SOC and cyber insurance: what Swiss insurers require
Cyber insurers in Switzerland and the EU increasingly require applicants to evidence security controls. MFA, EDR, segregated backups, a documented incident response plan and a patch process appear on nearly every proposal form. Missing 24/7 detection via a managed SOC or MDR is rarely a formal exclusion. It is a strong premium driver and, in many policies, the only realistic way to meet short policy notification deadlines.
How this compares to neighbouring topics
This page treats cyber insurance as a control requirement. SOC and ISG notification and SOC and FINMA cover federal regulatory notification duties separately. SOC ROI covers the full economics, including the premium effect. What is a SOC explains what a SOC does.
This summary draws on publicly available policy wordings, market analyses and broker publications from 2024-2026. Active carriers in the Swiss market include Zurich, AXA, Baloise, Helvetia, Allianz and Chubb. These requirements reflect common practice and vary by policy. Only your specific contract is binding.
What insurers require in practically every case
These five controls appear on nearly every proposal form. If they are missing, insurers decline the application, impose specific exclusions or offer cover at an uneconomical premium.
- MFA for all privileged accounts and remote access
- EDR on every endpoint (no plain AV)
- Segregated or immutable backups with documented restore tests
- Patch process for critical vulnerabilities within a few days
- Documented incident response plan with named roles
What appears on most SME proposal forms
Insurers sometimes treat missing controls as formal grounds for exclusion. Their absence typically leads to a surcharge, higher excess or sub-limits. 24/7 detection is the point at which a managed SOC or MDR enters the picture, because internal SME teams cannot deliver it alone.
- 24/7 detection (managed SOC, MDR or equivalent) with evidence of human analysts in the loop
- PAM or equivalent control of privileged access
- Email filtering with anti-phishing and attachment sandboxing
- Regular security awareness training with phishing simulations
- No unpatched end-of-life systems in the production network
The 72-hour notification deadline and why it needs a SOC
Many Swiss and EU policies set short notification deadlines from awareness of a reportable event, commonly 72 hours. Your own policy is what counts. Late notification regularly leads to reductions or denial for breach of duty. Without 24/7 detection, the clock effectively starts Monday morning even though the attack happened Friday evening. A managed SOC compresses signal-to-awareness from days to hours and makes meeting the deadline realistic in the first place.
Warranties: whatever you tick, you must uphold
Proposal forms typically contain warranties or affirmations about MFA, EDR, patch process and backup regime. If you cannot demonstrate these controls during a claim, the insurer reduces or denies the payout. That applies even when the control existed at application and simply eroded in day-to-day operations.
The applicant ticks 'yes' for MFA on the form while excluding service accounts and legacy VPN access in practice. Attackers exploit that exception, and the insurer denies cover.
The specific role a SOC plays in the insurance context
- Evidence: continuous proof that controls work in practice.
- Time: detection and awareness within the 72-hour notification deadline, including outside office hours.
- Forensics: structured log collection and timeline that the insurer requires in a claim.
- Loss magnitude: documented fast response reduces downtime and thus claim size, which improves renewals.
Checklist before application or renewal
- Check MFA coverage: every privileged and remote access including service accounts and legacy VPN.
- Check EDR coverage: no grey endpoints, no unmanaged exceptions.
- Documented restore test from the last twelve months available on request.
- 24/7 detection: confirm who starts the notification clock at night, weekends and public holidays.
- Incident response plan: named roles, contact chains, insurer hotline anchored in the plan.
- Read warranties word by word and reconcile with internal reality before signing.
Placement in SOC operations
SOC as a Service Switzerland describes the operating model that meets insurance requirements.
Legal basis and sources
- FINMA Guidance 05/2020 on reporting cyber attacks (Art. 29 para. 2 FINMASA): finma.ch
- FINMA Guidance 03/2024 refining the reporting duty: finma.ch
- ISG (SR 128), Art. 74a-74f: Fedlex
- ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
- Reporting data security breaches to the FDPIC: edoeb.admin.ch
- Cybersecurity Ordinance (CSV, SR 128.51): Fedlex
Frequently asked questions
Is a SOC formally mandatory for cyber insurance?
Most standard policies have no formal SOC requirement. In practice, SMEs can rarely demonstrate the required 24/7 detection without a managed SOC or MDR. For larger or regulated organisations, a managed SOC is now an explicit item on many proposal forms.
How much does a SOC affect the premium?
Documented controls can visibly reduce premiums, with some carriers offering explicit MDR discount programmes. The figure depends on insurer and segment. The larger economic effect often lies in avoided sub-limits and exclusions rather than headline discount.
Is MDR sufficient instead of a managed SOC?
For most SME policies: yes, provided the MDR provider evidences 24/7 detection, documented response and forensic access. For the detailed difference see [What is MDR](/en/soc/what-is-mdr) and [SOC vs. MDR](/en/soc/soc-siem-edr-xdr-mdr-terms).
What happens if we miss the 72-hour deadline?
Insurers invoke breach of duty and reduce or deny cover. What counts is the time of awareness within the organisation, not the time IT leadership is informed. Without 24/7 detection, that time for a weekend attack is effectively Monday morning.
Why exactly 72 hours and not 24 or 48?
Deadlines of 72 hours are common. Individual contracts set shorter or longer periods. The specific contract is always the binding source.
Related terms
- Ransomware Ransomware is malicious software that encrypts data and demands a ransom for decryption.
- Incident Response Incident Response is the structured process of containing, eradicating, and recovering from a security incident.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- Playbook A playbook is a predefined procedure describing how a SOC responds to a specific type of security incident.