When her insurer sent back the cyber-insurance contract to renew, Dr Anne P. expected a routine signature. Instead, she found a security questionnaire: is two-factor authentication switched on for the practice's mailboxes? Are the patient-record backups tested? At the front desk, Lucie F. admitted that no one had ever checked. Which leaves one uncomfortable question: on the day of an incident, would the insurer actually pay?
What cyber-insurance really covers (and what it leaves out)
Cyber-insurance is a contract that transfers part of the financial cost of an IT incident — an attack, a data breach, an outage caused by an intruder — to an insurer. It does not replace security: it cushions the blow when, despite everything, something gets through.
In practice, a good policy usually covers three families of costs. First, crisis management: calling in specialists at short notice to understand the attack, clean up the systems and recover the data. For a medical practice, that can mean restoring access to the patient record after a ransomware attack — malicious software that encrypts your files and demands a ransom to make them readable again. Second, business interruption: the revenue lost while the practice runs at half speed, appointments and billing on hold. Third, ancillary costs: notifying the people affected, legal advice, communications, and sometimes support in handling a request from a patient or an authority.
One item is often underestimated: the indirect consequences. A health-data leak isn't only a repair bill — it's damaged trust, patients who hesitate, a reputation to rebuild. Some policies cover part of these effects (communications costs, support), others don't. It's a point to clarify before signing, because no two contracts are alike: what follows describes market trends, not your particular policy. For a firm decision, your broker or insurer remains the right person to ask.
But a contract is best read backwards, through its exclusions — the situations where the insurer won't pay. Four come up almost every time. A deliberate act by an employee, an act of sabotage, is not covered. Neither is outdated infrastructure left without updates: if a flaw known for months was never patched, the insurer may conclude the risk was not under control. Acts of war and state-attributed attacks are excluded on principle. And above all — this is the SME blind spot — failing to honour your own security commitments.
Because cyber-insurance is almost never unconditional. It is usually conditioned on a minimum of hygiene: when you take out the policy, you declare a number of measures as being in place. If, on the day of the incident, those measures didn't really exist, the payout can be reduced or even refused. That is exactly what the questionnaire Dr Anne P. received is testing: the insurer isn't selling a blind safety net, it's checking that you have set up your own.
Add to that the numbers people forget to read. The cap, first: the maximum amount the insurer will reimburse. The deductible, next: the share you bear on every claim. Sometimes a waiting period before cover kicks in. A policy capped at a few tens of thousands of francs will not cover a group practice that is shut down for several weeks.
The difference plays out at claim time. Take two care providers hit by ransomware on the same Monday. The first had declared two-factor authentication and tested backups — and genuinely had them: its insurer covers the emergency response, the lost days of activity and the legal fees, and the practice restarts with confidence. The second had ticked the same boxes on paper, but authentication was only switched on for some accounts and the last backup was months old and never tested. The result: a trimmed payout, painful conversations, and a bill largely on its own shoulders. Same contract, same incident — two opposite outcomes, decided long before the attack.
What to remember
Three ideas are enough to change how you see the subject.
Cyber-insurance is a shock absorber, not a shield. It steps in after the incident to limit the financial damage; it does not prevent the attack and replaces no protective measure. Presenting it to your partners as "we're covered, so we're fine" is the surest way to be caught out.
You have to earn it. Most contracts require a base of cyber hygiene — two-factor authentication, tested backups, up-to-date systems, access management — and may refuse to pay if that base wasn't there. In other words, the steps that make you insurable are exactly the ones that reduce the risk: you never work for nothing.
The contract lives in the detail. Caps, deductibles, exclusions, declared obligations: it's those lines, not the sales pitch, that decide what you'll actually receive. In Switzerland, an incident involving health data also falls under the nFADP, the federal data protection act, which requires the data controller — here, the practice — to take "appropriate" measures and to report certain breaches to the authority. No insurance relieves you of that responsibility.
Steps to set up this week
You need no budget and no IT specialist to move forward. Three concrete steps, well within reach of Dr Anne P. and Lucie F.
1. Pull out the contract and read the exclusions
Open the policy — or ask your broker for it — and find three things: the cap, the deductible, and the list of exclusions and conditions. Note the sentences that start with "provided that" or "subject to": those are your obligations. If a clause requires two-factor authentication or backups, it binds you. A broker isn't there only to sell: they can explain, in plain language, what you actually signed.
2. Tick the baseline prerequisites
Use the insurer's questionnaire as a checklist. Switch on two-factor authentication (MFA) for the mailboxes and for access to the patient record: on top of the password, a second proof, for example a code on your phone. Check that a recent backup exists and that someone knows how to restore it — a backup that has never been tested is a backup you merely hope for. Install the pending updates on the front-desk computers. Those three steps cover most of what the insurer looks at.
3. Keep a record
On the day of a claim, the insurer will ask for evidence: who had access to what, when the backup was tested, when a given patch was applied. Open a simple shared document and jot down, as you go, the measures in place and their dates. That written memory is worth its weight in gold at claim time — and it also reassures a patient or an authority who might have questions.
Where do you really stand?
Cyber-insurance isn't decided in a vacuum: you negotiate it far better when you know your own posture. Knowing where your practice is solid and where it rests on trust is precisely what lets you answer the insurer's questionnaire honestly — and secure better cover at the right price.
That's where the Cyber Passport self-assessment comes in. It certifies nothing and sells no policy: question by question, it shows you the real state of your measures against recognised good practice and the expectations of the nFADP. Enough to approach your next cyber-insurance renewal with your eyes open, and no nasty surprise on the day it counts.



