Cyber Risk Becomes a Top Priority

The attack rarely begins in the server room. It arrives in the inbox as a credible email, comes in the form of a phone call from a purported executive, or is disguised as a modified payment order. Swiss SMEs frequently experience cyber incidents, yet they assess their own risk as surprisingly low. This gap between experience and perception becomes a vulnerability.

August 2026

49 percent of employees surveyed at Swiss SMEs report having experienced a serious cyber incident at their workplace in the past three months. Nevertheless, only 22 percent rate their company’s cyber risk as high. Among micro-enterprises with one to nine employees, the discrepancy is particularly wide. Thirty-eight percent report incidents, yet only 15 percent perceive a high risk.

This is alarming. Cybercrime today hardly targets big names anymore. Attacks are automated, scalable, and targeted. A small business can suffer direct harm through compromised login credentials, invoices, or payment processes. At the same time, it can become a gateway into supply chains and customer networks.

Basic protection remains inadequate
Phishing is the most frequently perceived threat, at 25 percent. It affects companies of all sizes with nearly equal frequency. This is followed by, among other things, malware, CEO fraud, identity theft, potential data breaches, and operational disruptions.

The new Deloitte SME Cybersecurity Index scores 58 out of 100 points. It measures six basic employee-related measures. On average, these protective measures are thus implemented at only 58 percent.

Authentication stands out in particular. Sixty-six percent of companies use multi-factor authentication. Passwordless methods and single sign-on each account for 45 percent. Among micro-enterprises, the index scores only 44 points. Regular training is implemented by 32 percent of these companies, and phishing tests by 24 percent. For medium-sized companies, these figures stand at 82 percent and 63 percent, respectively.

Insurance Is No Substitute for Precautionary Measures
Cyber insurance is gaining importance, but its adoption remains low. In 2025, there were approximately 72,000 corporate policies in Switzerland. This corresponds to 11.5 percent of companies domiciled here. Micro and small businesses in particular often remain uninsured, even though a loss can hit them particularly hard relative to their revenue.

A policy alone is hardly enough to solve the problem anyway. Insurers are increasingly demanding verifiable minimum standards. Without access rules, tested backups, or a defined emergency response process, the foundation for effective coverage is often already missing.

Resilience Is a Management Responsibility
Cybersecurity belongs on the executive management’s agenda. A few consistently implemented fundamentals are crucial. Strong authentication, restrictive access rights, short, regular training sessions, tested backups, and a clear emergency plan increase the ability to respond effectively in the event of a crisis.

It’s about much more than just IT. Cyber resilience protects operations from outages, safeguards payment processes, and ensures trust among customers and partners.

More articles