Twice a year, the NCSC, Switzerland’s national cyber security centre, publishes a report taking stock of the threats it has observed. The most recent, released on 30 March 2026, covers the second half of 2025. It makes useful reading for any executive, because it does not deal in theoretical scenarios: it describes what actually happened in Switzerland.
A threat level judged stable, but high
The first finding is fairly reassuring: the NCSC considers that the overall threat level has remained relatively stable and that the country’s cyber resilience remains robust. There was no collapse, no catastrophic wave.
That does not mean the pressure is easing. On the contrary, the report stresses that attacks are becoming more targeted and more complex. In other words, attackers are professionalising their methods, which means basic defences are outpaced more quickly.
Ransomware remains the most serious threat
Ransomware, the software that encrypts your files and demands a ransom to give you back access to them, continues to rank among the most serious dangers for Swiss organisations. The NCSC recorded 57 incidents of this kind in the second half of 2025.
The report points to an intensification of activity by the Akira group, one of the most active actors over this period, and identifies a vulnerability in SonicWall equipment (a manufacturer of firewalls and network security equipment) as a frequently exploited entry point. This detail is instructive: very often, the attack does not target a human weakness, but a piece of equipment whose updates have been neglected.
The NCSC maintains its recommendation not to pay the ransom. The reasoning is simple: once the payment has been made, nothing guarantees that the criminals will not publish your data anyway, and every ransom paid funds and encourages the attacks that follow.
Phishing techniques that keep reinventing themselves
The report also highlights vishing campaigns and real-time phishing. Vishing, a contraction of “voice phishing”, is phishing by telephone: the attacker calls the victim while posing as a trusted party (a bank, an IT support desk) in order to extract information or push them into acting. Real-time phishing, for its part, allows the attacker to intercept authentication codes at the very moment the victim enters them.
Notably, “SMS blasters” were observed in Switzerland for the first time during the summer of 2025. These are devices capable of sending fake SMS messages en masse to nearby phones, without going through the operators’ network, in order to spread fraudulent links. This is the kind of new threat that catches off guard companies used to email scams alone.
What these figures tell SMEs
Reading this report, one lesson stands out for SME executives. The most frequent attacks do not rely on inaccessible high technology: they exploit equipment that has not been updated, stolen passwords and the trust of employees on the telephone. These are angles that can be reduced.
You can act immediately on several fronts. Keeping your firewalls and network equipment up to date closes a door that the Akira group, among others, knows how to exploit. Making your teams aware that a phone call can be an attack makes them less vulnerable to vishing. Isolating your backups gives you a way out when facing ransomware, without having to negotiate with criminals.
In perspective
These measures genuinely reduce your exposure, and it would be wrong to claim otherwise: you can already do a great deal yourself to limit the damage. But a report like the NCSC’s also shows the limits of the generic approach. Attackers target specific equipment, adapt their techniques and change their methods from one half-year to the next.
Knowing which of these risks truly weigh on your company, which pieces of equipment on your network are your weak point and how to prioritise your security investments calls for a perspective tailored to your concrete situation. This is where a professional assessment takes over from good practice: not to replace it, but to turn general vigilance into protection that genuinely matches your company.