Back to Blog
Artificial IntelligenceIT Security

AI Is Accelerating Cyberattacks – What Swiss Businesses Need to Know Now

Daniel Da Cruz··5 min read
White robot with human features – representing artificial intelligence and cybersecurity.

Switzerland's Federal Office for Cybersecurity (BACS) made it official in May 2026: advanced AI models are significantly accelerating both the development and execution of cyberattacks. This isn't a future scenario – it's the reality today.

In 2024, BACS registered nearly 63,000 cyber incidents in Switzerland – over 13,500 more than the year before. The curve is pointing sharply upward, and AI is the new accelerant behind it.

What AI Changes in the Context of Cyberattacks

AI doesn't necessarily make attackers smarter. It makes them faster – and dramatically lowers the barrier to entry.

Launching a targeted attack used to require deep expertise: How is the network structured? What software is running? Where are the vulnerabilities? Today, a language model or automated agent can handle all of that.

In practice, this means:

  • Phishing at scale: AI generates personalised, flawless attack emails in any language – in seconds and in unlimited volume
  • Automated vulnerability scanning: AI agents scan systems, connect the dots, and identify attack points that classic scanners miss
  • Social engineering at a new level: According to BACS, over 80% of damage comes not from technical gaps but from manipulation of people – and AI makes that manipulation far more convincing

Who Is Most at Risk?

The short answer: everyone. But Swiss SMEs carry a particular risk.

Large enterprises have dedicated security teams, incident response plans, and automated monitoring systems. Many SMEs don't – and that's exactly what makes them attractive targets. Not because of high value, but because of low resistance.

On top of that: since 1 April 2025, Switzerland requires mandatory reporting of cyberattacks on critical infrastructure – authorities, energy suppliers, healthcare facilities, and many of their suppliers. Failure to report in time risks fines.

What Businesses Should Do Right Now

The good news: solid defence is entirely possible. BACS outlines clear measures – here's the practical take:

1. Keep systems up to date

Apply patches and updates as quickly as possible. Most successful attacks exploit known vulnerabilities – not zero-days.

2. Control access

Least privilege: every person and every system gets only the access it actually needs. Multi-factor authentication everywhere.

3. Train your people

AI-generated phishing emails are no longer identifiable by bad grammar. Regular training and clear processes for suspicious messages are essential.

4. Use Private AI, not Public AI

If your company uses AI – and it should – make sure company data doesn't leave your own environment. Private AI solutions on Microsoft Azure Switzerland North keep data in Switzerland, compliant with Swiss nDSG and EU GDPR.

5. Have an emergency plan

What happens if you're hit anyway? Backups, a communication plan, clear responsibilities. Thinking this through in advance significantly reduces the damage.

How Business IT Partners Can Help

We support Swiss businesses in building practical, effective defences against AI-powered threats:

  • Security assessment: We analyse your existing IT infrastructure, identify exposed endpoints, open ports, and misconfigured services – and deliver a prioritised action plan
  • Private AI implementation: We deploy AI solutions on Microsoft Azure Switzerland North – with a dedicated environment, no data sharing with external model providers, compliant with Swiss nDSG and EU GDPR
  • Identity & access management (IAM): We implement least-privilege concepts, multi-factor authentication (MFA), and Conditional Access policies via Microsoft Entra ID
  • Endpoint & cloud hardening: We harden your servers, cloud workloads, and endpoints against CIS benchmarks and Microsoft Security Baselines – automated and auditable
  • Backup & disaster recovery: We design and implement immutable backups and tested recovery processes so a ransomware attack doesn't become a total loss
  • Employee training: We train your teams to recognise AI-generated attack patterns – phishing, deepfake calls, social engineering, and BEC attacks
  • Incident response planning: We build a practical IR plan with you, including communication templates, escalation paths, and the BACS reporting process

See how a real attack on AI infrastructure unfolded in our article on the McKinsey AI platform hack.

Book a free initial consultation →

Conclusion

AI is a tool – and like any tool, it can be used for attack or defence. Leaving AI only on the attacker's side while doing nothing defensively means losing this arms race.

Swiss businesses serious about IT security need two things: an honest assessment of where they stand today, and the targeted use of AI on the defensive side.


Sources

AI for Your Business

Want to put AI to work in your business?

From AI agents to private AI: we guide you from strategy to implementation — privacy-compliant and tailored to your processes.

Book a Free Consultation

30 min · Free · No obligation

AI consulting for businesses