SOC and cyber insurance: what Swiss insurers require

Cyber insurers in Switzerland and the EU increasingly require applicants to evidence security controls. MFA, EDR, segregated backups, a documented incident response plan and a patch process appear on nearly every proposal form. Missing 24/7 detection via a managed SOC or MDR is rarely a formal exclusion. It is a strong premium driver and, in many policies, the only realistic way to meet short policy notification deadlines.

All

How this compares to neighbouring topics

This page treats cyber insurance as a control requirement. SOC and ISG notification and SOC and FINMA cover federal regulatory notification duties separately. SOC ROI covers the full economics, including the premium effect. What is a SOC explains what a SOC does.

On sources

This summary draws on publicly available policy wordings, market analyses and broker publications from 2024-2026. Active carriers in the Swiss market include Zurich, AXA, Baloise, Helvetia, Allianz and Chubb. These requirements reflect common practice and vary by policy. Only your specific contract is binding.

What insurers require in practically every case

These five controls appear on nearly every proposal form. If they are missing, insurers decline the application, impose specific exclusions or offer cover at an uneconomical premium.

  • MFA for all privileged accounts and remote access
  • EDR on every endpoint (no plain AV)
  • Segregated or immutable backups with documented restore tests
  • Patch process for critical vulnerabilities within a few days
  • Documented incident response plan with named roles

What appears on most SME proposal forms

Insurers sometimes treat missing controls as formal grounds for exclusion. Their absence typically leads to a surcharge, higher excess or sub-limits. 24/7 detection is the point at which a managed SOC or MDR enters the picture, because internal SME teams cannot deliver it alone.

  • 24/7 detection (managed SOC, MDR or equivalent) with evidence of human analysts in the loop
  • PAM or equivalent control of privileged access
  • Email filtering with anti-phishing and attachment sandboxing
  • Regular security awareness training with phishing simulations
  • No unpatched end-of-life systems in the production network

What improves premiums and cover but is rarely mandatory

  • Log retention of at least 12 months with forensic access
  • Network segmentation between client, server and OT zones
  • Annual tabletop or crisis exercise with executive leadership
What the market shows

International market analyses and insurer programmes show: documented controls can visibly reduce premiums, and individual carriers run explicit MDR discount programmes. The exact figure depends on insurer and segment.

The 72-hour notification deadline and why it needs a SOC

Many Swiss and EU policies set short notification deadlines from awareness of a reportable event, commonly 72 hours. Your own policy is what counts. Late notification regularly leads to reductions or denial for breach of duty. Without 24/7 detection, the clock effectively starts Monday morning even though the attack happened Friday evening. A managed SOC compresses signal-to-awareness from days to hours and makes meeting the deadline realistic in the first place.

Warranties: whatever you tick, you must uphold

Proposal forms typically contain warranties or affirmations about MFA, EDR, patch process and backup regime. If you cannot demonstrate these controls during a claim, the insurer reduces or denies the payout. That applies even when the control existed at application and simply eroded in day-to-day operations.

The expensive default mistake

The applicant ticks 'yes' for MFA on the form while excluding service accounts and legacy VPN access in practice. Attackers exploit that exception, and the insurer denies cover.

The specific role a SOC plays in the insurance context

  • Evidence: continuous proof that controls work in practice.
  • Time: detection and awareness within the 72-hour notification deadline, including outside office hours.
  • Forensics: structured log collection and timeline that the insurer requires in a claim.
  • Loss magnitude: documented fast response reduces downtime and thus claim size, which improves renewals.

Checklist before application or renewal

  1. Check MFA coverage: every privileged and remote access including service accounts and legacy VPN.
  2. Check EDR coverage: no grey endpoints, no unmanaged exceptions.
  3. Documented restore test from the last twelve months available on request.
  4. 24/7 detection: confirm who starts the notification clock at night, weekends and public holidays.
  5. Incident response plan: named roles, contact chains, insurer hotline anchored in the plan.
  6. Read warranties word by word and reconcile with internal reality before signing.

Legal basis and sources

  • FINMA Guidance 05/2020 on reporting cyber attacks (Art. 29 para. 2 FINMASA): finma.ch
  • FINMA Guidance 03/2024 refining the reporting duty: finma.ch
  • ISG (SR 128), Art. 74a-74f: Fedlex
  • ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
  • Reporting data security breaches to the FDPIC: edoeb.admin.ch
  • Cybersecurity Ordinance (CSV, SR 128.51): Fedlex

Frequently asked questions

Is a SOC formally mandatory for cyber insurance?

Most standard policies have no formal SOC requirement. In practice, SMEs can rarely demonstrate the required 24/7 detection without a managed SOC or MDR. For larger or regulated organisations, a managed SOC is now an explicit item on many proposal forms.

How much does a SOC affect the premium?

Documented controls can visibly reduce premiums, with some carriers offering explicit MDR discount programmes. The figure depends on insurer and segment. The larger economic effect often lies in avoided sub-limits and exclusions rather than headline discount.

Is MDR sufficient instead of a managed SOC?

For most SME policies: yes, provided the MDR provider evidences 24/7 detection, documented response and forensic access. For the detailed difference see [What is MDR](/en/soc/what-is-mdr) and [SOC vs. MDR](/en/soc/soc-siem-edr-xdr-mdr-terms).

What happens if we miss the 72-hour deadline?

Insurers invoke breach of duty and reduce or deny cover. What counts is the time of awareness within the organisation, not the time IT leadership is informed. Without 24/7 detection, that time for a weekend attack is effectively Monday morning.

Why exactly 72 hours and not 24 or 48?

Deadlines of 72 hours are common. Individual contracts set shorter or longer periods. The specific contract is always the binding source.

Continue reading in this cluster
SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland
Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.
SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisor
FINMA requires supervised institutions to document detection and response capabilities and demonstrate operational resilience. Institutions must report material cyber incidents within 24 hours of assessment. FINMA Circular 2023/1 Operational Risks and Resilience is the authoritative reference. It has been in force since 1 Jan 2024 and replaced Circular 2008/21. A SOC delivers 24/7 detection, a ticket and evidence trail and audit-ready evidence. Institutions need all three to meet the requirements reliably.
What a SOC costs: cost drivers, pricing models, in-house or service
SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.
What is a SOC? Definition, tasks and structure
A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.