Skip to content
Lambert Consulting

Our first department

This is what needs to work every morning.

Your servers, your workstations, your phone systems, and your identities. The foundation that no one notices as long as it holds, but that everyone notices the day it fails.

View the department
Multi-siteNational and international projects
3Branches in French-speaking Switzerland
View our client projectsCase Studies and References
Let us know how you're doingGetting a quote is free

How We Work

A piece of advice, not a sales pitch.

Our approach is consultative: we tell you what we think, even when it’s not in our best interest. That’s what makes projects succeed.

About Us
1995First project, using Microsoft SMS
Family-orientedOn a human scale and sustainable

Our Branches

Vaud, headquarters9 Avenue des Baumettes, 1020 Renens+41 21 806 37 15
Valais134 Oscar-Bider Street, 1950 Sion+41 27 552 00 22
FribourgChemin de Montmoirin 18a, 1618 Châtel-Saint-Denis+41 26 322 59 05
Monday through Friday8:00 a.m. – 6:00 p.m.
Contact UsFirst 30-minute consultation, with no obligation

Cyber Insurance Questionnaire: Measures an SME Agrees to Follow

The application form for Helvetia’s Special SME Cyber Insurance, dated July 1, 2026, poses the question in a single line: “Do you comply with the requirements?” followed by “(See our cybersecurity brochure, pages 4 and 5).” The form offers two checkboxes: Yes and No. The list of requirements can be found in the brochure, spanning two pages.

Publication Date
13 minReading time
Identity and SecurityBlog Archive

At La Mobilière, the obligations are set forth in the General Terms and Conditions for Cyber Insurance, Edition 01.2024: one section lists five of them, beginning with “Under the cyber insurance policy, you are required to take the following measures.”

These two insurers operating in Switzerland therefore publish their lists, and these provisions are contractual obligations. Both contracts specify the consequences if these obligations are not met. An executive who fills out a cyber insurance questionnaire—whether at the time of underwriting or renewal—is therefore answering questions whose implications are outlined elsewhere, not just on the form itself.

Where is the list you're signing?

In Helvetia’s brochure, the company explains the basis for these measures: Helvetia states that it developed them “in accordance with the recommendations of the Federal Office for Cybersecurity (FOICS) and in collaboration with various specialists in IT security and data protection.” Page 4 is titled “Organizational and Technical Security Guidelines,” which is divided into three organizational measures followed by six technical measures. Page 5 adds four points: the gateway between the IT system and the system that controls the machines, the website’s data protection statement, external service providers, and periodic audits.

The same list appears in Helvetia’s general terms and conditions under the heading “Organizational and Technical Safety Rules,” introduced by the phrase “In addition, the following minimum loss prevention requirements must be met.” The brochure specifies that these minimum requirements apply “depending on the size and nature of your business.” The brochure is intended to help you prepare your response; the contract constitutes the commitment.

At La Mobilière, the five obligations are summarized on a single page of the general terms and conditions, and the contract adds a broader obligation: “You have a duty of care. This means that you must protect the insured data by taking all necessary measures.”

Access Management and the Role of Multifactor Authentication

Three of Helvetia’s measures concern access. The first calls for the “definition and implementation of an authorization management system with different levels of authority,” citing, for example, role-based access to financial, personal, or customer data. The second calls for the “definition and implementation of an access policy (Access Policy).” The third, classified as a technical measure, calls for the “technical implementation of the defined access policy and authorization management.”

Multifactor authentication is not mentioned as such in any of these three lines. It appears in Helvetia’s definition of “Access Policy” in the glossary of its general terms and conditions: the access policy “includes both traditional password policies and alternative authentication methods such as multifactor authentication (MFA)”, and these guidelines “must be implemented at all levels of the organization.”

As for Mobilière, the fourth requirement stipulates that security measures must “always comply with the latest state of the art and the manufacturer’s recommendations, particularly with regard to passwords, system configurations, and firewalls.” The contract therefore refers to the manufacturer’s recommendations. For an environment Microsoft 365, this recommendation is explicitly stated: Microsoft recommends requiring multi-factor authentication for all users, and especially for administrators.

Regarding permissions, Microsoft recommends using roles with the fewest possible permissions and limiting the number of users who have them, particularly for the Global Administrator role, whose holders, as Microsoft notes, have nearly unlimited access to the organization’s settings and most of its data. To determine how these roles are distributed between you and your service providers, check who owns your tenant at Microsoft 365.

A Microsoft report Entra ID provides the number of users capable of multi-factor authentication—that is, those who are both enrolled in a strong authentication method and authorized by policy to use it: this is the figure you should request. Microsoft itself notes the limitation of this figure: it does not reflect users enrolled in multi-factor authentication outside of Microsoft Entra ID. Accessing this report requires a Microsoft Entra ID P1 or P2 license.

Backup and the semi-annual verification required by Helvetia

Both contracts require a backup, but they do not require the same one.

MeasurementHelvetiaLa Mobilière
Backup Frequencydaily, with automatic operation monitoringFull backup, at least once a week
Copy Out of Reachstored in such a way that it cannot be tampered with, damaged, destroyed, or stolen along with the original data—for example, offline or in a tamper-proof formatstored off-site, at a sufficient distance from the original location

Helvetia adds three requirements that are not included in the table. The backup “cannot be overwritten for at least one week.” “The quality of the data backup must be verified at least every 6 months,” for example by comparing data volumes and verifying functionality through sampling. And “access to either the original data or the backup data must be guaranteed at all times.” Therefore, a backup that completes without errors every night is not sufficient to meet this requirement.

For data hosted in Microsoft 365, Microsoft 365 Backup covers the sites SharePoint, accounts OneDrive , and mailboxes Exchange, with a configurable recovery window of three months, six months, one year, or two years, and pay-as-you-go billing rather than per-user licensing. The immutability has a limit. Storage operates on an append-only basis: the service adds restore points without ever modifying existing ones. However, the tool’s administrator can delete them upon leaving the service, and a fixed 90-day grace period then allows them to be recovered. Find out who holds this role at your organization.

Patches, and systems for which no patches are available

Both contracts specify a deadline for installing security patches. At Helvetia, this deadline is thirty days, “unless more time is needed to ensure the patches’ compatibility,” and the contract includes a provision for cases where no patch is available: “Software/systems for which security patches or updates are not available must be isolated.” At La Mobilière, the deadline is thirty days for a moderate or high vulnerability, and fourteen days for a critical vulnerability.

This approach doesn’t work on screen. You must first take inventory of your software and hardware, then compare that inventory to the end-of-support dates published by each vendor. For Microsoft, these dates are public and centralized on the product lifecycle pages. Microsoft states there that older products may not meet current security requirements and that it may be unable to provide security updates for them. For products subject to the Fixed Lifecycle Policy, the same page indicates that security updates remain available beyond the end of support through the Extended Security Updates program. The Fixed Lifecycle Policy does not cover all products, and Microsoft notes that each product’s lifecycle page lists its specific dates.

La Mobilière adds a requirement to conduct an analysis: in the event of a critical vulnerability, the affected systems must also be analyzed to determine whether they have been exposed to malware, the necessary measures must be implemented, and the insurer must be notified as soon as possible if exposure is confirmed.

Training, Service Providers, and Periodic Inspections

Helvetia’s third organizational measure calls for “regular awareness-raising and security training for policyholders regarding cyber risks.” The brochure goes on to note that Helvetia offers free security training on its website for the employees of its policyholders.

Regarding third parties, page 5 lists three requirements. When third parties—such as suppliers—have access to your IT system and digital data, or when you work with external service providers on digital data, you must first ensure that they comply with data protection laws and other applicable guidelines. Second, “you must have a written assurance from your business partners.” Finally, when using services cloud critical to the business, you must ensure that the external service providers delivering them have a contingency plan and a business continuity plan in place. Helvetia defines these critical services as those cloud used for core business processes and whose availability accounts for more than 30% of annual revenue or operating income.

The last point on page 5 concerns duration: “All security measures must be reviewed periodically. It is essential that both technology and organizational measures remain up to date at all times.”

The company’s own incident response plan does not appear on either of these two lists. Instead, the contracts specify obligations that must be met on the day of the incident. La Mobilière lists several of these: immediately notify the insurer and request coverage for expenses; engage a specialized company or grant access to the one the insurer has engaged; and secure the affected hardware, software, and data to make them available for as long as necessary.

What happens if an answer is incorrect?

These two situations are addressed separately: Mobilière devotes an article to inaccurate disclosures made at the time of application, while the two contracts address breaches of obligation that occur during the term of the contract.

An inaccurate statement. The Swiss Reinsurance Company’s terms and conditions use the term “concealment”: “We may terminate the insurance contract if you have committed concealment. This is the case if you have failed to disclose or have inaccurately disclosed a material fact in the insurance application.” ” The same article specifies the effect on claims that have already occurred: termination ends the insurer’s obligation to pay benefits “to the extent that the material fact that was the subject of the non-disclosure influenced the occurrence or extent of the loss,” and any benefits already received must be repaid. The insurer has four weeks to terminate the policy from the time it becomes aware of the omission.

A breach of obligation. Here, both contracts describe a proportional reduction, not a loss of coverage. Mobilière states that in the event of a culpable breach, the benefit is reduced “to the same extent that your actions influenced the occurrence or extent of the loss,” and that there is no reduction in the absence of fault. Helvetia similarly states that the indemnity is reduced “to the extent that the occurrence or extent of the loss was influenced,” and that the insurer is not released from its obligations if the breach cannot be considered willful, or if the policyholder proves that it had no influence “either on the occurrence of the loss or on the extent of the benefits owed by the insurance company.” Both parts of this second condition must be proven together.

There is a third scenario: an accurate answer may no longer be accurate. Both contracts require immediate notification of any change in a fact that is material to the assessment of risk, and Helvetia specifies that all facts about which it requested information in the application form are considered material. An answer provided during a previous application therefore remains binding, and a change in device, provider, or organization renders it no longer accurate.

Our Reading

A cyber insurance questionnaire arrives with a deadline; it’s just one page long, and it looks like a piece of paperwork. The list is in the document referenced by the form, not on the form itself. If you go through the inventory line by line before filling out the form, you’ll have a written description of the facts for each box—and that’s the order we’ll follow: first the referenced document, then the inventory, and finally the form.

On the merits, we’ll be blunt: checking “yes” without verifying the facts serves no purpose. Both contracts limit the amount of coverage based on the actual impact of the violation on the claim, and one of them includes a grounds for termination due to an inaccurate statement. Checking a box without due consideration therefore does not improve coverage; it simply adds a point of contention when it comes time to pay the claim.

What determines the response is the extent of the gap. If the assessment reveals one or two areas that need to be brought up to standard, it’s a project that takes a few weeks and is handled internally with the usual service provider, as part of an IT outsourcing contract if one exists. If the inventory shows that none of the measures are in place, the questionnaire is no longer the issue: the upgrade becomes a project in its own right, with its own budget and timeline, and insurance comes afterward.

The scope of a claim is determined by your insurer or your broker—and them alone. An IT service provider can establish the facts—which accounts, which backups, which unpatched systems—and those facts are what you need to formulate your response. They cannot tell you what the insurer will do with your response, and a response based on an ad hoc interpretation of the contract carries the same risk of being inaccurate.

What You Can Check Today

  1. Find the document referenced in your questionnaire and read it in its entirety. At Helvetia, it’s the cybersecurity brochure, pages 4 and 5. At La Mobilière, it’s the section on obligations in the general terms and conditions. For other insurers, the question on the form will tell you where to look.
  2. Log in to your work email from a device you never use and see if you're prompted for two-factor authentication. This test takes two minutes and doesn't require any special permissions.
  3. Request a list of accounts that have an administrative role, and a list of accounts exempt from multi-factor authentication. An exemption is not unusual; not knowing which ones exist is.
  4. Ask for the date of the last quality check of your backups and a written report of the results. This is not the same as the date of the last successful backup.
  5. Ask where the copy of your data is located that would not be affected by a cyberattack on your systems, and who has the authority to delete it.
  6. Request a list of software and hardware for which the vendor no longer releases security patches.
  7. Review the answers you provided in the previous contract. If any of them are no longer true, both contracts require you to report this.

The second point can be handled on your own. The other six can be addressed in a single message to the person who manages your IT systems, and the expected responses are documents.

Sources

After reading

What an article Can't Know

An article describes what applies to everyone. What varies from one organization to another is the inventory: which applications, which accounts, and which pieces of equipment are actually involved in your organization. The inventory determines the scope of the effort, and it cannot be summarized on a single page.

You'll be speaking directly with the engineers who will be doing the work, not with a middleman. We'll respond within 24 business hours.

If the topic has changed

Check what is still true

Announced dates are sometimes postponed, products are renamed, and conditions change. The blog tracks these topics over time: when a rule changes, a new post announces it.

Search for a topic in the blog