Intelligence
Swiss intelligence service says most data-leak safeguards are in place
Investigations into alleged data transfers, deletions and links to the Russian cybersecurity firm Kaspersky have led Switzerland’s defence ministry to conclude that most recommended safeguards at the Federal Intelligence Service have been implemented.

Switzerland says intelligence safeguards now largely in place
Most of the safeguards recommended after a series of intelligence scandals are now in place, Switzerland’s Defence Ministry said on September 21, 2026. The assessment follows investigations into alleged data transfers, data deletion and contacts between the former cyber division of the Federal Intelligence Service, or FIS, and Russian cybersecurity company Kaspersky.
The ministry said earlier recommendations had been implemented “in principle”. It also said several investigations had “sufficiently clarified” incidents inside the former unit. The findings give the intelligence service substantial institutional relief after scrutiny of how sensitive information was handled.
The review examined allegations that FIS data moved through Kaspersky to Russian intelligence services. It also considered claims that records had been deleted. Those issues date back to incidents and reports handled by the cyber division since 2001, making the review a long examination of systems, decisions and oversight.
The ministry’s conclusion does not close every file. The alleged collaboration with Kaspersky remains unresolved and is now part of a criminal investigation. Police and the Office of the Attorney General are examining that aspect separately from the administrative and supervisory reviews.
Four reviews test the data leak allegations
Four separate review mechanisms examined the allegations: one internal inquiry, two external inquiries and an audit by the supervisory authority. The breadth of that process reflects the sensitivity of the claims and the importance of independent checks around Switzerland’s intelligence service.
The inquiries focused on the former FIS cyber division, which dealt with cyber incidents and reports over more than two decades. Investigators were asked to establish whether information had been transferred unlawfully, whether data had been erased and whether outside technology providers created channels to foreign intelligence services.
Their findings provide a limited but significant answer on the deletion allegations. The authorities found no evidence of “large scale” data deletion. That wording leaves room for questions about individual records or narrower incidents, but it rejects the most expansive version of the claim made public about the unit.
The Defence Ministry has also said that recommendations from previous reports were generally implemented. The phrase “in principle” is important: it records broad compliance with the proposed safeguards without declaring every operational or legal question settled. The Kaspersky allegations remain outside that conclusion and are moving through the criminal justice system.
Kaspersky allegations remain with prosecutors
The Kaspersky question remains open, and prosecutors now hold the most consequential unresolved thread. Authorities have referred allegations of collaboration between the former FIS cyber division and the Russian cybersecurity company to the police and the Office of the Attorney General.
The allegations concern possible data transfers through Kaspersky to Russian intelligence services. The source material does not establish that such transfers occurred, and the Defence Ministry’s broader review does not settle the matter. A referral for investigation is therefore a procedural step, not a finding of criminal conduct.
The case carries particular weight in Switzerland because intelligence agencies depend on strict control of data, suppliers and technical access. Kaspersky has been the subject of scrutiny in several countries because of its Russian ownership and alleged links to state structures. Swiss officials have also faced questions about contacts with other Russian companies, according to earlier reporting.
The criminal investigation will need to establish what information was exchanged, who authorised any contact, which systems were involved and whether Swiss law was breached. Until that work is complete, the administrative conclusion that most safeguards are in place cannot resolve the central allegations surrounding Kaspersky.
Oversight must now follow the safeguards
Switzerland’s intelligence oversight now faces the task of proving that safeguards work in practice, not only on paper. The Defence Ministry’s statement says recommendations have generally been implemented, giving the FIS a framework for handling sensitive material after years of reported incidents.
That framework will matter as cyber threats intensify and intelligence agencies rely on outside software, contractors and specialist expertise. Controls over procurement, data movement, deletion records and access logs must allow authorities to reconstruct decisions when concerns arise. The investigations show why those records matter: the allegations stretch back to 2001, while the questions about Kaspersky remain active.
The next clear milestone is the outcome of the criminal investigation led through the police and the Office of the Attorney General. Its findings could confirm that the existing safeguards were sufficient, expose gaps that administrative reviews did not identify or clarify the limits of responsibility inside the former cyber division.
For the Swiss public and Parliament, the ministry’s conclusion offers reassurance on large scale deletion claims, while leaving a live accountability issue around alleged cooperation with Kaspersky. The case will remain a test of how Switzerland balances operational secrecy with credible oversight.