Avantec AG
Zug
Everything You Need to Know About Cyber Insurance Now – AVANTEC
- 08 August 2026
- 100%
- Permanent position
- Zug
About the job
The successful cyber-attacks on Stadler Rail and Meier Tobler have caused damages amounting to millions. Even for small and medium-sized enterprises, costs of 50 to 100 kCHF per attack are to be expected on average. Such attacks continue to increase and become ever more sophisticated, while companies and their business models become increasingly dependent on digitalisation and smooth IT operations. Preventive measures to reduce cyber risks are important, but residual risks are unavoidable and can be costly for a company. Cyber insurance offers a sensible complement to existing risk management. Which damages these insurances cover, why it makes sense, and what to watch out for, you can read in this blog article. Cyber insurance briefly explained – which damages are covered… Although there is no reporting obligation for cyber-attacks in Switzerland yet, reports about them are accumulating in the media. It can no longer be sugar-coated: any company can be affected. Whether a denial-of-service attack on an online shop, an attack with ransomware and the associated extortion attempt, or a targeted and individualised phishing campaign – the range of different attack methods is large. And so is the damage potential. In addition to the actual restoration of systems and data, costs arise for the involvement of external IT specialists, legal services, or PR experts for crisis communication. Depending on the impact, claims from third parties, e.g. customers, must also be examined, handled, and possibly compensated. An operational interruption also causes significant damage in the form of productivity loss and lost revenue. The usual business liability insurance in companies covers the insured's fault towards third parties, but usually only personal injury and property damage are covered. Cyber-attacks primarily involve financial losses. Cyber insurance covers both damages caused by the insured to a third party and damages incurred by the insured themselves (own damage). Third-party claims arise if the insured damages, loses, or impairs the business activities of third parties due to deficiencies in their system. Own damages include, among other things, the loss of own data or loss of earnings due to operational interruption. The following list shows which damages or costs can be covered by cyber insurance: Restoration of lost and damaged data Restoration of IT systems and networks Investigation costs including involvement of IT and forensic experts Extortion payments (e.g. in case of ransomware) Damages due to operational interruptions including loss of earnings (e.g. in denial-of-service attacks) Expenses for crisis communication and PR experts to mitigate reputational damage Costs for legal defence against unjustified third-party claims Compensation of justified third-party claims Liability in connection with data protection It is basically irrelevant whether the damage was caused by a cyber-attack, a disruption of internal network security, or human error or a programming mistake. Cyber insurance therefore applies not only in the case of cybercrime. …and which damages are not covered Nowadays, there are many providers of cyber insurance in Switzerland. However, these offers differ in the breadth and depth of insured services or coverage, so it is important to know your own cyber risks well and to correctly derive the needs for cyber insurance. It should also be taken into account that not all possible damages or causes can be insured. The following risks are generally not yet covered: Internet interruption Money transfer due to social engineering (e.g. C-level fraud) Lost earnings due to reputational damage Compensation claims due to intellectual property infringement Replacement of hardware In these cases, the company only has the option to reduce the occurrence and/or extent of damage through technical and organisational measures or to accept the risk. But even insurable risks can be tricky, as the legal dispute between the food company Mondelez and Zurich Insurance Group shows. Mondelez had insured itself against damages related to IT system failures, explicitly including malware as a cause. In 2017, Mondelez fell victim to the NotPetya malware, which caused massive damage. The insurer paid part of the sum insured but refused to pay the rest. NotPetya was classified as a war-like act by a state actor, as Russia could be identified as the originator of this ransomware. Such damages are usually excluded from insurance policies. This point is problematic insofar as malware originally funded or developed by states is often later also available to other cybercriminals. And now? Cyber risks belong in risk management, and at the highest level! Cyber insurance is not a magic bullet and should certainly not be considered in isolation from other measures. Companies must move away from leaving responsibility for IT and cyber risks to the IT department. With the already existing and further rapidly increasing dependence on IT, these risks must be addressed by the board of directors and top management. As part of the company's risk management, cyber risks must also be assessed based on probability of occurrence and extent of damage, and effective measures defined. Minor risks can be borne by the company itself, but in more critical cases, cyber insurance is a sensible addition to existing practice. Since the spectrum of cyber-attacks is very broad, not everything can be insured. Professional risk management should provide answers as to which cases are relevant and where it is financially worthwhile to invest in insurance. It should definitely be considered whether there are already overlaps with existing insurances, e.g. regarding business interruption. Recently, I spoke with an IT manager of an industrial company who complained that the company management spends a lot of money on cyber insurance, which he would rather invest in further technical measures. Ultimately, the right mix of measures is decisive. Preventive measures are good but do not protect 100%. Residual risks are unavoidable and must also be effectively managed. One aspect must not be forgotten: quickly recognising an attack and responding immediately can contribute to damage mitigation just as much as preventive measures. Investments in technical measures for detection & response are therefore as sensible as considering cyber insurance. Anyone who wants to take out cyber insurance will probably be confronted with a catalogue of measures anyway, as insurers typically set minimum requirements for companies' IT security precautions. For example, the German Insurance Association (GDV) recommends implementing or adhering to at least the following 10 security standards: Anti-virus programmes must always be kept up to date. Data backup must be performed at least once a week. Updates and security patches for software must be applied promptly. The network must be secured by a firewall as well as security monitoring and intrusion prevention solutions. Access for IT administrators must be set up and access rights restricted. Access for employees must be set up with their own login credentials. Users should be forced to use complex passwords and change them regularly. Mobile devices and data carriers must be encrypted and secured by two-factor authentication (2FA). Backup copies must be stored physically separate from the server/data. The backup concept must be regularly tested (data restoration). Conclusion While dependence on digitalisation and IT continues to increase massively, more and more criminals are sniffing out the business with cyber-attacks. No matter how much time and money companies invest in measures against these IT threats, a residual risk remains and it can be very costly. Cyber risks belong in the top management's risk management and should be regularly reassessed. Preventive measures are good, but it makes sense to engage with the topic of cyber insurance regarding residual risks to limit potential financial damages. It’s all in the mix. Technical solutions for detection & response should also be considered, as they can also contribute to damage mitigation by detecting attacks early and enabling immediate response. Where we have only scratched the surface in this blog article on cyber insurance, in part 2 we will try to provide deeper insight into conditions, coverage, practical suitability, risks, and side effects. For this, we will ask the expert. Stay tuned. Links Detection & Response: What options are available: tec-bite.ch/welche-moeglichkeiten-gibt-es-fuer-detection-response/ Security Monitoring Service – Alerts and events for your detection & response solutions: avantec.ch/services/security-monitoring-service/ The article Everything You Need to Know About Cyber Insurance Now – and Why It’s Time to Deal With It – Part 1 first appeared on Tec-Bite.