When cybercrime becomes a serious issue 

A cyberattack rarely begins with a big bang. It often starts with a compromised account, an infected attachment, an unpatched vulnerability or a suspicious connection that only comes to light later. At the Cybersecurity Talk Zurich, it became clear that when cybercrime strikes a company, it is not just about technology. It is about decision-making, preserving evidence, crisis communication, recovery and the question of who takes on which role in the event of an emergency.

That afternoon, around 60 participants were presented with three different perspectives on the same threat: the viewpoint of the cyber investigations unit at the Zurich Cantonal Police, the experience of a company that had actually been affected, and the day-to-day operations of a Security Operations Centre tasked with detecting and containing attacks at an early stage.

With Stefan Gruner, Head of Cyber Investigations at the Zurich Cantonal Police; Roger Mattmann, former CISO of the AMAG Group and now Head of the Information Security Unit (FSIS) at the Zug Cantonal Finance Department; and Tobias Meier, CTO of MTF Solutions, it became clear that cybersecurity affects senior management, IT, staff, processes and external partners in equal measure.

Cybercrime is not just a ‘hoodie’ stereotype 

Stefan Gruner kicked things off with an insight that one rarely gets: how do the police operate when a cyberattack is no longer just a theoretical concept but becomes the subject of a criminal investigation?

Gruner demonstrated that cyber investigations involve far more than simply gathering technical evidence. First, it is essential to understand exactly what has happened. The next steps involve securing evidence, digital traces, data storage media, log files, network traffic and international cooperation. The police’s aim is not to get a company’s IT systems up and running again. Their remit is to identify and locate the perpetrators and to secure admissible evidence.

Gruner used the example of ransomware to illustrate just how professionalised cybercrime has become today. Behind many attacks are not individuals in hoodies, but organisations with a division of labour comprising developers, affiliates, analysts, money launderers and negotiators. Cybercrime has thus long since become a business model, with clear roles, well-rehearsed procedures and a simple goal: to make money.

Gruner also highlighted the biggest vulnerability: people. Many attacks succeed not because of sophisticated technology, but because of simple carelessness. His sobering observation from real-world experience: it is ‘really frightening’ how poor many passwords still are – even a password better than ‘Admin’ would prevent a great deal.

Artificial intelligence is also a factor in cyber investigations, albeit in a more down-to-earth way than is often portrayed. There is no single ‘button’ that allows AI to carry out entire attacks independently. What is increasing significantly, however, is the scaling up of individual elements of an attack: social engineering to scout out a company’s structure, or the drafting of phishing emails. However, the police have not yet been able to clearly establish a measurable overall effect on case numbers.

For SMEs, one message in particular was key: reporting incidents early helps. Not because the police will then restore the backup or repair the systems, but because every report helps to identify patterns, secure evidence and tackle the problem as a whole. In an emergency, therefore, IT, incident responders, senior management, the legal department and the police should ideally be sitting around the same table. Reports from incident responders are particularly valuable for investigations, as they show where attackers were within the system and what actually happened.

Gruner also remained clear but realistic on the issue of ransom payments. The police advise against paying. At the same time, he showed understanding for the fact that, in an emergency, companies may face an existential decision: pay, or risk being unable to continue operations. This is precisely why so much is decided earlier on: in terms of preparation, backups, responsibilities and the question of who to call immediately in an emergency.

“The police are looking for evidence and the perpetrators, not the next backup. We therefore always recommend calling in an incident responder – their report is invaluable to our investigations.”

The attack that almost turned into a worst-case scenario 

Roger Mattmann then demonstrated what a cyberattack feels like from the perspective of an affected company. Not as an abstract risk, but as a situation in which decisions suddenly have to be made that affect operations, communication and customer trust.

At the end of January 2020, the AMAG Group fell victim to a cyberattack. At the time, AMAG announced publicly that its IT systems had been attacked from outside and that security work might cause disruptions to certain processes. What lay behind this brief statement was considerably more complex: according to AMAG’s sustainability report, the company was alerted by the then National Centre for Cyber Security, formerly MELANI, after a suspicious IP address had been contacted from the AMAG network. A phishing email received around a month earlier is considered the likely point of entry.

Mattmann brought home just how precarious the situation was: the attackers already had domain administrator rights – effectively the highest level of control within the company. The response was drastic: AMAG disconnected from the internet. For a company with around 300 garages, this had a massive impact on day-to-day operations: no test drives, no repair work, no parts orders. Even working from home was suddenly no longer an option – without an internet connection, all staff had to come into the office, where there simply weren’t enough workstations for everyone. The cyberattack thus became not just an IT incident, but an operational state of emergency.

Because simply cleaning up the system was not enough when domain admin rights had been compromised, AMAG opted for a comprehensive rebuild: Around 5,100 PCs were set up from scratch, with the old and new environments running in parallel for months. What appeared from the outside to be a successfully fended-off attack meant, internally, seven months of strain, weekend work, troubleshooting and decisions made under intense pressure.

For Mattmann, one common thread ran through almost every cause of a cyber attack: the human factor. Whether a system is patched too late, a password is too weak or a phishing email is opened – in the end, there is almost always a human decision behind it. Even a technical vulnerability is ultimately often a ‘human error’ if an available update is left uninstalled for days instead of being applied immediately. He illustrated just how quickly this can be exploited using an example from his own experience: After a security vulnerability became known, the first attempt to attack a system that had not yet been patched took place within just five minutes.

No ransom was paid. Nevertheless, according to Mattmann, AMAG invested almost six million Swiss francs. A large part of this did not simply go towards new security tools, but towards streamlining established structures, modernisation and a cleaner, more easily monitored operation.

His lesson from this was pragmatic: companies must know, well before an emergency arises, who takes on which role. Of particular importance are key internal personnel from IT and specialist departments who are familiar with systems, dependencies and access rights, and who can be immediately released from their day-to-day duties in an emergency. External specialists are important. But without internal knowledge, any response will be slower.

AMAG was later awarded the first ISSS Courage Award for its open communication regarding the incident. The award is intended to encourage companies to make cyber incidents and the lessons learnt from them public, and to reduce the stigma associated with cyber attacks.

“Cybersecurity doesn’t begin when an incident occurs. Once an attack becomes apparent, the only thing left to determine is how well a company is prepared.”

Active defence: Technology detects, people decide 

To conclude, Tobias Meier, CTO of MTF Solutions, drew a parallel between crisis management and day-to-day security. After all, before an attack becomes a matter for the police or a crisis management team, there are usually early warning signs: an unusual login, a suspicious link, a compromised account or activity that does not fit with normal behaviour.

This is precisely where a Security Operations Centre comes into play. It does not simply collect technical alerts, but helps to filter out the relevant incidents from a multitude of individual signals. Tobias Meier demonstrated just how important this interplay between technology, staff and organisation is. Firewalls, antivirus software and XDR systems form the technical foundation. However, what is crucial is whether trained staff, clear procedures and a functioning contingency plan turn this into an effective defence.

A large proportion of today’s attacks take place where companies carry out their day-to-day work: in Microsoft 365. Over 80 per cent of the security incidents handled by MTF last year were related to this. The reason is obvious: hardly any other system brings together emails, Teams chats, OneDrive, SharePoint, calendars and internal communication in a single place.

‘A single compromised Microsoft 365 account doesn’t just open up a mailbox – it opens up the whole company.’

Meier explained why such attacks are so dangerous for businesses. The first step often seems harmless: a well-written message, a seemingly familiar sender, a link to what appears to be a login page. However, anyone who confirms their login there may, under certain circumstances, be revealing not only their username and password to attackers, but also their active session. Traditional multi-factor authentication can be bypassed in such scenarios because the attacker positions themselves between the user and the target system.

This is often when the real danger begins. Attackers do not need to encrypt data immediately to cause damage. They eavesdrop, set up redirects, monitor communication patterns and wait for the moment when an intervention is worthwhile – for example, when an invoice is sent, a payment is being prepared or bank details are being updated. A compromised account can thus quickly become a business risk.

Effective defence therefore does not begin with a single measure. It is built on multiple layers: awareness, phishing-resistant login with passkeys, conditional access, geoblocking, regular security updates and backups that are separate from the production system. However, it is also crucial that anomalies are not simply left as technical alerts. They must be assessed, investigated and, where necessary, immediately translated into concrete actions.

Artificial intelligence is also transforming this work. Attackers use AI to make phishing messages more credible, replicate websites more quickly or gather information about companies more efficiently. Defenders use AI to analyse large volumes of data, triage alerts and detect anomalies more quickly.

MTF: Your partner for cyber security and resilience 

The Cybersecurity Talk Zurich demonstrated that cybersecurity is only effective when different perspectives work together. The police focus on clues, evidence and identifying the perpetrators. A company that has been affected focuses on operations, communication and recovery. A Security Operations Centre focuses on early detection, containment and response.

For SMEs, it is precisely this collaboration that is crucial. Cyberattacks cannot be completely prevented. But companies can do a great deal to ensure that an incident does not result in damage that threatens their very existence: with clear roles, trained staff, functioning backups, reliable partners and a security architecture that detects attacks at an early stage.

Ultimately, one simple realisation remained: cybersecurity is not a state that is achieved once and for all. It is an ongoing process. And in the event of an emergency, it is not just a question of what technology is in place, but whether people, processes and partners are prepared to act appropriately.

Contact us

Whether it’s a Security Operations Centre, incident response, Microsoft 365 protection, awareness training or an emergency response plan: MTF supports SMEs in realistically assessing cyber risks and implementing appropriate measures.

Get in touch with us. We’d be happy to advise you.

Also interesting 

Do you have Questions ?

Stephan Keller
Chief Financial Officer