Swiss Study Warns Small Businesses Are Still Underestimating Growing Cyber Threats
Small and medium-sized enterprises across Switzerland are facing an increasingly dangerous digital threat environment, yet many business owners continue to underestimate the scale of the risks confronting their organizations, according to newly released research that is raising concerns among cybersecurity experts and risk-management professionals.
The findings come as cybercrime continues to rank among the most significant threats to businesses worldwide. While large corporations often dominate headlines following major cyber incidents, researchers say smaller companies are becoming increasingly attractive targets because they frequently lack the resources, expertise and protective measures needed to defend against modern attacks.
A study published by VZ VermögensZentrum in cooperation with the Lucerne University of Applied Sciences and Arts found that many Swiss SMEs still assume cyber risks are unlikely to affect them directly. Researchers warned that such assumptions can leave businesses exposed to disruptions that extend far beyond information technology systems. Cyber incidents can interrupt operations, damage data, strain customer relationships, create legal obligations and place significant financial pressure on companies. In severe cases, business continuity itself may be threatened.
The warning comes amid growing evidence that cyber threats are becoming more sophisticated and more widespread. Cybersecurity specialists note that artificial intelligence is increasingly being used by cybercriminals to automate attacks, improve phishing campaigns and identify vulnerabilities more efficiently. As a result, even smaller businesses that previously believed they were unlikely targets are finding themselves exposed to a rapidly evolving threat landscape.
According to the study, one of the biggest challenges facing SMEs is a gap between perceived risk and actual exposure. Research released by Deloitte this year found that nearly half of surveyed SME employees had experienced a serious cyber incident at their workplace within the previous three months. Yet only a much smaller share considered their organization’s cyber risk to be high. The disconnect was especially pronounced among the smallest firms, where awareness often lagged behind the reality of the threat environment.
Cybersecurity experts say this perception gap can create dangerous blind spots. Businesses that underestimate risk are less likely to invest in security training, implement modern authentication measures or establish contingency plans for responding to attacks. Without such safeguards, organizations may struggle to recover when incidents occur.
The study highlights phishing as one of the most common threats affecting Swiss businesses. Fraudulent emails, fake invoices, manipulated payment requests and attempts to steal login credentials continue to be among the primary techniques used by cybercriminals. These attacks often require little technical sophistication but can result in significant financial losses when employees are successfully deceived.
Official statistics also illustrate the scale of the challenge. Swiss authorities recorded tens of thousands of digital offenses in recent years, while cybersecurity agencies emphasize that many incidents are never reported. Because reporting remains incomplete, experts believe the true extent of cybercrime affecting Swiss businesses is substantially higher than official figures suggest.
Researchers argue that stronger awareness is only part of the solution. Businesses must also gain a clearer understanding of their digital dependencies and operational vulnerabilities. Risk assessments, clearly defined responsibilities, tested backup systems and incident-response plans are increasingly viewed as essential components of modern business management rather than optional IT measures.
Another area receiving attention is cyber insurance. The VZ study found that fewer than 12% of Swiss companies currently hold cyber insurance policies. Researchers suggest adoption remains low because coverage can be difficult for smaller firms to evaluate and compare. However, experts caution that insurance should not be viewed as a substitute for preventive security measures. Instead, it forms only one element of a broader risk-management strategy.
Industry specialists have repeatedly stressed that organizations seeking insurance coverage often need to demonstrate a minimum level of cybersecurity readiness before policies can be issued. Measures such as multi-factor authentication, employee training programs and documented security procedures are increasingly becoming prerequisites for obtaining meaningful protection.
Recent studies indicate that many Swiss companies still have work to do. Research from the SwissVR Monitor found that a large majority of businesses lack dedicated strategies for responding to AI-enabled cyberattacks, while emergency preparedness remains inconsistent across many organizations. These shortcomings are viewed as particularly concerning because attackers are increasingly using advanced technologies to improve the effectiveness of their operations.
Government agencies and cybersecurity organizations have intensified efforts to raise awareness among SMEs. The National Cyber Security Centre has repeatedly emphasized that cyberattacks are no longer limited to large corporations and that practical, affordable security measures can significantly reduce exposure to risk. Educational initiatives and training programs have therefore become a growing part of Switzerland’s cybersecurity strategy.
The latest findings reinforce a message that has emerged consistently from recent research: while cyber threats continue to evolve, many smaller businesses remain insufficiently prepared. Experts argue that improving awareness, strengthening basic protections and integrating cybersecurity into everyday business planning will be essential if Swiss SMEs are to navigate an increasingly digital economy with confidence. As cybercrime becomes more sophisticated and more costly worldwide, the ability to recognize and manage cyber risk is rapidly becoming a fundamental requirement for long-term business resilience.
