cyberversicherung.ch

Cyber Threats in Switzerland 2026: Facts, Risks and Protection

Published: Updated: Reading time: 4 min

The short answer

The Swiss cyber threat landscape based on BACS and Federal Statistical Office data: phishing, ransomware, payment fraud and practical protection measures.

What the latest Swiss figures show

No single figure describes the cyber threat landscape. Reports to the Federal Office for Cybersecurity (BACS), police-recorded offences and insurance claims measure different events and must not be added together.

IndicatorConfirmed figureContext
Voluntary reports to BACS in 202564,733Reports from individuals and organisations; not automatically confirmed attacks
Offences involving a digital method in 202557,761Police Crime Statistics from the Federal Statistical Office
Recorded phishing cases in 20257,409Up from 5,930 in 2024, an increase of 24.9%
Mandatory reports from 1 April to the end of 2025325Only within the reporting regime for critical infrastructure

These figures demonstrate a sustained burden. They do not establish the probability or likely cost of an incident for a particular business.

Five relevant attack patterns

1. Phishing and stolen credentials

Fraudulent emails, messages, login pages and phone calls seek credentials, approvals or payments. Useful controls include:

  • multi-factor authentication for email, remote access and administrator accounts
  • independent confirmation of changed bank details through a known channel
  • a simple internal route for reporting suspicious messages
  • targeted revocation of sessions and credentials after a suspected compromise

2. Ransomware and extortion

Ransomware can encrypt systems, steal data, or do both. A tested recovery process matters more than merely having a backup:

  • keep separated or immutable backups
  • test restoration regularly
  • restrict administrative privileges
  • segment systems and patch exposed services promptly
  • define incident-response roles and external contacts in advance

Paying a demand does not guarantee recovery or deletion of stolen data. Any decision requires legal, forensic and, where appropriate, law-enforcement assessment.

3. Payment fraud and business email compromise

Attackers impersonate executives, suppliers or employees, or take over their email accounts. New beneficiaries, changed payment instructions and urgent exceptions should be verified through a known contact and a second approval.

4. Vulnerable systems and supply chains

An incident can originate in the organisation’s own systems, software, cloud services or IT providers. Businesses should identify critical dependencies, monitor security notices and agree who informs whom and who can act during an incident.

5. Denial of service and operational outages

DDoS attacks target availability. Technical failures at service providers can also interrupt operations without being cyber attacks. Resilience planning should cover capacity, alternatives, recovery and communication.

Practical priorities for businesses

  1. Map critical processes: identify essential systems, data and service providers.
  2. Secure identities and privileges: prioritise email, remote access, cloud administration and backups.
  3. Prioritise patches: address internet-facing and actively exploited vulnerabilities first.
  4. Test backups: measure recovery time and data loss with a realistic scenario.
  5. Harden payment processes: verify account changes and unusual payments independently.
  6. Exercise the response plan: practise decisions, contacts, evidence preservation, communications and notifications.
  7. Include suppliers: agree access, incident notification and recovery arrangements with critical partners.

Reporting duties after an incident

Different incidents trigger different duties:

  • Under Article 24 FADP, a controller must notify the FDPIC as quickly as possible where a data security breach is likely to result in a high risk to the personality or fundamental rights of affected persons. Swiss law does not set a fixed 72-hour deadline.
  • Since 1 April 2025, covered operators of critical infrastructure must report certain cyber attacks to BACS within 24 hours of discovery. Missing information can generally be supplied later.
  • Sector-specific requirements may also apply. Filing a criminal complaint can be useful, but it is not a universal legal duty after every cyber attack.

What cyber insurance may contribute

Depending on the policy, insured services may include IT forensics, legal advice, data and system restoration, crisis communication, business interruption or liability claims. This is not a blanket coverage promise: triggers, definitions, exclusions, sublimits, deductibles, waiting periods and application statements all matter.

Payment fraud, extortion, cloud outages and incidents at IT providers require particular scrutiny. Cyber insurance complements technical and organisational controls; it does not replace them.

Sources

BTAG Versicherungsbroker AG · Bern

Have questions about cyber insurance?

BTAG clarifies your risk profile and discloses any commission before conclusion. The request does not oblige you to buy.

Quote advice by BTAG Versicherungsbroker AG, Bern — FINMA-registered insurance intermediary.

Verified primary sources
Transparent compensation