relevant for SMEs

Ransomware attacks, theft of customer data, disruption of billing systems: cyber risks no longer affect only large corporations. In Switzerland, where the digitalisation of accounting, document archiving and electronic payments is now widespread even among small practices and craft businesses, a single incident can halt operations for days and generate costs in the five- or six-figure range.

Cyber insurance does not replace technical protective measures, but complements risk management with financial coverage and incident response services. For entrepreneurs, IT managers and accounting trustees, the question is not simply "do we need it or not?", but rather "which coverages are appropriate for our risk profile" and "how are premiums, deductibles and indemnities reflected in the accounts".

This guide outlines the coverages typically available on the Swiss market, the claims handling process and the correct accounting treatment of IT and insurance costs under Swiss accounting standards (Swiss GAAP FER), with practical references for users of accounting software such as Accountex.

Overview of cyber risks for Swiss SMEs

Before taking out a policy, it is worth mapping the company's concrete risks. Swiss SMEs typically expose the following vulnerabilities:

Ransomware and malware

Encryption of servers, email or backups, with a ransom demand in cryptocurrency. Without tested offline backups, downtime and recovery costs escalate rapidly.

Personal data breach

Unauthorised access to customer, employee or patient data. Under the revised Federal Act on Data Protection (nFADP/FADP), in force since 1 September 2023, SMEs must ensure adequate technical and organisational measures and may face criminal penalties against responsible individuals as well as compensation claims.

Phishing and cyber fraud

Fraudulent emails inducing bank transfers or disclosure of credentials. Direct financial losses and third-party liability are often among the most sought-after coverages.

Business interruption

Unavailability of ERP, CRM, e-commerce platforms or production systems. Even a few days of downtime can jeopardise liquidity, especially in sectors with tight margins or marked seasonality.

Comparative table of typical cyber coverages

Policies on the Swiss market vary by insurer, sector and company size. The following table summarises the most common coverages and their relevance for an SME:

Coverage What it includes SME relevance
Incident response IT forensics, containment, system restoration, 24/7 hotline High — often the immediate value of the policy
Ransomware / cyber extortion Negotiation costs, ransom (if permitted), data restoration High — check exclusions and limits
Business interruption (cyber BI) Loss of profit and fixed costs during downtime caused by a cyber incident Medium-high — depends on digital dependency
Third-party liability Damage to clients from data breaches, online defamation, malware transmission High — sectors with sensitive data (healthcare, consulting, HR)
Data breach notification and management Communications to the FDPIC, affected individuals, legal advice High — strengthened obligations under the nFADP
Cyber fraud / social engineering Losses from fraudulent transfers induced by third parties Medium — often subject to sub-limits or high deductibles
Fines and penalties Administrative sanctions for regulatory violations Low — often excluded or limited due to mandatory law
Media and PR crisis Communications consulting and reputation management Medium — useful for B2C companies or those with a strong online presence

Note: many standard commercial liability policies explicitly exclude cyber-related damage. A dedicated cyber policy or specific extension is almost always necessary for effective coverage.

First party vs third party: two families of protection

Cyber policies are primarily distinguished by the nature of the damage covered:

First-party coverages (own damage)

Protect the insured company against the direct costs of an incident: forensics consulting, backup restoration, ransom payments, production downtime, notification expenses. They form the backbone of most cyber policies for SMEs.

Limits and deductibles apply per claim or per policy year. It is essential to verify whether internal costs (IT staff hours) are reimbursable or excluded.

Third-party coverages (damage to third parties)

Cover claims from clients, suppliers or other third parties for damage caused by a cyber incident attributable to the company: data breaches, interruption of services provided, unintentional malware distribution.

Often integrated into professional liability insurance or a separate cyber module. For medical practices, consultants, law firms and SaaS companies, third-party limits deserve particular attention.

Premiums, limits and underwriting requirements

In Switzerland, premiums for SME cyber policies typically start from a few thousand francs per year for basic coverages with modest limits, and can exceed CHF 10,000–20,000 for companies with high turnover, sensitive data or critical dependence on digital systems. Factors influencing the premium include sector, turnover, number of employees, offline backup presence, multi-factor authentication (MFA), patch management and claims history.

Insurers almost always require an underwriting questionnaire (cyber risk assessment). Inaccurate declarations can lead to reduced or denied indemnification. Document internally the state of security controls at the time of underwriting and at each renewal.

Contractual elements to review carefully: deductible per claim, waiting period for business interruption, sub-limits for individual coverages, co-insurance clauses, obligation to involve insurer-approved vendors in the event of a claim, and exclusions for state-sponsored attacks or failure to meet minimum security requirements.

Claims management: stages and documentation

A cyber incident requires coordinated and timely action. Most cyber policies require notification within 24–72 hours of discovering the incident. Late or failed notification can jeopardise coverage.

1. Containment and policy activation

Isolate compromised systems, preserve digital evidence and contact the insurer's hotline immediately. Do not pay ransoms without written authorisation, unless the contract provides otherwise. The insurer usually appoints a forensics expert and a specialist lawyer.

2. Documentation for the adjuster and accounting

Record every action chronologically: date and time of discovery, systems involved, external consulting costs, internal IT staff hours, hardware and software restoration expenses, communications with clients and authorities. Keep invoices, bank statements and correspondence with the insurer in a dedicated folder — also useful for the statutory audit.

3. Regulatory obligations (nFADP)

If the incident involves a breach of data security that is likely to result in a high risk to the personality or fundamental rights of the data subjects (Art. 24 FADP), assess the obligation to notify the Federal Data Protection and Information Commissioner (FDPIC) and, where necessary, to inform the affected individuals. Legal advice covered by the policy can support this assessment.

4. Settlement and closure

The insurer approves covered costs net of the deductible. Non-reimbursed items remain the company's responsibility. At the end, agree a written summary with the total indemnity paid and excluded items — necessary for correct accounting entries.

Accounting in Switzerland under Swiss GAAP FER

For entrepreneurs and trustees, the correct allocation of premiums, incident costs and indemnities ensures a faithful balance sheet and simplifies tax reporting. Below are the most common operational rules for SMEs applying Swiss GAAP FER.

Transaction Typical account (Kontenrahmen KMU) Accounting treatment
Annual cyber policy premium 6300 Versicherungsaufwand (Sachversicherungen) Operating expense at accrual; if paid in advance, amortisation via active transitory account (1300 Aktive Rechnungsabgrenzungen)
IT security investments (firewall, EDR, backup) 1520 Büro-/IT-Anlagen or 6570 Informatikaufwand Hardware and perpetual licences with a useful life > 1 year: capitalisation and depreciation; SaaS and recurring maintenance: direct expense
Incident costs (consulting, restoration) 6570 Informatikaufwand / 6700 Sonstiger betrieblicher Aufwand Record when actually incurred; track potentially reimbursable items separately
Deductible borne by the company Same account as related costs Not reimbursable — remains fully in the income statement as a cost of the period
Insurance indemnity received Offset against expense account or 8510 Ertrag ausserordentlich Preferred method: offset against expenses already recorded (netting). Alternative: extraordinary income if costs are already closed
Loss of profit (cyber BI) Revenue accounts (class 3) / 6700 Sonstiger betrieblicher Aufwand Document the loss calculation with accounting evidence; the indemnity offsets the proven and contractually covered loss

Tax implications: cyber insurance premiums are generally deductible as operating expenses for income tax and profit tax purposes. Indemnities may be taxable if they compensate losses already deducted or if classified as extraordinary income; classification depends on the nature of the compensation and the accounting treatment chosen. If in doubt, consult your trustee or tax adviser.

VAT: premiums for direct insurance in Switzerland are not subject to VAT (Art. 21 para. 2 VAT Act). IT services purchased to manage an incident (consulting, restoration) may attract deductible VAT if the company is registered.

Recognition and estimation: under the prudence principle (Swiss GAAP FER 9/10), do not anticipate indemnities not yet confirmed by the insurer. Record the indemnity at final settlement or when the amount is virtually certain and collection is probable.

Practical organisation with Accountex

Integrated accounting software makes it easier to track IT costs and manage insurance claims. Here is a recommended operational setup:

  • Dedicated chart of accounts: create sub-accounts under 6300 (cyber premiums) and 6570 (IT expenses and incident response) to separate ordinary costs from claim-related costs. In the event of an incident, quickly filter reimbursable items.
  • Cost centre or project: open a cost centre "Cyber Incident [year]" to associate invoices, expense reports and internal hours. Simplifies reporting to the insurer and accounting closure at the end of the claim.
  • Digital attachments: archive the policy, underwriting questionnaire, adjuster's report and settlement as attachments to accounting entries. Useful for audits and insurance renewals.
  • Budget and monitoring: enter the annual premium and recurring IT expenses in the budget to compare planned and actual costs, identifying variances linked to incidents or security investments.

Checklist for entrepreneurs and trustees

  • Check whether commercial liability insurance excludes cyber risks and assess a dedicated policy.
  • Map personal data processed and align coverages with nFADP obligations.
  • Document security controls (MFA, backups, patching) for underwriting and renewal.
  • Keep the hotline and claims notification procedure in an incident response plan.
  • Account for premiums on 6300 and IT costs on 6570, with sub-accounts for claims.
  • Do not anticipate indemnities; record at final settlement.
  • Reconcile premiums paid, IT expenses and any insurance reimbursements quarterly.
  • Integrate cyber insurance into corporate risk management and liquidity planning.

Conclusion: prevention, coverage and integrated accounting

Cyber insurance does not eliminate cyber risk, but reduces its financial impact and provides immediate access to specialist expertise in the event of an incident. For Swiss SMEs, the combination of adequate technical measures, a well-sized policy and orderly accounting forms a solid foundation for digital resilience.

Entrepreneurs and trustees who rigorously track premiums, security costs and claims not only comply with Swiss GAAP FER, but also have useful data for negotiating insurance renewals, justifying IT investments and demonstrating conscious risk management — even when dealing with banks, corporate clients and auditors.

Simplify your Swiss accounting

AccountEX handles VAT, QR-invoices and bookings with AI. Start for free.