cybersecurity
Swiss companies are unprepared for AI-enabled cyberattacks
A SwissVR Monitor finds that 74% of Swiss companies have no explicit strategy for AI-enabled cyberattacks, while many lack tested recovery plans. The article would examine the specific vulnerabilities facing SMEs, the responsibilities of company boards and the steps businesses should take before an AI-assisted attack occurs.

Swiss Firms Face an AI Security Gap
74% of Swiss companies have no explicit strategy for AI-enabled cyberattacks. That finding from the latest SwissVR Monitor places a clear weakness in the country’s corporate defenses as criminal groups increasingly use artificial intelligence in their operations.
The study, published on September 16, 2026, points to a gap between the speed of technological change and the way companies manage risk. Artificial intelligence can increase the scale and speed of criminal activity, while many businesses still lack a documented response specifically aimed at AI-assisted attacks.
The exposure matters across Switzerland’s economy. Companies depend on digital systems for payments, logistics, production, customer records and communications. A disruption in one of those systems can quickly affect suppliers, employees and clients, even when the original breach begins with a single compromised account.
The SwissVR Monitor also identifies weaknesses beyond prevention. 55% of companies have no contingency plan, or have plans that have not been tested, for restoring essential IT processes. A response document that has never been rehearsed may leave staff uncertain about who makes decisions, which systems come first and when outside help should be called.
Why SMEs Have Less Room for Error
Only 18% of small businesses say they are prepared, compared with 40% of large companies. The difference highlights the particular burden facing Swiss SMEs, which often operate with smaller IT teams, limited security budgets and less capacity to run repeated exercises.
Size does not determine whether a company will be targeted. An SME may hold valuable customer information, connect to a larger supplier or provide a service that another business cannot easily replace. Its systems can also offer criminals a route into a broader commercial network.
The SwissVR findings do not identify a single technical weakness shared by every small company. They do show that preparedness remains uneven. For an SME, the first practical step is to identify its most important processes and the systems behind them. Leaders need a current list of critical accounts, suppliers, data stores and recovery contacts.
Companies should also limit unnecessary access, require strong authentication, keep software updated and separate backups from the systems they protect. These measures do not eliminate risk. They give a business more options when an attacker compromises an account, disrupts operations or demands a rapid decision.
Put Cyber Risk on the Board Agenda
Only one in two board members is regularly informed about cybersecurity incidents. That figure puts governance at the centre of the preparedness problem. Cybersecurity decisions compete with investment, staffing and growth priorities, but a board cannot assess operational risk without regular, clear reporting.
Directors do not need to manage firewalls or investigate every alert. They do need to know which business services are most exposed, how quickly the company can restore them, who has authority during an incident and whether previous exercises uncovered unresolved problems.
Management should give the board a concise risk picture at regular intervals. It should include significant incidents and near misses, the status of critical suppliers, unresolved vulnerabilities, backup performance and results from recovery tests. Reports should distinguish between policies that exist on paper and controls that have worked under pressure.
The board also needs to confirm who leads the response. Legal, communications, IT, human resources and operational managers may all have roles. Clear escalation rules can prevent delays when systems fail or sensitive information may have been exposed. The SwissVR findings show why this oversight cannot remain an occasional agenda item.
Test Recovery Before Attackers Arrive
55% of companies lack a tested route back to essential IT operations. That weakness can turn a security incident into a prolonged business interruption. Recovery planning must cover more than data backups. It should explain how staff will work, communicate with customers, verify transactions and restore priority services if normal systems become unavailable.
A credible plan begins with an inventory of essential processes and their dependencies. Companies should define recovery priorities, acceptable downtime and decision-making authority. They should test backups, confirm that restoration procedures work and involve the employees and suppliers who would be needed during an outage.
Exercises should include realistic complications, such as a compromised administrator account, unreliable internal communications or uncertainty about which data can be trusted. After each test, management should record failures, assign owners and set deadlines for corrective action.
Swiss companies also need a clear incident reporting process. The SwissVR Monitor found that board information is inconsistent, and internal confusion can slow technical and legal decisions. Before an attack, businesses should establish trusted contacts for IT support, insurers, legal advice and relevant authorities. Preparation will not prevent every intrusion, but it can reduce the time between detection, containment and recovery.