What the latest Swiss figures show
No single figure describes the cyber threat landscape. Reports to the Federal Office for Cybersecurity (BACS), police-recorded offences and insurance claims measure different events and must not be added together.
| Indicator | Confirmed figure | Context |
|---|---|---|
| Voluntary reports to BACS in 2025 | 64,733 | Reports from individuals and organisations; not automatically confirmed attacks |
| Offences involving a digital method in 2025 | 57,761 | Police Crime Statistics from the Federal Statistical Office |
| Recorded phishing cases in 2025 | 7,409 | Up from 5,930 in 2024, an increase of 24.9% |
| Mandatory reports from 1 April to the end of 2025 | 325 | Only within the reporting regime for critical infrastructure |
These figures demonstrate a sustained burden. They do not establish the probability or likely cost of an incident for a particular business.
Five relevant attack patterns
1. Phishing and stolen credentials
Fraudulent emails, messages, login pages and phone calls seek credentials, approvals or payments. Useful controls include:
- multi-factor authentication for email, remote access and administrator accounts
- independent confirmation of changed bank details through a known channel
- a simple internal route for reporting suspicious messages
- targeted revocation of sessions and credentials after a suspected compromise
2. Ransomware and extortion
Ransomware can encrypt systems, steal data, or do both. A tested recovery process matters more than merely having a backup:
- keep separated or immutable backups
- test restoration regularly
- restrict administrative privileges
- segment systems and patch exposed services promptly
- define incident-response roles and external contacts in advance
Paying a demand does not guarantee recovery or deletion of stolen data. Any decision requires legal, forensic and, where appropriate, law-enforcement assessment.
3. Payment fraud and business email compromise
Attackers impersonate executives, suppliers or employees, or take over their email accounts. New beneficiaries, changed payment instructions and urgent exceptions should be verified through a known contact and a second approval.
4. Vulnerable systems and supply chains
An incident can originate in the organisation’s own systems, software, cloud services or IT providers. Businesses should identify critical dependencies, monitor security notices and agree who informs whom and who can act during an incident.
5. Denial of service and operational outages
DDoS attacks target availability. Technical failures at service providers can also interrupt operations without being cyber attacks. Resilience planning should cover capacity, alternatives, recovery and communication.
Practical priorities for businesses
- Map critical processes: identify essential systems, data and service providers.
- Secure identities and privileges: prioritise email, remote access, cloud administration and backups.
- Prioritise patches: address internet-facing and actively exploited vulnerabilities first.
- Test backups: measure recovery time and data loss with a realistic scenario.
- Harden payment processes: verify account changes and unusual payments independently.
- Exercise the response plan: practise decisions, contacts, evidence preservation, communications and notifications.
- Include suppliers: agree access, incident notification and recovery arrangements with critical partners.
Reporting duties after an incident
Different incidents trigger different duties:
- Under Article 24 FADP, a controller must notify the FDPIC as quickly as possible where a data security breach is likely to result in a high risk to the personality or fundamental rights of affected persons. Swiss law does not set a fixed 72-hour deadline.
- Since 1 April 2025, covered operators of critical infrastructure must report certain cyber attacks to BACS within 24 hours of discovery. Missing information can generally be supplied later.
- Sector-specific requirements may also apply. Filing a criminal complaint can be useful, but it is not a universal legal duty after every cyber attack.
What cyber insurance may contribute
Depending on the policy, insured services may include IT forensics, legal advice, data and system restoration, crisis communication, business interruption or liability claims. This is not a blanket coverage promise: triggers, definitions, exclusions, sublimits, deductibles, waiting periods and application statements all matter.
Payment fraud, extortion, cloud outages and incidents at IT providers require particular scrutiny. Cyber insurance complements technical and organisational controls; it does not replace them.