Cyber risks: Swiss SMEs underestimate the dangers

A VZ-HSLU analysis indicates that cyber incidents are the top global risk: nearly 58'000 digital crimes in Switzerland in 2025.
Context
TL;DR
- SMEs still underestimate cyber risks
- Allianz ranks them first globally in 2026
- Nearly 58'000 digital crimes in Switzerland in 2025
- Just under 12% of companies have coverage
Key facts
- Study → VermögensZentrum and HSLU
- Risk Barometer 2026 → cyber incidents in first place
- Global costs in 2024 → approximately 9,5 trillion US dollars
- Digital crimes in Switzerland in 2025 → nearly 58'000
- Resolution rate → 17,6%
- Coverage in Switzerland → just under 12%
The danger does not remain in the IT department
Nearly 58'000 crimes committed using digital means were recorded in Switzerland in 2025. The crime statistics cited by VZ add a high number of unreported cases, while the resolution rate stood at 17,6%.
This is the Swiss picture highlighted by the study published today by VermögensZentrum in collaboration with Lucerne University of Applied Sciences and Arts, HSLU. The research starts from a belief still held by many small and medium-sized enterprises: that they are not affected by cyber threats. For VZ and HSLU, this assumption is dangerous.
The reason given is that the consequences go beyond the IT sphere. An attack can disrupt operations, damage data and systems, jeopardize customer relationships, trigger legal obligations or put a company's liquidity under severe strain. In the worst-case scenario, the very existence of the SME is at stake.
VZ points to Allianz's Risk Barometer 2026, which for the fifth consecutive time ranked cyber incidents first among business risks globally. Estimates of the costs caused by cybercrime worldwide in 2024 reach approximately 9,5 trillion US dollars. If it were a national economy, cybercrime would be the world's third-largest, after the United States and China.
From perception to management
VZ and HSLU wanted to understand how SMEs can properly understand, classify and insure against cyber risks as part of effective management. The study starts from a precise limitation: cyber threats cannot be avoided entirely. Management therefore requires greater knowledge of digital dependencies, clarified responsibilities, emergency procedures and a conscious assessment of the financial consequences. This approach links cyber risk to the overall management of the company, not to a single department.
Operational details
Risk should be understood as a business issue
The most useful piece of information for an SME, in the reading proposed by VZ and HSLU, is not merely the existence of a cyber threat. It is the way in which an attack can shift the problem from a single system to the entire business. The source encourages understanding and classifying risks precisely because the consequences can affect operations, data, customers, legal obligations and liquidity.
A map of the consequences
| Affected element | Effect indicated by the source |
|---|---|
| Operations | Disruption |
| Data and systems | Damage |
| Customer relationships | Compromise |
| Legal obligations | Possible activation |
| Liquidity | Pressure |
This map helps avoid two opposite mistakes. The first is to treat the incident as an issue confined to IT, ignoring the financial side and customer relationships. The second is to rely solely on the policy, even though the study considers insurance a fundamental component. Coverage, however, does not replace prevention or effective hazard management.
For those managing an SME, the question is not whether the risk can be eliminated: the study says that cyber threats cannot be avoided entirely. The question becomes which digital dependencies the company knows about, which responsibilities have been clarified and which emergency procedures have been prepared. At that point, the assessment must reach the financial consequences.
The Swiss figure on coverage remains the one indicated by the study: just under 12% of companies have coverage. The percentage should be read together with the other indication from VZ and HSLU: insurance is a fundamental component, but it does not replace prevention and effective management. For a separate reference on personal expenses, costo della vita in Svizzera is available.
The internal review can start with the effect and work back to the dependency that generates it. If operations are interrupted, the consequence for business functioning is examined; if data and systems are damaged, what is involved is clarified; if customers are affected, the relationship is considered; if legal obligations or pressure on liquidity emerge, the assessment moves beyond purely technical language. This is the distinction between technology and management that the study asks SMEs to make.
Recommended tools
For an updated estimate, use the net salary calculator and the CHF-EUR exchange comparator.
Key points
A five-step internal procedure
The study does not propose eliminating risk, but indicates how to manage it better. The guidance can become a concrete workflow for an SME.
1. Map digital dependencies. Start with the systems and data on which the business depends. Knowledge of these dependencies is the starting point the study identifies for better risk management.
2. Clarify responsibilities. Define who handles the various steps in managing cyber risks, so that the issue has an internal point of reference.
3. Prepare emergency procedures. Organize the response to business interruption and damage to data and systems described in the research.
4. Assess the financial consequences. Consciously consider liquidity, customer relationships and any legal obligations that may result from an attack.
5. Examine insurance. Coverage against cyber risks is a fundamental component, but it must be accompanied by prevention and effective risk management.
A choice that does not replace prevention
The fifth step does not mean shifting all responsibility to the policy. According to VZ and HSLU, insurance replaces neither prevention nor effective management. The Swiss figure, with just under 12% of companies having coverage, indicates that insurance protection should be considered within overall management and not in isolation.
The process also serves to distinguish technical severity from business impact. A damaged system or piece of data can be assessed based on its effect on the business; a compromise of customer relationships must be considered together with legal obligations; pressure on liquidity forms part of the financial assessment. These are the effects described by the source, rearranged into an operational sequence.
For the banking aspect of liquidity management, consult conti bancari in Svizzera. To complement the business analysis with a review of personal finances, use calcolatore stipendio/imposte.
Source: swissinfo.ch
Frequently Asked Questions
- Why do cyber risks affect the entire SME?
- According to the VZ-HSLU study, the consequences of an attack go beyond IT. They can disrupt operations, damage data and systems, compromise customer relationships, trigger legal obligations and put liquidity under severe strain. In the worst-case scenario, the very existence of the SME is at stake. That is why the risk becomes part of business management; it does not remain confined to technology.
- How many digital crimes have been recorded in Switzerland?
- The crime statistics cited by VZ recorded almost 58'000 offences committed using digital means in 2025. The source also reports a high number of unreported cases. The resolution rate was 17,6%. VZ reports these figures to describe the state of digital crime in Switzerland.
- Is cyber risk insurance enough?
- No. The study describes insurance as a fundamental component, but specifies that it does not replace prevention or effective hazard management. In Switzerland, to date, just under 12% of companies have such coverage. The policy should therefore be considered alongside an understanding of digital dependencies, responsibilities, and emergency procedures.
- What should SMEs do according to VZ and HSLU?
- Companies should have a better understanding of their digital dependencies, clarify responsibilities, prepare emergency procedures, and consciously assess financial consequences. The study aims to understand how to properly comprehend, classify, and insure cyber risks as part of effective management. Dangers cannot be avoided entirely, but they can be managed better.
Related articles
- All articles: Safety and crime
- Attacco informatico al fornitore software di Publica
- Modifica dell'ordinanza sulla liquidità: il Consiglio federale estende il potenziale di approvvigionamento di liquidità attraverso le banche centrali.
- TranspaReg: Quadri chiede rinvio per rischio informatico
- Sviluppatore informatico in Ticino: guida per frontalieri
- UBS sotto pressione: capitale al 90% per filiali estere