How companies remain capable of taking action when under pressure 

Cyberattacks rarely give any warning. By the time they become apparent, there is often little time for lengthy discussions. Systems fail, decisions have to be made under pressure, and suddenly it becomes clear just how well a company is actually prepared. This was precisely the focus of the Cybersecurity Talk Liechtenstein in Ruggell. Around 50 senior executives from the region gained insights into modern cybercrime, real-world crisis management, active defence and the question of what companies can learn from risk management in elite sport.

The evening made it clear that cybersecurity is not purely a technical matter. It concerns senior management and the board of directors just as much as it does IT, staff and external partners.

Cybercrime has long been a professional business model 

Cybercrime often only comes to light when a large corporation is affected or a particularly high-profile case makes the headlines. The reality is much broader. Small and medium-sized enterprises, in particular, are specifically targeted by attackers.

Reto Zeidler, lecturer in cybersecurity at Lucerne University of Applied Sciences and Arts and an independent security consultant, explained why. Cybercrime today is organised on the basis of a division of labour. Some specialists seek out potential victims, others gain access to systems, whilst others still provide malware or infrastructure. Even money laundering can be purchased as a service.

One example of this is ransomware-as-a-service. Professional providers make attack platforms and malware available and, if the attack is successful, receive a share of the ransom paid. This significantly lowers the technical barrier to entry for attackers.

This also changes the economic logic behind cyberattacks. For perpetrators, a single victim does not need to be as large as possible. What matters is whether an attack can be carried out efficiently and scaled up.

Zeidler summed it up clearly:

‘SMEs are not collateral damage. They are the target.’

Added to this is artificial intelligence. In his view, it does not create fundamentally new forms of attack, but it does significantly accelerate existing methods. Potential targets can be analysed more quickly, large volumes of data evaluated more efficiently, and phishing messages created more professionally. Fake voices and videos are also becoming more readily available.

For Zeidler, AI is therefore one thing above all else: a fire accelerant.

When risk becomes reality 

Michael Hasler gave a first-hand account of just how quickly an abstract threat can turn into a real corporate crisis.

The former Global Head of IT reported on a serious ransomware attack on an international manufacturing company. At 6.15 am on Monday morning, the monitoring system triggered an alarm. Shortly afterwards, it became clear that large parts of the infrastructure had been encrypted. Two data centres, numerous servers and client machines, as well as systems in several countries, were affected. Production, logistics, administration and retail outlets were, in some cases, no longer operational.

Hasler describes the first few hours as a succession of bad news. Even the backups initially appeared to be encrypted. At the same time, the company had to decide which systems were needed first, how staff should be informed and how operations could continue, at least in part.

In some cases, this meant going back to pen and paper.

Sales outlets were supported by telephone, payment terminals were reconfigured and processes were improvised. Ultimately, a snapshot that the attackers had overlooked proved decisive. It enabled the infrastructure to be rebuilt using a relatively up-to-date data set.

‘In an emergency, it’s a reliable backup system that makes all the difference – and strong partners you can count on.’

It also became clear that technical priorities do not automatically follow the corporate hierarchy. It was not the managing director’s laptop that needed to be up and running first, but rather those systems and devices that enable production, logistics and core business processes.

Preparation begins before an emergency strikes

Hasler’s account of the days immediately preceding the attack was particularly striking. As early as Friday, the company had received a tip-off that its name had appeared in relevant forums. The systems were monitored more closely, though initially without any notable findings.

In hindsight, it was clear what more drastic measure would have been sensible: cutting off the connection to the outside world. Yet decisions of this kind are anything but straightforward during day-to-day operations. Subsequent analysis also revealed that the attackers had gained access to the infrastructure much earlier. Among other things, inadequately protected external access and legacy technical issues played a part. 

For Hasler, the most important lessons therefore lay not solely in individual technical measures. Equally crucial are clear lines of responsibility, documented processes, effective business continuity management and partners who can be called upon immediately in an emergency. The knowledge of individual staff members can also be decisive in this regard. Who understands the interdependencies of a particular production machine? Who knows which external provider is responsible? And is this knowledge documented should a person leave the company?

His reflection on his own situation prior to the incident was correspondingly self-critical. When asked how well the company had been prepared at the time, Hasler replied, in essence: “I had blind faith.” Cybersecurity cannot simply be delegated to the IT department. Responsibility for risks, priorities and crisis decisions remains a management task.

Identifying issues before an incident leads to damage 

Genau an diesem Punkt setzte Tobias Meier, CTO von MTF Solutions, an. Sein Fokus lag auf der Frage, wie Bedrohungen möglichst früh erkannt und eingedämmt werden können.

Informationssicherheit basiert für ihn auf drei Säulen: Organisation, Mitarbeitende und Technik. Eine einzelne Sicherheitslösung kann deshalb nie alle Risiken abdecken. Prozesse und Verantwortlichkeiten gehören genauso dazu wie Security Awareness, technische Schutzmechanismen, sichere Authentifizierung und funktionierende Backups.

Meier betonte dabei besonders die Rolle der Mitarbeitenden:

‘Security awareness is almost the most powerful tool you have.’

Regular training sessions, phishing simulations and a cautious approach to suspicious logins or messages can help to stop many attacks at an early stage.

Figures from MTF’s Security Operations Centre illustrate the sheer volume of data that requires additional technical monitoring. In 2025, more than 95 billion security-related events were processed for the clients under MTF’s care. This resulted in around 79,000 alerts, which were investigated in more detail. 158 cases were treated as specific incidents. None of these resulted in a major incident that disrupted operations.

A key focus is on Microsoft 365. According to Meier, around 80 per cent of the incidents handled by MTF relate to this area. Compromised accounts are of particular interest to attackers because they can provide access to emails, files, Teams and other corporate information. What makes this particularly insidious is that attackers do not necessarily act immediately after taking over an account. They can monitor email traffic over a prolonged period and wait for a suitable opportunity to, for example, manipulate payment details.

The aim of a Security Operations Centre is therefore not to make every attack impossible. It is about detecting and classifying suspicious activity as early as possible and intervening before it causes significant damage.

From the Streif to business management 

After discussing cybercrime, ransomware and security operations, the focus shifted to the ski slopes to round off the session.

Marco Büchel is familiar with situations where decisions have to be made in a matter of seconds. The former World Cup ski racer described a run on the Streif where a jump did not go as planned. In the blink of an eye, he had to decide whether to stick to his intended line or change his plan. His insight:

‘If reality changes my plan, I change the plan, not the goal.’

This is precisely where the link to corporate risk management lies. Preparation is crucial. Equally important, however, is the ability to accept a changed situation, reassess risks and still remain capable of taking action.

Anyone standing at the start of the Streif cannot completely eliminate risk. However, they can prepare, assess the risk and allow sufficient leeway for the unexpected.

Büchel ultimately boiled the question of consciously managing risk down to two personal questions:

«How hard do you want it? And why are you doing it?»

MTF: Your partner for cybersecurity and resilience 

Remaining capable of acting is the real goal

The Cybersecurity Talk Liechtenstein explored cyber resilience from a wide variety of perspectives. Nevertheless, a common thread ran through all the presentations: it is not about completely eliminating every risk. It is about understanding risks, preparing for them in a targeted manner, and remaining capable of taking action even when reality deviates from the plan.

This includes technical safeguards and continuous monitoring, as well as effective backups, clear lines of responsibility, documented processes, well-rehearsed emergency procedures and reliable partners.

Cybersecurity thus becomes an integral part of corporate governance. After all, when a crisis strikes – if not before – it is no longer just about systems and data, but about whether a company can continue to operate and make the right decisions under pressure.

MTF supports companies in addressing cyber risks holistically: from security awareness and technical protective measures, through security operations and continuous monitoring, to support in the event of an incident.

The focus is not on a single security solution, but on the interplay between organisation, staff and technology. The aim is to create an IT environment that detects threats at an early stage, reduces risks and helps companies remain capable of acting even in the event of a crisis.

Also interesting 

Do you have Questions ?

Michael Stüssi
Sales Manager