Main findings
In the age of artificial intelligence, cyber-security is becoming a crucial factor in competitiveness and resilience.
Organisations that consistently invest in risk awareness, modern security architectures, organisational resilience and collaborative partnerships today are laying the foundations for long-term success tomorrow, even in an increasingly dynamic threat landscape.
Cyber-attacks are becoming faster, more scalable and more sophisticated. Artificial intelligence (AI) is speeding up attacks even further. Although the threat level is rising, Swiss SMEs are slow to defend themselves in three critical areas.
A representative Deloitte study paints a worrying picture: 49 per cent of employees have experienced a serious cyber incident in the last three months – but only 22 per cent consider the risk to be high. This perception gap is particularly pronounced among micro-enterprises: 38 per cent report incidents, but only 15 per cent see the risk as high.
Cyber-threats have become a universal phenomenon. Phishing affects businesses of all sizes – at 25 per cent, it is the most commonly perceived threat, regardless of company size. Scalable attacks via email, compromised login details and manipulated payment processes leave even small businesses vulnerable. Yet many companies still underestimate this vulnerability.
The Deloitte SME Cyber-security Index measures the prevalence of six elementary security measures and stands at an average of 58 out of 100 points. This indicates that, on average, only 58 per cent of security measures are implemented.
The most significant vulnerabilities concern modern authentication methods:
Micro-enterprises in particular are falling behind, reaching just 44 points on the index. Training is much less common among micro-enterprises (32 per cent) than among medium-sized enterprises (82 per cent). Only 24 per cent of micro-enterprises carry out phishing tests – compared with 63 per cent of medium-sized enterprises.
However, where measures are in place, they are effective: 88 per cent of respondents whose companies use email alerts consider them to be useful.
The cyber insurance market is growing – but not fast enough. According to the Swiss Insurance Association (SVV), with 72,000 policies, only 11.5% of companies domiciled in Switzerland are insured. The insurance gap is particularly wide among micro-enterprises and small businesses.
It is a paradox: small businesses in particular can be hit hardest by cyber damage in relation to their revenue – yet they are the least likely to be insured. There are many reasons for this:
The cyber threat landscape has changed fundamentally, with attacks becoming faster and more scalable. There are three mutually reinforcing factors:
Companies have only a narrow window of opportunity to ensure their technological resilience.
Action options for the federal government, businesses, and insurers
The Deloitte study ‘Underestimated, unprotected, underinsured: Cyber risks for SMEs in Switzerland’ is based on a representative online survey of 924 employees working for Swiss companies with fewer than 250 employees, all of whom use computers in their work. The survey was carried out in April 2026, and cyber experts from insurance companies were then interviewed in June and July 2026. According to the classification used by the Federal Statistical Office, SMEs are defined as companies with up to 249 employees.
References
1 Cybersecurity Ventures (2025), 2025 Cybersecurity Almanac: 100 Facts, Figures, Predictions And Statistics,
https://cybersecurityventures.com/cybersecurity-almanac-2025/
2 CrowdStrike (2026), Global Threat Report 2026, https://www.crowdstrike.com/en-us/global-threat-report/
3 MuleSoft (o. J.), Legacy applications can be revitalized with APIs, https://www.mulesoft.com/legacy-system-modernization/legacy-application