The 3R Group, the Réseau radiologique romand, announced in early May 2026 that it had been the victim of a new IT intrusion that occurred in late April. The company operates around twenty medical imaging centres spread across the cantons of Vaud, Geneva, Valais, Fribourg, Neuchâtel, Bern and Zurich. This is the second time in the space of a year that the network has been affected, the first attack dating back to April 2025.
This incident is not a technical curiosity reserved for specialists. It illustrates mechanisms that concern every company, including the smallest, and is worth pausing over.
What happened, in plain terms
According to the information released, the intrusion caused a partial outage of the group’s IT systems. In practical terms, the twenty centres remained open but with reduced capacity: certain types of examination had to be postponed. An IT intrusion refers to the unauthorised access of a third party to an organisation’s systems, often with the aim of stealing data or blocking its operation.
The company stated that it was not possible, at this stage, to say with certainty whether any data had been stolen. It specified that no ransom would be paid, in line with the authorities’ recommendations, filed a criminal complaint and reported the incident to the National Cyber Security Centre (NCSC, the federal authority that centralises cyberattack reports in Switzerland).
Why the healthcare sector is targeted
Medical centres and hospitals concentrate particularly sensitive data: patient records, medical images, administrative information. This data holds great value for criminals, whether to resell it or to put pressure on the establishment. On top of this comes a constraint specific to the medical field: the interruption of services has direct consequences for patient care, which increases the pressure to restore operations as quickly as possible.
Awareness is real within the sector. As early as September 2025, eighteen university and cantonal hospitals from across Switzerland had founded an association, the Healthcare Cyber Security Center, intended to set up an early-warning system and mutual assistance in the event of an attack. The fact that one network has been hit twice in a year nevertheless shows that vigilance must be permanent, not occasional.
What this says to an SME outside healthcare
You may run an accounting firm, a shop or an engineering office, far removed from the hospital world. The story nevertheless concerns you on several counts.
First, no organisation is too small or too inconspicuous to be targeted. The most common attacks are not targeted: they cast a wide net and strike whoever leaves a door open. Second, if you are a supplier or service provider to a larger organisation, you are part of its supply chain, and therefore of its exposure surface. A weakness on your side can become a point of entry into your client’s.
Finally, the position taken by the 3R Group (not paying a ransom, filing a complaint, reporting the incident) is exactly the one recommended by the Swiss authorities. Paying never guarantees the recovery of data and feeds the criminals’ business model.
The basic measures: useful but not enough
There are measures you can put in place yourself, without a large budget, that genuinely limit the damage: regular backups disconnected from the network (so you can restart even if your systems are locked), two-factor authentication on important accounts (a password supplemented by a temporary code), the systematic updating of software, and regular awareness training for your staff on booby-trapped emails.
These steps are indispensable. But we must be honest: on their own, they are not enough to protect a company. A network of medical centres has far greater IT resources than an ordinary SME, and it was still hit twice. The reason is simple: every company has its own architecture, data flows and dependencies. A list of generic best practices is no substitute for an expert eye that examines your specific weak points.
In conclusion
The attack on the Réseau radiologique romand is a reminder of an uncomfortable reality: the question is not whether an organisation will be targeted, but when, and above all what state it will be in on that day. Doing a great deal yourself is the first step, and it is within your reach. But measuring your real exposure, prioritising the risks specific to your activity and preparing a response in the event of an incident calls for a professional analysis tailored to your situation. It is precisely this assessment work, company by company, that turns goodwill into genuine resilience.