Swiss population neglects cyber protection

According to the 2024 Cyber Study, 24,000 Swiss SMEs have fallen victim to a cyberattack over the past three years. The public perceives cybercrime as a threat—but neglects to take protective measures.

(Iconic image: Unsplash.com)

In the past three years, one in twenty people in Switzerland has been the victim of a cyberattack. This is revealed in the latest edition of the Cyber Study 2024, which sheds light on the digital security awareness of SMEs, the population and IT service providers in Switzerland.

The study was commissioned by Digitalswitzerland together with Mobiliar, the Swiss Digital Security Alliance (ADSS), the University of Applied Sciences Northwestern Switzerland (FHNW), the Swiss Academy of Engineering Sciences (SATW) and the Swiss Internet Security Alliance (SISA). It was carried out by YouGov. The organizations presented the results of the study in a video conference.

The risk assessment of SMEs, IT service providers and private individuals. (Image: zVg.)

Despite the growing threat of cybercrime, many of those surveyed take insufficient protective measures, as the study shows. Four percent of the SMEs surveyed had fallen victim to a cyberattack in the past three years. This equates to around 24,000 companies in Switzerland. Of these companies, 73 percent suffered considerable financial damage. Nevertheless, more than half of SMEs consider the risk of a serious attack to be low. Among IT service providers, this figure is 68% of those surveyed.

Lack of emergency plans and safety concepts

It is worrying that four out of ten companies do not have an emergency plan in the event of a serious cyberattack. In addition, many SMEs are hesitant when it comes to using digital tools such as password managers or biometrics. There is also a need to catch up when it comes to implementing security concepts and staff training.

SMEs often lack an idea of the skills attackers have and what their motives are, explained Simon Seebeck, Head of the Cyber Risk Competence Center at Mobiliar, during the press conference. "There is a lack of understanding of what it can mean to find yourself in the clutches of cyber criminals and what damage you can suffer." This is because the topic is complex and difficult to grasp.

How do companies protect themselves against this? According to Seebeck, there is still a greater need for action when it comes to organizational measures than technical ones. These are often outsourced to an IT service provider. Andreas Kaelin, co-founder and Managing Director of ADSS, addressed this topic.

"Less than half of SMEs can confirm that their IT service providers are cyber-certified. So in principle, more than half of SMEs trust their IT service providers blindly," said Kaelin. He then went back to promoting the Cyberseal. This is a seal of approval from the ADSS that demonstrates expertise in the area of cybersecurity. In contrast to the ISO 27001 certificate, for example, it would focus on technical and less on organizational aspects.

The advantages of cybersealing according to Kaelin. (Image: zVg.)

False sense of security among private individuals

Private individuals often rate their cyber security higher than it actually is. Five percent of respondents have been affected by a cyberattack in the past three years. However, the majority believe that they have a good to very good knowledge of how to protect themselves against cyber attacks. However, according to the study, this assessment is at odds with the actual behavior of the respondents. For example, over a third of them would use the same password for different services and wait with updates.

"We all risk falling victim to a cyber attack every day," said Seebeck. "The risk of being damaged by a fire or a weather risk is much lower." Despite this significant threat, respondents felt fairly safe. "According to the Mobiliar Digital Barometer, however, around 30 percent of the population lack basic digital skills, which means they lack the basis for safe behavior in the digital space," said Seebeck.

Awareness-raising and training are crucial to improving cyber security. 62 percent of those surveyed stated that they were interested in improving their skills. "It remains to be seen whether this interest will be actively implemented," said Seebeck. However, there would be no lack of information formats. "The gap between the threat situation and ignorance regarding cyber threats is problematic."

When it comes to online shopping, 72% of respondents rarely or never worry. 13 percent of those surveyed stated that they had actually experienced paying for something they did not receive in the past five years. Almost two thirds of respondents would like to be better informed about how they can protect themselves online. However, there is a lack of willingness or ability to take action, they say.

AI on both sides

During the press conference, the companies also addressed the topic of artificial intelligence. This is used on both sides of the fronts. "AI is used by cyber criminals to scale attacks. This means that the attackers' business case also works for attacks on small targets and they earn money," said Seebeck.

Nicole Wettstein, Head of Tech Intelligence and Cybersecurity Program Manager at SATW and Vice President of ITsec4KMU, showed the other side of AI. "IT service providers in particular, but also parts of the population, have used AI so far, at least on a trial basis," she said. Among IT service providers, the proportion is just under 70 percent, compared to just under 40 percent of the population. SMEs are much more reticent, with a share of 20 percent.

According to Wettstein, SMEs and IT service providers use AI primarily for text generation, information procurement and software development. However, AI is also an important tool for cyber security. "It helps to identify threats, prevent them and respond to them quickly. However, this tool is still only being used by a minority of IT service providers and SMEs." Just 6 percent of SMEs would use AI in this way. "There is therefore still room for improvement in the use of AI to improve cyber security." (Coen Kaat/NetzKI Bot)

The use of AI according to the study. (Image: zVg.)

The study was conducted throughout Switzerland from July 4 to August 5, 2024. The SME sample comprised 526 interviews, the population sample 1247 interviews and the sample of IT service providers 401 interviews.

This article first appeared in Netzwoche.

More articles on the topic