Skip to main content
Datia
Contact us
CloudCybersecurity

IT Security for SMEs: What Cyber Insurers Expect Today

3 min read

What cyber insurers require from Swiss SMEs, which protective measures really matter, and how to secure your IT step by step – a guide from Datia.

Illustration of IT operations and security processes

“We’re too small to be a target” – we hear this sentence again and again in conversations with SMEs. The reality looks different: ransomware attacks today predominantly hit small and medium-sized businesses, because that is where the barriers are lowest. For an SME, an encrypted server quickly means several days of standstill – and that is exactly why cyber insurers now set concrete technical requirements before they issue a policy at all.

In this post we show which measures insurers typically require, why that list doubles as a solid security roadmap, and how Datia helps companies in the Lenzburg region and across Aargau put them into practice.

Why the insurance question is a good opportunity

Many SMEs only engage with IT security when a customer, an auditor or indeed an insurer asks about it. That is nothing to be ashamed of – it is an opportunity. At their core, insurers’ requirement catalogues are a distilled list of the measures proven to prevent or limit real damage. Companies that implement them are not just insurable – they are genuinely better protected.

Then there is the legal framework: the revised Swiss Data Protection Act (revFADP) obliges companies to protect personal data through appropriate technical and organisational measures. And since April 2025, operators of critical infrastructure in Switzerland have been required to report cyberattacks to the Federal Office for Cybersecurity (NCSC). Even companies not subject to that reporting duty are well advised to take the NCSC’s recommendations as their benchmark.

The typical minimum requirements

The details vary from insurer to insurer, but these points come up practically every time:

  1. Multi-factor authentication (MFA): for e-mail, remote access (VPN), administrator accounts and cloud services. The single most effective protection against stolen passwords – and the most common gap in SMEs.
  2. Tested, separated backups: backups that are isolated from the network or stored immutably (offline or immutable), and – crucially – regular restore tests. A backup that has never been restored is wishful thinking.
  3. Timely patch management: security updates for operating systems and applications within defined deadlines. Outdated systems that have fallen out of support are a red flag for insurers.
  4. Endpoint protection (EDR): modern protection on laptops and servers that detects and stops attacks – not just classic antivirus.
  5. An access rights concept: administrator privileges only where they are needed. Anyone reading e-mail with an admin account turns every phishing click into a total loss.
  6. Employee awareness: regular, short training sessions on phishing and handling data. Most successful attacks start with an e-mail, not with high technology.
  7. An incident response plan: Who gets informed, who decides, how do we communicate when the systems are down? A one-page document that makes the difference when it counts.

Where the cloud helps – and where it doesn’t

A modern cloud workplace meets many of these requirements almost as a by-product: MFA is standard, updates arrive automatically, data is stored redundantly in Swiss data centres, and access is logged centrally. For many SMEs, migrating to the cloud is therefore also a security project – we have described the steps in our guide to cloud migration.

But: the cloud does not take the responsibility off your shoulders. Access rights, backup strategy, training and the incident response plan remain your job – no matter where the servers are.

How to approach it pragmatically

Our advice to SMEs: treat the list above as an order of priority, not a wish list.

  1. Weeks 1–2: enable MFA everywhere, separate admin accounts. Costs little, delivers the most.
  2. Month 1: review the backup concept and run a real restore test.
  3. Months 2–3: define a patch process, identify legacy systems, roll out EDR.
  4. Ongoing: short training sessions, an annual review of the incident response plan.

With this in place you will not only pass most insurers’ questionnaires – you will have genuinely defused the most likely damage scenarios.

A partner close by

IT security is not a product you buy once, but a state you maintain. Datia is based in Lenzburg and serves companies around Aarau, Baden, Zofingen and across Aargau – from the initial assessment through implementation to ongoing operations. Short distances mean one thing here: when something happens, we are reachable.

Want to know where your company stands today? Book a free initial consultation – we will go through the points together, clearly and without alarmism.

Not sure where to start?

Tell us what you need across Web, Cloud, Data or AI. The first call is free and without obligation. You'll talk directly to the engineer who'd do the work.

Related Articles