Every week, an article claims that cyberattacks are exploding in Switzerland. Figures circulate, often without a source, sometimes without a date. An SME owner trying to work out where they stand ends up facing a mix of official statistics, commercial estimates and unverifiable claims.
This article cites only figures published by official sources or by studies whose methodology is known. For each one, it states what it actually measures, and above all what it does not measure. That second part is almost always missing, and yet it is precisely what determines what you can conclude from it.
The reference figures
voluntary cyberincident reports received in 2025, compared with 62,954 in 2024
Source: NCSC, semi-annual report 2025/II, published on 30 March 2026
of reports in the second half of 2025 concern fraud, or 15,090 reports
Source: NCSC, semi-annual report 2025/II (July to December 2025)
of Swiss SMEs report having been victims of a serious cyberattack over three years
Source: SME Cybersecurity Study 2025, 515 SMEs surveyed
The first figure is the one most media outlets repeat. It comes from the National Cyber Security Centre, the NCSC, which centralises reports from the public and from businesses. In 2025, it received 64,733, compared with 62,954 the year before. The increase is real, but modest: around 3%.
The second half of 2025 breaks down into 29,006 voluntary reports and 145 mandatory reports. This distinction between voluntary and mandatory is essential, and we return to it further below.
What do Swiss businesses actually report?
The breakdown of reports is more informative than their total. It shows which phenomena actually affect people and businesses on a daily basis.
| Reported phenomenon | Reports in H2 2025 | Share of total |
|---|---|---|
| Fraud (all forms combined) | 15,090 | around 52% |
| Phishing | 6,299 | around 22% |
| Spam | 4,284 | around 15% |
| Ransomware (reported directly to the NCSC) | 57 | less than 1% |
Source: NCSC, semi-annual report 2025/II, covering July to December 2025. The shares are calculated on the 29,006 voluntary reports for the period.
Three lessons follow from this.
Mass-market cybercrime is, first and foremost, fraud. More than one report in two concerns an attempted scam: a fake invoice, fake technical support, a fake online shop, a fake investment. These are attacks that target credulity, not technical flaws. No firewall stops them.
Phishing remains entry point number one. With 6,299 reports, it forms the second category. It is also the one that often precedes the rest: a password stolen by e-mail opens the door to fraud or ransomware. Our article on phishing details the forms these messages take.
Ransomware is rare in number, decisive in consequences. Only 57 incidents were reported directly to the NCSC in the second half of 2025. The Akira variant, already leading in the first half, consolidated its position. This low volume should not be reassuring: an SME hit by ransomware can find itself completely at a standstill for days.
The special case of CEO fraud
One threat deserves to be singled out, because it specifically targets businesses rather than the general public. CEO fraud consists of impersonating an executive in order to obtain an urgent transfer from an employee in the finance department.
Swiss businesses filed 605 reports of this type in the first half of 2025, a record number, then 366 in the second half. The drop in the second period does not mean the phenomenon is durably declining: these half-yearly variations often follow the campaigns run by criminal groups.
This is the figure that should catch the attention of an SME owner, because it matches exactly the risk profile of a small structure: few hierarchical levels, an accountant who knows the boss personally, and a culture where a request from management is not questioned. The mechanism is described in detail in our article on CEO fraud.
What are the limits of these figures?
This is the most important section of this article. These statistics are the best Switzerland has available, but they do not measure what many people believe they measure.
The 64,733 reports for 2025 are, in their overwhelming majority, voluntary. No one obliges an SME to report an incident. The real number of incidents occurring in Switzerland is therefore necessarily higher, and no reliable method can quantify this gap. A report also does not mean that an attack succeeded: many reports concern attempts spotted in time.
Four biases stack up, and you need to keep them in mind before citing these statistics.
The voluntary nature of reporting. A company that suffers an attack has no general obligation to say so. Many do not, out of fear for their reputation, fear of losing customers or partners, because they are unaware that a reporting channel exists, or because they would rather resolve the problem quietly with their IT provider.
Incidents that are never detected. You can only report what you have seen. Fraudulent access to a mailbox can last for months without anyone noticing. The statistics capture only the visible part.
The awareness effect. A rise in reports can reflect a rise in attacks, but also better awareness of the reporting mechanism. Prevention campaigns mechanically increase the number of reports. It is impossible to disentangle the two effects with certainty.
The absence of grading. A report for a phishing e-mail deleted in three seconds counts just as much, in the total, as a report for ransomware that paralysed a company. The total says nothing about severity.
These limits do not make the figures useless. They simply require reading them as an indicator of trend and threat structure, not as an exhaustive count.
The reporting obligation does not apply to your SME
Since 1 April 2025, critical infrastructure operators have been required to report cyberattacks to the NCSC. The legal basis is the Information Security Act, the ISA. Penalties for non-compliance have applied since 1 October 2025.
This point is regularly misunderstood, including in the press.
The ISA's reporting obligation targets only critical infrastructure operators: administrations, energy, transport, healthcare, telecommunications, and the financial sector in particular. A trust company, a garage, an independent medical practice or an industrial SME are not covered by this law. They may report voluntarily, and this is useful, but they are not required to.
The breakdown of the 145 mandatory reports for the second half of 2025 confirms this scope: 25% came from the public sector, 18% from IT and telecommunications, and 15.7% from finance and insurance.
One important nuance remains. Not being subject to the ISA does not mean having no obligations at all. The Federal Act on Data Protection (FADP) requires notifying the FDPIC of personal data security breaches that pose a high risk to the people concerned. This regime is independent of the ISA and applies to all companies. We cover this in detail in your FADP obligations.
What do Swiss SMEs think of their own protection?
Reports to the NCSC describe the threats. They say nothing about companies’ preparedness. For that, you need to turn to the SME Cybersecurity Study 2025.
Its methodology is public, which is rare and worth highlighting: a survey conducted from 25 June to 5 August 2025 among 515 SMEs with 1 to 49 employees and 336 IT service providers, at the initiative of the Swiss Digital Security Alliance together with La Mobilière, digitalswitzerland, FHNW, HES-SO Valais-Wallis, ISSS, SATW, SISA and YouGov Switzerland.
Four findings emerge from it.
4% of the SMEs surveyed report having suffered a serious cyberattack over the past three years. The figure looks low. However, it covers serious, reported attacks, in very small companies, many of which lack the means to detect a discreet incident.
42% consider themselves sufficiently protected, down from 55% the previous year. This drop in confidence can be read in two ways: either SMEs are objectively less well protected, or they have a better grasp of what they do not know. The second reading would actually be good news.
28% no longer consider the subject a priority, up from 18%. This increase is the most worrying signal in the study. Attention is fading.
88% consider cybercrime a serious problem. The gap with the previous figure sums up the situation of many French-speaking Swiss SMEs: the risk is recognised in principle, but it does not translate into concrete action.
What should a business owner take away from this?
Three conclusions emerge from all this data, and none of them depends on a debatable estimate.
Your main risk is not technical, it is human. Fraud and phishing together account for nearly three-quarters of reports. These attacks go through your employees, not through a flaw in your server. Raising your team’s awareness therefore delivers a better return than any hardware purchase.
The statistic that concerns you the most is the one nobody publishes. It is not the national number of attacks, it is your ability to get back up and running. How long would your company remain at a standstill if your data were encrypted tomorrow morning? The answer depends on your backups, and on the last time you tested them. See the 3-2-1 backup rule.
The absence of a legal obligation is not a reason to report nothing. A report to the NCSC costs nothing, contributes to national knowledge of threats and gives you access to recommendations. It is also one of the reflexes to have during the first hours of an incident.
To concretely position your company against these findings, the cyber check-up assesses your main weak points in a few minutes. All the threats described here are covered in detail in the Threats pillar.