Cybersecurity in SMEs: Threat Landscape and Government Support
Fact Check: The Cyber Situation in Switzerland

Cyberattacks Remain a Serious Threat to Switzerland
The cyber threat in Switzerland remains high. In the second half of 2025, the Federal Office for Cybersecurity (BACS) received 29,006 voluntary reports of cyber incidents. Additionally, there were 145 mandatory reported incidents from critical infrastructure sectors. BACS describes the overall reporting volume as "stable at a high level."
The latest semi-annual report from the Federal Office does not indicate a sharp increase in cyber incidents. However, the threat remains diverse: fraud, phishing, and ransomware continue to be among the primary dangers. Concurrently, BACS observes new attack methods and increasing exploitation of international software supply chains.
Fraud Remains the Most Frequent Phenomenon
At 52 percent, more than half of the voluntary reports concerned the phenomenon of "fraud." However, the composition within this category has changed. According to BACS, fraudulent calls made in the name of authorities, particularly frequent since mid-2023, significantly decreased.
Simultaneously, cybercriminals developed new methods. BACS observed, among others, "voice phishing" and "real-time phishing." In some cases, victims are directed to fake offers via fraudulent advertisements in search engines.
New variants also emerged, specifically tailored to Swiss characteristics. These included, for example, phishing attempts related to loyalty point programs. So-called "double phishing" was also observed, where attackers use an already successful phishing attack to deceive a victim a second time.
Ransomware Remains a Serious Threat
Extortion software also remains a relevant threat for Swiss organizations. In the second half of 2025, BACS received a total of 57 ransomware incidents, reported either voluntarily or due to mandatory reporting requirements.
BACS emphasizes that ransomware and associated data extortion continue to affect organizations of various types. The development of the "Akira" ransomware variant was particularly striking. Its activities had already played a significant role in the first half of 2025 and intensified further in the second half of the year.
SonicWall devices were a significant attack surface. BACS points out that the manufacturer's corrective instructions, following a vulnerability known since 2024, were not consistently implemented by all affected parties.
Software Supply Chains Gain Increased Focus
Another development concerns international software supply chains. In the second half of 2025, Swiss organizations were affected not only by vulnerabilities in widely used software products but also, in some cases, by compromised open-source components.
The problem is complex: if a widely used library becomes infected with malware or has a security vulnerability, numerous applications using that component can potentially be affected.
In this context, BACS refers to the two "Shai-Hulud" campaigns in September and November 2025. More than a thousand npm packages were compromised. The affected packages collectively had monthly download figures in the hundreds of millions.
Swiss Devices Also Abused for Attacks
BACS also observes a growing number of compromised devices that are part of so-called ORB networks. These often include internet-connected devices and routers infected with malware.
Such devices can be used by attackers for further attacks without their owners' knowledge. This means that devices belonging to private individuals or companies in Switzerland can unintentionally become part of a foreign attack infrastructure.
BACS therefore recommends regular security updates, especially for internet-exposed devices. The authority also points out that such infrastructures are not exclusively used by cybercriminals. International observations in 2024 already indicated that state actors also use ORB networks for espionage and sabotage activities.
No Explosive Increase in Cyber Incidents
Despite the various threats, the report does not depict an explosive increase in cyber incidents in Switzerland. BACS describes the impact of the cyber threat situation on Switzerland as "relatively stable," despite the increasingly tense geopolitical environment.
The Federal Office also assesses Switzerland's cyber resilience as largely robust overall. However, this does not mean that individual companies or authorities are protected from severe attacks. Ransomware, phishing, and compromised software, in particular, can cause significant damage.
What Does This Mean for Swiss Companies?
The report does not indicate an above-average impact on specific company sizes. Therefore, a particular clustering of ransomware attacks on SMEs cannot be inferred from the published figures.
Nevertheless, this development remains relevant for small and medium-sized enterprises. The decisive factor is less company size and more how well systems, employees, and data are protected. A successful cyberattack can have significant operational and financial consequences for any business.
Basic protective measures therefore remain important: security updates should be installed promptly, backups created regularly, and critical systems separated from each other where possible. Two-factor authentication and employee awareness against phishing are also central security measures.
Federal Council Works on New Regulations
At the political level, cyber resilience is also to be improved. In August 2025, the Federal Council mandated BACS, together with the Federal Office of Communications (OFCOM) and the State Secretariat for Economic Affairs (SECO), to prepare a consultation draft for new legislation on the cyber resilience of digital products by autumn 2026.
The focus is on security requirements for products with digital elements. Furthermore, rules for market surveillance are to be established, and the basis for a potential ban on the import and distribution of insecure devices is to be created.
The planned Swiss regulation aims to align with the European Cyber Resilience Act. At the same time, the Federal Council wants to keep the administrative burden on companies as low as possible and avoid Swiss companies operating internationally being confronted with diverging requirements.
Reporting Remains Voluntary for Most Companies
A general reporting obligation does not currently exist for all companies. Mandatory reported cyber incidents primarily concern operators of critical infrastructures. In the second half of 2025, BACS received 145 such reports.
However, companies and private individuals can voluntarily report cyber incidents to BACS. These reports are important for the federal government as they help to create the most comprehensive possible picture of the current threat situation.
The Cyber Threat Remains High
The semi-annual report thus presents an ambivalent picture. The total number of reports remains stable at a high level, while cybercriminals continuously develop their methods.
Phishing becomes more targeted, ransomware remains a serious threat, and international software supply chains open up new attack vectors. Additionally, compromised devices can be unknowingly misused for further attacks.
For Switzerland, this means: a dramatic deterioration of the overall situation cannot be inferred from the current figures. However, BACS also does not give the all-clear. The resilience of companies, authorities, and private users remains a central component of Swiss cybersecurity.
Sources
- Federal Office for Cybersecurity (BACS): Semi-annual report 2025/2, published on March 30, 2026.
- Federal Office for Cybersecurity (BACS): Current figures on voluntary and mandatory reported cyber incidents.
- Federal Council: "The Federal Council wants to strengthen the cyber resilience of digital products," August 20, 2025.



