Cet article est disponible uniquement en anglais.
Swiss Cyber Threat Landscape: The Gap Between Attack Frequency and Board Awareness Is Widening
Check Point recorded an average of 1,515 weekly cyberattacks per organisation in Switzerland in August 2026, a 36 percent increase year on year. Switzerland still fares better than its German-speaking neighbours: Germany recorded 1,834 attacks (+53 percent) and Austria 2,468 (+41 percent). Public administration remains the most affected sector, followed by consumer goods and services, then healthcare. (Check Point)
Published the same day, a separate survey found that Swiss boards lack cyber expertise. Read together, the two reports describe a widening distance between how often organisations are attacked and how well the people accountable for that risk understand it.
Two developments deserve more attention than the topline number. First, a shift in targeting logic: attackers are increasingly selecting targets based on ease of access rather than value of contents. This dismantles the persistent assumption among Swiss SMEs that being small means being uninteresting. Second, the emergence of Orova, a ransomware group that first appeared in May 2026, focuses specifically on SMEs within certain industries, and had already climbed to third place among the most active groups by August. Phishing remains the primary route in, with roughly one in every 112 emails classified as phishing, increasingly relying on time pressure and emotional triggers rather than links alone.
An organisation can absorb a knowledge gap at board level when incidents are rare. At 1,515 weekly attacks, with groups deliberately targeting companies of this size, that tolerance disappears. The practical consequence is not that directors need technical training. It is that they need to be able to ask the right questions: can the organisation continue operating during an incident, who decides on an extortion demand, and what are the reporting obligations. Under NIS2 and DORA, both of which reach Swiss firms through EU-facing business and supply chains, management accountability for cyber risk is explicit rather than implied. A board that cannot describe its own exposure has a governance problem, not an IT problem.
A practical readiness approach starts with reviewing the attack surface: what is reachable from the internet with valid credentials and no exploit required — remote access portals, VPN endpoints, webmail, administrative interfaces. Multi-factor authentication on every one of these is the single highest-value control available to a smaller organisation. Since phishing increasingly relies on urgency rather than obvious technical tells, verification discipline through a pre-agreed, out-of-band channel matters for payment instructions, changes to bank details, and credential requests.
On governance, three questions belong on the next board agenda, with answers recorded: how long could we operate without our core systems, who decides whether to pay, and what must we report and to whom. If these cannot be answered in the meeting, that is the finding. If IT is outsourced, ask the provider which of these controls are actually in place rather than merely available, and when backup restoration was last tested end to end.
Key message: Attacks on Swiss organisations rose 36 percent year on year, ransomware roughly doubled globally, and a new group is specifically targeting SMEs by sector. Attackers are selecting targets by ease of access rather than value, removing the protection smaller firms believed their size provided. Close the easy entry points first, enforce out-of-band verification for anything involving money or credentials, and make sure the board can answer three basic questions before an incident forces them to.