SMEs bear brunt of rising cyber attacks as most boards lack AI strategy

74% of Swiss companies have no strategy against AI-driven cyberattacks, even as the share of small firms hit nearly doubled from 20% to 37% in three years.

Published on: Sep 16, 2026
SMEs bear brunt of rising cyber attacks as most boards lack AI strategy

Cybercriminals are using AI to launch more frequent and damaging attacks, yet 74% of Swiss companies lack a dedicated strategy to counter these threats. The gap between escalating risk and boardroom preparedness is widest among small and medium-sized enterprises (SMEs), where the proportion hit by cyber-attacks nearly doubled in three years, jumping from 20% in 2023 to 37% in 2026.

The findings come from the 20th swissVR Monitor, a survey of 281 board members conducted by the swissVR association, Deloitte, and the Lucerne University of Applied Sciences and Arts. Overall, 41% of companies reported falling victim to a cyber-attack, up 13 percentage points from three years ago. Large companies saw attack rates hold steady at 45% in 2023 and 48% in 2026, meaning the surge is concentrated almost entirely in smaller firms.

Boards prioritize cyber but lack specialist knowledge

IT and security management now ranks among the top ten strategic priorities for boards over the next twelve months. Business interruptions were the most common consequence of an attack, cited in 42% of cases, followed by data breaches at 22%. The real number of incidents is likely higher. Only half of all boards receive regular reports on cyber incidents, according to the survey.

Board-level expertise remains thin. 68% of boards have no member with proven cyber or IT knowledge, relying instead on senior management or external specialists. Klaus Julisch, Cyber-Security Lead at Deloitte Switzerland, said the criminal use of AI is multiplying damage potential. "Cyber risks are soaring, multiplying the potential for damage - with consequences that many companies, and indeed the public sector, still underestimate," he said.

Recovery planning and reporting gaps persist

Preparations for serious incidents show similar weaknesses. 55% of companies either have no contingency plan or have not tested their plan to restore core IT processes quickly after a major attack. Large companies are twice as likely as small firms to have tested recovery plans, at 60% versus 32%. Financial service providers stand out as an exception. Over two-thirds have IT recovery plans in place, a readiness Mirjam Gruber-Durrer, Professor of Normative Board Management at the Lucerne University of Applied Sciences and Arts, attributes to stricter regulation. "The sector forms part of Switzerland's critical infrastructure, and security standards are therefore much more firmly established," she said.

Reporting to the board has actually declined in key areas since 2023, even as attacks increased. Reports on the need for action and investment dropped by 18 percentage points, and reporting on the general threat situation fell by 13 points. Isabelle Amschwand, President of swissVR, said defining a clear cyber strategy is a core management responsibility. "Cyber resilience is part of risk management and is therefore an ongoing management responsibility that belongs on the risk dashboard and the board of directors' agenda," she said.

AI-specific strategies remain rare

Only 18% of small businesses have made strategic preparations for AI-based attacks, compared to 40% of large companies. The overall figure of 26% with a strategy leaves a large majority of organizations exposed to threats that use AI to automate and scale attacks. For executives and board members, understanding these risks is becoming a governance requirement, not just a technical concern. Resources on AI for Executives & Strategy address how leadership teams can build this understanding into their oversight role.

Testing crisis management processes has improved, with half of boards now running exercises, up from 34% three years ago. But the survey makes clear that many boards are still operating without the specialist knowledge, tested plans, or consistent reporting needed to govern cyber risk effectively. For cybersecurity professionals tasked with defending against AI-driven threats, structured skill-building paths such as AI for Cybersecurity Analysts can help close the capability gap that boards are struggling to address.

Why this matters for executives and strategy leaders

The data shows a direct line from boardroom inattention to operational damage. When half of boards do not receive regular incident reports and two-thirds lack a member with cyber expertise, the organization is making risk decisions blind. For executives, the immediate step is not to become technical experts but to demand a tested Minimum Viable Company recovery plan and a reporting cadence that puts cyber risk on the dashboard alongside financial and compliance risks. Without those, the board cannot fulfill its supervisory duty on what has become a top-ten strategic threat.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)