Thanks to AI, cyberattacks are becoming faster and can be deployed at greater scale. At the same time, many Swiss SMEs remain insufficiently protected and underinsured. This is the conclusion of a representative survey conducted by Deloitte among employees of Swiss SMEs: many companies underestimate the risks and do not systematically implement basic protective measures. In addition, small businesses in particular are still far too unlikely to have cyber insurance.
The cyber threat landscape for Swiss businesses is deteriorating markedly. Cyberattacks are rising sharply and, thanks to artificial intelligence (AI), are becoming increasingly targeted and effective. Small and medium-sized enterprises (SMEs) are especially exposed: they often have fewer resources, underestimate the risks they face, implement fewer cybersecurity measures and are also less well insured. That is the finding of a study on the cybersecurity of Swiss SMEs conducted by audit and advisory firm Deloitte.
The findings point to a significant gap between the cyber threats companies are actually facing and their perception of risk (see figure 1): 49% of SME employees surveyed have experienced a serious cyber incident at their employer over the past three months, yet only 22% believe the cyber risk facing their company is high. This perception gap is particularly pronounced among microenterprises with between 1 and 9 employees: while 38% report serious cyber incidents, only 15% consider the risk of cyberattacks to be high.
Phishing affects companies of all sizes
Phishing — the attempt to steal data or trigger payments using fraudulent messages — is the most frequently reported cyber threat, at 25%. Strikingly, phishing is almost as common in microenterprises as it is across SMEs as a whole. This clearly shows that even very small companies are exposed to cyber risk. Employees also report malware, CEO fraud, identity theft, suspected data leaks and business disruption. These risks affect companies of every size.
“Many SMEs underestimate just how far cyberattacks have evolved. Today, attacks can be carried out at scale, they are automated and they affect companies of every size. Phishing, compromised credentials or manipulation of payment processes, in particular, can have serious consequences even for small businesses,” says Florian Widmer, Cyber Risk partner at Deloitte Switzerland. “An organisation’s ability to withstand cyberattacks therefore starts with the basics: strong authentication, restrictive access rights, regular training, tested backups and a robust emergency plan.”
Basic security measures are not yet universal
Deloitte’s SME cybersecurity index, published for the first time on the basis of this study, measures the extent to which six fundamental people-related security measures have been adopted and stands at 58 points out of 100 (see figure 2). In other words, the relevant security measures are, on average, implemented to only 58% of their full extent, revealing a significant gap in basic protections.
The weaknesses are particularly evident in modern authentication methods. Only 45% of companies have introduced passwordless authentication methods such as biometric techniques. Multifactor authentication is more widespread at 66%, but it is still far from universal. At the same time, where measures are in place, employees view them as effective: 88% of respondents whose company uses email alerts find them useful. The survey measures employees’ perceptions, not actual effectiveness. It also shows that not all companies are yet using this type of warning system.
Insurance coverage remains patchy
Beyond risk awareness and the implementation of protective measures, Deloitte’s study highlights a third shortcoming: insurance coverage. While cyber insurance is gaining ground in Switzerland, market penetration remains low. According to recent figures from the Swiss Insurance Association (SIA), around 72,000 business policies had been taken out in 2025. As a result, only 11.5% of companies domiciled in Switzerland are insured against cyber risk.
Insurance coverage is particularly weak among micro and small enterprises. Yet these are precisely the businesses that can be hit hardest by cyber incidents, because the damage can weigh more heavily relative to their turnover. Many SMEs, however, do not have the basic security measures required to take out cyber insurance. Other factors also make access to cyber insurance more difficult, including the complexity of underwriting procedures and limited commercial appeal, as commissions paid on cyber policies are often modest for small businesses.
“For SMEs, cyber insurance is useful well before a cyberattack occurs,” says Marcel Thom, partner in Deloitte Switzerland’s Insurance practice. “Its added value lies in combining prevention, rapid emergency support and financial protection. Small businesses in particular need clear products, transparent requirements and simple, digitally supported underwriting processes. That is how cyber insurance can become a central element of business resilience.”
Stricter requirements, but no heavy-handed regulation
The study also reveals clear expectations regarding the role of the state. 87% of respondents support stronger cybersecurity requirements. At the same time, only 19% back stricter, purely state-imposed minimum standards. For Switzerland, this points to a pragmatic mandate: the Confederation should set clear minimum standards and facilitate cooperation between companies, trade associations, insurers and IT service providers.
Deloitte’s study “ Under-estimated, unprotected, under-insured : cyber risks for SMEs in Switzerland ” is based on a representative online survey of 924 employees of Swiss companies with up to 249 staff, all of whom use a computer as part of their work. The survey was conducted in April 2026. In addition, interviews were held in June and July 2026 with cybersecurity experts from the insurance sector. According to the classification of the Federal Statistical Office, companies with up to 249 employees are considered SMEs.
Find all our Strategic Case articles