Skip to main content

Underestimated, unprotected, underinsured: Cyber risks for SMEs in Switzerland

Three security vulnerabilities are putting businesses at risk

Main findings

In the age of artificial intelligence, cyber-security is becoming a crucial factor in competitiveness and resilience.

Organisations that consistently invest in risk awareness, modern security architectures, organisational resilience and collaborative partnerships today are laying the foundations for long-term success tomorrow, even in an increasingly dynamic threat landscape.


Cyber-attacks are becoming faster, more scalable and more sophisticated. Artificial intelligence (AI) is speeding up attacks even further. Although the threat level is rising, Swiss SMEs are slow to defend themselves in three critical areas.

A representative Deloitte study paints a worrying picture: 49 per cent of employees have experienced a serious cyber incident in the last three months – but only 22 per cent consider the risk to be high. This perception gap is particularly pronounced among micro-enterprises: 38 per cent report incidents, but only 15 per cent see the risk as high.

Three security vulnerabilities

Vulnerability 1: Cyber risks are systematically underestimated

Cyber-threats have become a universal phenomenon. Phishing affects businesses of all sizes – at 25 per cent, it is the most commonly perceived threat, regardless of company size. Scalable attacks via email, compromised login details and manipulated payment processes leave even small businesses vulnerable. Yet many companies still underestimate this vulnerability.

Vulnerability 2: Basic protective measures are not implemented across the board

The Deloitte SME Cyber-security Index measures the prevalence of six elementary security measures and stands at an average of 58 out of 100 points. This indicates that, on average, only 58 per cent of security measures are implemented.

The most significant vulnerabilities concern modern authentication methods:

  • Passwordless authentication (e.g. biometric methods): only 45 per cent of companies
  • Single Sign-On (SSO): only 45 per cent of companies
  • Multi-factor authentication (MFA): 66 per cent – still not universally adopted

Micro-enterprises in particular are falling behind, reaching just 44 points on the index. Training is much less common among micro-enterprises (32 per cent) than among medium-sized enterprises (82 per cent). Only 24 per cent of micro-enterprises carry out phishing tests – compared with 63 per cent of medium-sized enterprises.

However, where measures are in place, they are effective: 88 per cent of respondents whose companies use email alerts consider them to be useful.

Vulnerability 3: Small businesses in particular do not have sufficient insurance cover

The cyber insurance market is growing – but not fast enough. According to the Swiss Insurance Association (SVV), with 72,000 policies, only 11.5% of companies domiciled in Switzerland are insured. The insurance gap is particularly wide among micro-enterprises and small businesses.

It is a paradox: small businesses in particular can be hit hardest by cyber damage in relation to their revenue – yet they are the least likely to be insured. There are many reasons for this:

  • Perception of risk: SMEs underestimate their risk and do not consider insurance to be necessary
  • Failure to meet security requirements: many SMEs do not meet, or do not fully meet, the security requirements needed to support or even obtain cyber insurance cover.
  • Complex processes: application processes are often too time-consuming for small businesses
  • Distribution gap: commissions on cyber insurance policies for micro-enterprises are often quite low, giving insurance advisers little incentive to sell these products.

The threat situation: A tight time frame

The cyber threat landscape has changed fundamentally, with attacks becoming faster and more scalable. There are three mutually reinforcing factors:

  1. Cybercrime is becoming more and more economically relevant and interconnected
    The financial losses are rising sharply: Cybersecurity Ventures expects the global cost of cybercrime to grow by 15 per cent per year1. At the same time, cyber risks are increasingly originating outside organisations – along supply chains and via technology partners. 35.5 per cent of data breaches in 2024 were attributable to third parties.
  2. Artificial intelligence and automation are increasing the speed of attacks
    CrowdStrike reports an 89 per cent increase in AI-enabled attacks for 2026. The average time taken to breach a system (eCrime breakout time) fell to 29 minutes – 65 per cent faster than in 20242. For businesses, this means that the time they have to react is shrinking dramatically.
  3. Complex and outdated IT landscapes make effective defence difficult
    On average, companies run over 1,000 applications, and critical processes often run on software that is decades old3. This complexity makes it difficult to ensure transparency, install updates and respond quickly to new vulnerabilities.

Companies have only a narrow window of opportunity to ensure their technological resilience.

What measures are needed now to keep pace with the growing threat landscape?

Action options for the federal government, businesses, and insurers

State: Creating a framework, empowering businesses

The survey sends a clear signal: 87 per cent of respondents would be in favour of more extensive cyber-security regulations. However, only 19 per cent want stricter, purely state-imposed regulations. Instead, 62 per cent would prefer flexible, industry-led standards or hybrid models.

The federal government should:

  • Set clear minimum standards – such as making multi-factor authentication compulsory for commercial providers
  • Promote transparency and comparability – through widely recognised standards or scoring models
  • Strengthen coordination – so that companies, industry associations, insurers and IT service providers can operate within a common framework.

This would enable Switzerland to position cyber-security as a competitive advantage: flexible enough for innovation, robust enough for resilience.

Businesses: Cyber resilience starts with the basics

For SMEs, there are five specific priorities:

1. Ensure that employees consistently adhere to minimum standards

  • Strong authentication (at least MFA, preferably passwordless authentication)
  • Restricted administrator rights
  • Regular awareness-raising for employees
  • Clear access rights and password rules.

Investing in these basic measures is far less expensive than the cost of a cyber incident.

2. Invest in further security measures

  • Regular, automated backups with recovery capabilities
  • Contingency planning and vulnerability scans
  • Network segmentation and remote access security
  • Systematic replacement of obsolete software and hardware.

3. Do not underestimate the importance of insurance cover

Cyber insurance offers more than just financial protection. It provides access to crisis management, contingency planning and specialists in the event of an emergency. Basic security measures are also important for obtaining more advantageous insurance conditions.

4. Do not manage your IT infrastructure yourself – entrust it to professionals

SMEs should focus on their core competencies and outsource their IT, rather than trying to manage their own infrastructure. Professionally managed IT is often more cost-effective and secure than in-house ad hoc solutions.

5. Protect payment and approval processes from being compromised

Many cases of financial loss suffered by SMEs are caused by tampered invoices and forged payment orders. Companies should establish:

  • Clear dual-control procedures
  • Compulsory call-back procedures when making changes to bank account details
  • MFA for email accounts
  • Regular awareness-raising

Insurers: Close the insurance gap

Simplification and customer-friendliness

Technology-driven risk assessment and simplified application processes instead of complex questionnaires. Fewer technical details, a greater focus on risks and crisis management.

Technology-driven risk assessment

Continuous, automated scans (online footprint, dark web monitoring, vulnerabilities) can supplement one-off surveys. A universal, transparent cyber score ensures greater clarity and comparability.

Prevention and assistance

Contingency planning, technical advice and specialist support services in the event of an emergency set insurers apart and create genuine added value. The assistance component in particular can be more valuable to SMEs than insurance cover alone.

About the study

The Deloitte study ‘Underestimated, unprotected, underinsured: Cyber risks for SMEs in Switzerland’ is based on a representative online survey of 924 employees working for Swiss companies with fewer than 250 employees, all of whom use computers in their work. The survey was carried out in April 2026, and cyber experts from insurance companies were then interviewed in June and July 2026. According to the classification used by the Federal Statistical Office, SMEs are defined as companies with up to 249 employees.

References

1 Cybersecurity Ventures (2025), 2025 Cybersecurity Almanac: 100 Facts, Figures, Predictions And Statistics, 
https://cybersecurityventures.com/cybersecurity-almanac-2025/

2 CrowdStrike (2026), Global Threat Report 2026, https://www.crowdstrike.com/en-us/global-threat-report/

3 MuleSoft (o. J.), Legacy applications can be revitalized with APIs,  https://www.mulesoft.com/legacy-system-modernization/legacy-application

Did you find this useful?

Thanks for your feedback