Summary
- A survey of 281 Swiss board members found that 41% believe their company has suffered a cyber attack.
- Seventy-four per cent of companies lack an explicit strategy for AI-enabled attacks, while 55% either have no core IT recovery plan or have not tested it.
- Smaller companies account for most of the reported rise in attacks and are less likely than large businesses to have tested recovery plans or dedicated cyber expertise.
Cybersecurity has climbed further up Swiss board agendas without producing the same progress in preparation, with new research finding that almost three-quarters of companies lack an explicit strategy for AI-enabled attacks while incident reporting and recovery readiness remain uneven.
The latest swissVR Monitor, produced with Deloitte Switzerland and Lucerne University of Applied Sciences and Arts, surveyed 281 board members between late May and early July. Some 41% of respondents estimated that their companies had already suffered a cyber attack, 13 percentage points more than three years ago, with most of that rise attributed to small and medium-sized businesses.
Among SMEs, the reported proportion affected rose from 20% in 2023 to 37% in 2026, while the figures for large companies remained steadier at 45% and 48% respectively. Business interruption was the most commonly reported consequence, accounting for 42% of incidents, ahead of data breaches at 22%.
Those numbers come from board-member assessments rather than independently verified incident data, and Deloitte notes that the true level of attack may be higher because half of boards do not receive regular reports on cyber incidents. Even with that limitation, the survey exposes a governance problem: companies increasingly treat cyber resilience as a board issue while still struggling to build the information, expertise, and tested processes needed to supervise it.
AI changes the cost of attack
The clearest new gap appears around artificial intelligence. According to the survey, 74% of companies have no explicit strategy for dealing with AI-enabled cyber attacks, while only 18% of small businesses have made strategic preparations compared with 40% of large companies.
AI does not create an entirely separate category of cyber risk, but it can change the economics of existing attacks by reducing the effort required to research targets, personalise phishing, generate convincing language, or automate parts of reconnaissance and exploitation.
For smaller companies, the imbalance can be particularly severe because attackers can use widely available tools while defenders may have no dedicated security team. A business with a few hundred employees can still hold valuable financial information, customer data, intellectual property, or access into larger supply chains without possessing the specialist staff available to a multinational.
The survey also points to a widening difference in recovery preparation. Fifty-five per cent of companies either have no contingency plan for restoring core IT processes after a serious attack or have not tested the plan they possess. Sixty per cent of large businesses reported tested recovery plans, compared with 32% of small companies.
That distinction is more useful than whether a recovery document exists. Cyber incidents expose dependencies between identity systems, cloud services, networks, applications, suppliers, backups, and communications processes, so a plan that has never been exercised can fail as soon as an organisation discovers that several supposedly independent recovery steps depend on the same unavailable system.
Boards still lack direct cyber expertise
The governance layer shows a similar mismatch between recognition and capability. Although 86% of boards say they follow current cyber developments and 84% have adopted a risk policy covering attacks, 68% have no board member with proven cyber or IT expertise.
Companies can compensate through management teams and external advisers, but boards still need enough understanding to challenge assumptions, determine whether management information is adequate, and distinguish genuine resilience from activity that looks reassuring on a dashboard.
Only half of boards in the survey receive regular information about cyber incidents, while one quarter receive none. Deloitte also reports that information reaching boards about required action and investment, and about the general threat environment, has fallen since 2023 even as respondents report more attacks.
That makes reporting quality an operational issue rather than a presentation issue. A board that receives counts of blocked phishing emails may know the security team is busy without knowing whether critical services could be restored after ransomware, whether identity systems have a tested fallback, or whether a major supplier has become a single point of failure.
The contrast with financial services is instructive. More than two-thirds of financial-service companies in the survey have IT recovery plans, which the researchers associate partly with stronger regulatory expectations. Rules cannot guarantee resilience, although they can force organisations to document responsibilities, rehearse recovery, and provide evidence that controls exist outside policy documents.
Smaller companies face a harder version of the same problem because cyber investment competes with other demands on limited budgets and specialist staff. Outsourcing monitoring, incident response, or security operations can fill capability gaps, but accountability for recovery and business continuity remains inside the organisation.
The research therefore describes a market where awareness has moved faster than operational preparation. As AI reduces some of the effort involved in attacking organisations, the difference between having a cyber policy and being able to recover from an incident is likely to become more visible.












