Cyber Security for Swiss Companies, The 2026 Guide
Introduction
The threat landscape for Swiss companies has measurably worsened over the past eighteen months. The Federal Office for Cyber Security (BACS / NCSC) recorded more than 70,000 reports through its reporting platform in 2025, an increase of over 30% compared with 2024. Ransomware remains the most financially damaging threat, followed by CEO fraud and supply-chain compromises. With the entry into force of the mandatory reporting duty for operators of critical infrastructure under Art. 74a–74h ISG (Information Security Act), additional binding obligations now apply.
This guide consolidates the security requirements Swiss SMEs and large groups will face in 2026. It covers:
- The current Swiss threat landscape
- The regulatory frame (ISG, DSG, NIS2 pull-through, FINMA, EU AI Act)
- The role of BACS and sector CERTs (Swiss FS-ISAC, MELANI successor)
- 18 prioritised controls (CIS Controls v8.1) for SMEs and groups
- Incident handling and reporting obligations
- SME vs. group prioritisation with indicative budgets
The guide is designed as a practical reference. It contains the sources you can cite in an audit, a board report or a supplier onboarding.
Swiss threat landscape 2026
Four threat clusters dominate the Swiss picture:
1. Ransomware with double extortion: encryption plus data exfiltration with a publication threat. Public 2025 cases (multiple municipalities, hospitals, a major logistics firm) show losses between CHF 200,000 and CHF 8 million including recovery. Typical initial vectors: phishing, unpatched VPN vulnerabilities, exposed RDP and supplier compromise.
2. Social engineering and CEO fraud: prepared, multi-stage campaigns, increasingly with AI-generated voice or video deepfakes, target accounting and treasury. BACS data show an average single-transaction loss of around CHF 250,000.
3. Supply-chain attacks: compromise of IT service providers (MSPs, M365 partners, ERP implementers) as a bridge into customer environments. Swiss SMEs are mostly caught off guard because they do not actively govern their providers' access.
4. State-aligned and hacktivist actors: visibly increased DDoS and web defacement activity against Swiss authorities, associations and prominent companies since 2022. Operational damage is usually low, reputational damage significant.
This picture justifies a defence-in-depth model: prevention (hardening, patching, MFA), detection (EDR, SIEM/SOC), response (IRP, forensics), recovery (immutable backups, BCM), always in parallel, never sequentially.
Regulatory frame
The regulatory frame in 2026 is denser than just two years ago. The main strands:
Information Security Act (ISG): in force since 1 January 2024. For operators of critical infrastructure, the mandatory cyber-incident notification under Art. 74a–74h ISG has applied since 1 April 2025, the deadline is 24 hours from awareness. The list of in-scope sectors includes energy, water, food, health, finance, transport, telecommunications, public administration and others.
DSG: Art. 8 DSG (technical and organisational measures) and Art. 24 DSG (breach notification to the FDPIC), ‘as soon as possible’ from awareness.
NIS2 directive (EU 2022/2555): EU law, but Swiss groups with EU subsidiaries, supplier status or service exports into the EU are pulled into the NIS2 world via contract chains.
FINMA Circular 23/01 ‘Operational Risks and Resilience, Banks’: for banks and securities firms, with ICT risk, BCM and cyber requirements.
EU AI Act: for AI systems with EU market exposure, with phased deadlines from February 2025.
Sector-specific rules: KVG/HMG for hospitals, BankG and FinIG for financial institutions, NEG for energy operators.
BACS and sector CERTs
Since 2024 the Federal Office for Cyber Security (BACS) has been the central federal authority for cyber security. It replaces the previous NCSC organisationally, takes on its tasks and serves as the contact point for the ISG reporting duty. Operationally BACS provides:
- Weekly briefings and situation reports
- Vulnerability advisories
- Sector CIRCL / CSIRT coordination
- Half-year and annual reports as references for board reporting
Regulated sectors have specialised CERT structures: the Swiss Finance ISAC for finance (closely aligned with FINMA and SNB), SwissEnergyCERT for utilities and eHealth Suisse / SwissCSIRT-Health for healthcare. Membership is often voluntary but increasingly a de-facto standard in tenders. We recommend every organisation above 250 employees actively use at least one ISAC membership, not only to consume intelligence, but to share own incidents anonymised and so harden the sector.
The 18 prioritised controls (CIS Controls v8.1)
The CIS Controls v8.1 are the most widely used prioritised control set internationally and map cleanly onto ISO 27001 Annex A and NIST CSF. For Swiss conditions we prioritise:
- Inventory of hardware and software assets (CIS 1, CIS 2)
- Data protection / data classification (CIS 3)
- Secure configuration (CIS 4)
- Account management and MFA (CIS 5, CIS 6)
- Continuous vulnerability management (CIS 7)
- Audit log management (CIS 8)
- Email and browser protection (CIS 9)
- Malware defence / EDR (CIS 10)
- Data recovery / immutable backups (CIS 11)
- Network security and segmentation (CIS 12, CIS 13)
- Security awareness and phishing simulation (CIS 14)
- Supplier security (CIS 15)
- Application security / SecDevOps (CIS 16)
- Incident response (CIS 17)
- Penetration testing (CIS 18)
CIS distinguishes three Implementation Groups: IG1 (SMEs, baseline, ~56 safeguards), IG2 (mid-market, ~130), IG3 (group, all 153). SMEs should have completed IG1 fully by 2026; from 250 employees upwards IG2 is the reference.
Incident handling and notification duties
A prepared incident response process reduces average incident costs by 40 to 60% according to industry studies. Preparation includes:
- A written incident response plan with roles (incident commander, tech lead, comms lead, legal lead)
- A 24/7 escalation and contact matrix
- Retainer contracts with a forensics partner with a guaranteed SLA (ideally 4 hours)
- Prepared communication templates (employees, customers, media, authorities)
- Regular tabletop exercises at least once per year, including the executive team
In 2026 Swiss reporting duties can overlap. A personal-data breach at a critical infrastructure operator can trigger three notifications:
- Art. 24 DSG to the FDPIC (as soon as possible)
- Art. 74b ISG to BACS (within 24 hours of awareness)
- Art. 33 GDPR to the competent EU authority (within 72 hours), if EU data subjects are affected
In regulated sectors a sector notification is added (FINMA, Swissmedic, FOPH, OFCOM). Operationally that requires a rehearsed triage in the first hours that prepares facts, data categories, affected numbers and security posture for the notification decision.
SME vs. group, prioritisation and budget
The threat picture for SMEs and groups is fundamentally the same, but the responses are not. Our investment guidance aligned to the Swiss market:
SME (10–250 employees): cyber budget typically 0.5–1.5% of revenue. Must-haves: MFA everywhere, Microsoft 365 / Google hardening, EDR on every endpoint, immutable backups with tested restores, monthly vulnerability scans, an annual penetration test on internet-facing systems, half-yearly phishing simulations, a written IRP and an external forensics retainer. An external part-time CISO (4–8 days per month) replaces an expensive full-time hire during the learning phase.
Mid-market (250–2,000 employees): budget 1–3% of revenue. Additional must-haves: ISO 27001 or equivalent framework, SIEM with 24/7 SOC (in Switzerland often hybrid, detection in-house, response outsourced), TLPT exercises every two years, internal audit, crisis management.
Group (>2,000 employees): budget 2–5% of revenue. Additional must-haves: a full security operations programme with an own CSIRT, annual TLPT, red team exercises, bug bounty, supplier security programme with audits, cyber insurance above CHF 25 million.
The right order is not ‘tools first, then process’ but: inventory, hardening, detection, response, exercise, improvement. Investing in this order delivers measurable risk reduction within 12 months.
How SIDD supports you
SIDD builds cyber security programmes for Swiss SMEs, mid-market and groups that are not only audit-ready but hold up in an incident. Our CISO / information security officer mandate covers strategic steering, risk management, supervisory reporting and crisis management. For continuous technical hardening we combine vulnerability scans, targeted penetration tests and, where required, red team and TLPT exercises for regulated sectors.
In addition we train employees and the executive team through our IT security workshops, explicitly tailored to the Swiss threat landscape and compliance duties. Where a full ISMS is sensible, we run the ISO 27001 implementation. For a first maturity baseline use our contact form; concrete investment and effort numbers come within five working days via our offer.
