Cyber resilience rather than burying one’s head in the sand 

Artificial intelligence (AI) is transforming cybersecurity on both sides. Companies are using it to make processes more efficient. At the same time, cybercriminals are using AI to prepare and automate attacks more quickly and make them appear more credible. Yet whilst the threat landscape is becoming more complex due to automated attacks, a dangerous trend is emerging in Switzerland: the priority given to cybersecurity in SMEs is declining. It is time to abandon the ‘head-in-the-sand’ approach and prepare for the inevitable.

Space legend Claude Nicollier once said of the threat from space: “The probability of an asteroid impact is 100 per cent. We don’t know when, but we must be prepared for it.” In today’s digital world, the “impact” is not a chunk of rock, but an encrypted server, a wiped-clean account or a total halt to production. The probability of a cyberattack on a Swiss company is now also close to 100 per cent. The question is not whether it will happen, but when – and whether you are prepared when the digital asteroid strikes.

Too small to be targeted? A dangerous misconception

It is a worrying finding: according to the latest study “SME Cybersecurity 2025”, the issue is losing ground among Swiss SMEs. Whilst everyone is talking about ChatGPT and the next AI revolution, protecting their own infrastructure is slipping down the list of priorities. Many companies are postponing necessary investments in favour of short-term projects. 

People are lulled into a false sense of security. “We’re too small”, “There’s nothing to steal from us” or “We’re only connected locally” are phrases we often hear at MTF. Yet it is precisely this complacency that poses the greatest security risk. Cybercriminals no longer operate like snipers who pick out a single, large target. They use AI-driven ‘dragnets’ that continuously scan the internet for vulnerabilities. An SME without an up-to-date security strategy is not a small fish in this net, but easy prey.

Facts that give pause for thought 

The figures speak for themselves: only 42% of Swiss SMEs feel well protected against cyberattacks – down from 55% the previous year. Even more alarming: for 28% of SMEs, cyber security will no longer be a priority by 2025 – an increase from 18% the previous year. This is happening at precisely the moment when the threat landscape is becoming vastly more severe due to AI.

Press round-up: Every sector is affected – from SMEs to large corporations. No business is too small.

THE ROLE OF AI: WHEN THE ATTACKER NEVER SLEEPS 

The integration of AI into cybercrime has fundamentally changed the rules of the game. What used to be manual work carried out by hacker groups is now done by algorithms in milliseconds.

Automated vulnerability scanning

AI bots now scan the Swiss internet in real time. They find outdated server software, unsecured remote access points or misconfigured cloud storage faster than a human administrator ever could. As soon as a vulnerability is discovered, the attack is often carried out fully automatically. This means that even if you think your company is “uninteresting”, your infrastructure will become a target simply because of a technical vulnerability.

Phishing 2.0: The perfect deception

Thanks to Large Language Models (LLMs), the days of clumsy phishing emails are over. According to the latest figures, 82.6% of all phishing emails are now created with the help of AI. Attackers today generate perfectly worded messages in flawless German (or even Swiss German) that are tailored precisely to the context of your company. These emails are almost indistinguishable from genuine business enquiries. The threshold for clicking on an infected link drops dramatically when the message appears to come directly from a known supplier or your own boss.

Deepfakes and identity theft

We are moving into an era in which we can no longer blindly trust our senses. Deepfakes – audio and video content manipulated or generated by AI – blur the line between reality and deception so perfectly that even experts can barely tell the difference. A brief phone call from a managing director requesting an urgent payment or the release of sensitive data now sounds completely authentic. In a business context, so-called ‘voice cloning’ is particularly dangerous: often, just a few seconds of audio material from public sources such as YouTube videos or interviews are enough to imitate a voice so convincingly that it sounds genuine.

A recent case from the canton of Schwyz illustrates the scale of the problem: an entrepreneur transferred several million francs to an Asian bank account after hearing the AI-cloned voice of his well-known business partner. Schwyz: Criminals make off with millions using artificial intelligence – News – SRF
The statistical trend behind this technology is alarming, as the number of deepfake files detected worldwide has skyrocketed from around 500,000 in 2023 to an estimated 8 million in 2025 – a rise of 1,500 per cent.

THE SWISS REALITY: FIGURES FROM THE BACS 2025 

The Federal Office for Cyber Security (BACS, formerly NCSC) continues to receive a high volume of reports. In 2025, just under 65,000 reports of cyber incidents were received. That is an average of 177 reports per day – or one report every 8 minutes.

CEO fraud at record levels
Among the fraud offences reported by companies, there has been a marked increase in CEO fraud: 970 cases were reported in 2025 – a 35% increase compared with 2024 (719 cases). Attackers are increasingly using AI-generated content and psychological manipulation to deceive employees.

THE BIGGEST CHALLENGES FACING SWISS SMEs 

According to BACS, it is always the same lapses that leave the door wide open:

  • Missing updates: 
    Many systems are running on known software for which security patches have long been available. Failing to install an update is an open invitation.
     
  • Poor password policy: 
    Despite all the warnings, weak passwords are still being used – or, even worse – the same login details are used for multiple services. Without multi-factor authentication (MFA), a user account is virtually unprotected these days. According to the SME study, only 53% of Swiss SMEs use MFA – a critical figure, as MFA is one of the most effective defences against AI-driven identity theft.
     
  • Unsecured remote access: 
    The rapid shift to working from home has left behind many makeshift solutions. Open remote desktop connections without additional security measures are the most common entry point for ransomware attacks in Switzerland. In 2025, 104 cases of ransomware were reported – a slight increase compared with the previous year.
     
  • The lack of an emergency plan:
    The study shows that only 30% of SMEs have an emergency plan in place for business continuity. When an emergency strikes, every minute counts. Those who have not defined clear responsibilities and do not know how to restore backups in the event of a crisis lose valuable time – and, ultimately, money. 73% of the SMEs affected suffered financial losses, whilst 27% lost customer data.

PREVENTION RATHER THAN PANIC: HOW TO MAKE YOUR SME RESILIENT 

The good news is: you don’t need to set up your own Security Operations Centre or become an AI expert yourself to protect yourself. It’s all about mastering the basics and consistently implementing modern security strategies.

Visibility and control

You can only protect what you know. A professional security assessment is the first step. This involves putting the entire IT infrastructure through its paces: Where is sensitive data stored? Which devices are on the network? Where are the vulnerabilities? MTF helps you achieve this transparency and draw up a list of priorities for securing your systems.

Multi-factor authentication (MFA): The digital gatekeeper

In a world where passwords are cracked in seconds by AI-powered attacks or stolen through sophisticated phishing, MFA is your most important line of defence. It ensures that a stolen password alone is worthless. Despite its enormous protective effect, according to the SME study, only 53% of Swiss businesses consistently rely on MFA – there is an urgent need for action here to effectively prevent identity theft.

The human factor: the “human firewall”

Technology alone will never be enough. As attacks are becoming increasingly psychological (social engineering), your staff must be made aware of the risks. Regular training and simulated phishing tests sharpen their awareness of potential threats. A healthy scepticism towards digital instructions should become part of your corporate culture. According to the SME study, only 32% of companies carry out regular security training. Particularly in the case of AI-powered attacks that rely on social engineering, an alert individual is often the last line of defence.

Zero Trust: Don’t trust blindly

The modern security concept is known as “Zero Trust”. This means that no device or user is trusted by default simply because they are on the company network. Every access attempt must be verified. This prevents an attacker who has gained entry to the system from spreading unhindered throughout the entire network.

Network segmentation: Firewalls for your data

Dividing your network into isolated segments acts like fire doors in a building: it prevents threats such as ransomware from spreading like wildfire throughout the entire organisation. In the event of an attack, the damage remains localised, whilst the rest of the infrastructure remains secure and operational. In the age of AI, this is crucial for stopping automated attacks that attempt to spread laterally throughout the entire system in a matter of seconds. 

Managed Security Services: Professional monitoring for SMEs

The reality in many SMEs: there is no in-house security department and no 24/7 monitoring. Managed Security Services (MSS) fill this gap. A specialist IT service provider takes charge of continuous monitoring, utilises AI-powered threat detection and responds in the event of an emergency. This gives SMEs access to security expertise and state-of-the-art Security Operations Centres (SOCs) that they could never set up themselves.

The last line of defence: intelligent backups

When all else fails, your backup is your lifeline. But beware: modern ransomware specifically targets backups in order to encrypt them too. A modern strategy relies on immutable backups, which cannot be tampered with even if the network is successfully attacked.

MTF: Your partner for COMPREHENSIVE CYBERSECURITY 

The threat posed by AI is real – but it is no reason to give up. The comparison with the digital ‘asteroid’ demonstrates one thing above all: preparation is both possible and necessary. The time for excuses is over. In a connected economy, cyber security is no longer just an IT discipline, but a prerequisite for business stability and growth. Those who follow the BACS’s tried-and-tested recommendations, establish clear processes and rely on trustworthy partners can operate with confidence and security even in the age of AI.

Here at MTF, we support Swiss SMEs in bridging the gap between technological innovation and essential security. From risk analysis to contingency planning – we ensure that you are prepared for any emergency.

Let’s build your digital shield together – start with a no-obligation cyber check for your business.

FAQs 

  1. Why are Swiss SMEs of interest to cybercriminals?
    Cybercriminals have long since moved beyond targeting large companies. Modern attacks are largely automated. AI-powered tools continuously scan the internet for vulnerabilities, regardless of a company’s size or sector. SMEs also often have limited security resources and are therefore frequently regarded as easy targets. For attackers, it is not the size of a company that matters, but how easily an attack can be carried out successfully.
     
  2. How can I still spot a phishing email today when AI crafts them so perfectly?
    Spelling mistakes are no longer a reliable indicator of a phishing email. Instead, always check the context: Is the request unusual? Does the message create a false sense of urgency? Are you being asked to disclose confidential data, click on a link or authorise a payment? If in doubt, unusual requests should always be verified via a second communication channel, for example by calling back a known number.
     
  3. What are Managed Security Services – and are they worth it for an SME?
    Managed Security Services (MSS) are outsourced security services in which a specialist partner takes over the monitoring and operation of security solutions. These include, for example, the continuous monitoring of systems, threat detection, incident management and Security Operations Centre (SOC) services. This approach is particularly beneficial for SMEs, as maintaining in-house security departments and 24/7 monitoring are often not economically viable.
     
  4. We have a backup – isn’t that enough protection?
    A backup is important, but it does not provide complete protection. Modern ransomware specifically targets backup systems and attempts to encrypt or delete them as well. How your backup is configured is therefore crucial: immutable backups cannot be tampered with, even in the event of a successful attack on the network. Regular restore tests are equally important. A backup is only truly reliable if recovery works when it really matters. The SME study shows that only 30% of Swiss SMEs have a tested contingency plan.
     
  5. Where do I start if I don’t know how well my business is protected?
    The first step is a structured assessment of the current situation. A security assessment provides transparency regarding the existing IT landscape, identifies vulnerabilities and highlights which risks should be addressed as a priority. On this basis, specific measures can be defined and investments targeted where they will have the greatest impact.
     
  6. Which security measures should Swiss SMEs prioritise?
    The most important fundamentals include the consistent installation of security updates, the introduction of multi-factor authentication (MFA), regular data backups, securing remote access, and raising staff awareness. Equally important are clearly defined emergency procedures and regularly tested recovery processes, to ensure the company remains operational even in the event of a crisis.

Also interesting 

Do you have Questions ?

Stephan Keller
Chief Financial Officer