Solutions
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21.25 12C21.25 13.2426 20.2426 14.25 19 14.25C17.7574 14.25 16.75 13.2426 16.75 12C16.75 10.7574 17.7574 9.75 19 9.75C20.2426 9.75 21.25 10.7574 21.25 12Z" stroke="black" stroke-width="1.5"/><path d="M7.25 12C7.25 13.2426 6.24264 14.25 5 14.25C3.75736 14.25 2.75 13.2426 2.75 12C2.75 10.7574 3.75736 9.75 5 9.75C6.24264 9.75 7.25 10.7574 7.25 12Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 16.1143C15.4512 15.4931 16.827 15.8617 17.4482 16.9377C18.0694 18.0137 17.7008 19.3895 16.6248 20.0107C15.5488 20.6319 14.173 20.2633 13.5518 19.1873C12.9306 18.1113 13.2992 16.7355 14.3752 16.1143Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 3.98927C8.45117 3.36805 9.82701 3.73671 10.4482 4.81269C11.0694 5.88867 10.7008 7.26451 9.62481 7.88573C8.54883 8.50695 7.17298 8.13829 6.55177 7.06231C5.93055 5.98633 6.29921 4.61048 7.37519 3.98927Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 20.0107C6.29921 19.3895 5.93055 18.0137 6.55177 16.9377C7.17298 15.8617 8.54883 15.4931 9.62481 16.1143C10.7008 16.7355 11.0694 18.1113 10.4482 19.1873C9.82701 20.2633 8.45117 20.6319 7.37519 20.0107Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 7.88573C13.2992 7.26451 12.9306 5.88867 13.5518 4.81269C14.173 3.73671 15.5488 3.36805 16.6248 3.98927C17.7008 4.61048 18.0694 5.98633 17.4482 7.06231C16.827 8.13829 15.4512 8.50695 14.3752 7.88573Z" stroke="black" stroke-width="1.5"/> </svg>

Modern Work

Modern workplaces and collaboration.

Effective solutions
We solve the IT challenges that most hinder Swiss SMEs. From Modern Work and Cyber Security to Cloud Migration.
Discover all solutions
Services
Craftsmanship Excellence
We support you from strategy consulting to seamless 24/7 operations. Professional, proactive, and individually tailored to your infrastructure.
Compare Service Models
About
Our story
100 years of experience. Your partner for innovation since 1925.
Blog Artikel
01.06.2026
3 min read

Cybersecurity Update October 2025 | Security Assessment – Baggenstos

Symbolic image: hand holding a glowing shield with a padlock inside a digital globe against a dark blue background.

Das Wichtigste in Kürze

  • BACS report after 6 months of mandatory reporting: 164 attacks on critical infrastructure, most often DDoS, hacking, ransomware and credential theft. The financial sector is the most affected
  • AI intensifies the threat landscape through more sophisticated attacks and deep fakes, but can also be deployed for threat defence
  • Tips for SMEs: classify data, least-privilege access, phishing-resistant passkeys, MFA, employee training and always verify questionable requests through a second channel

Attacks on Critical Infrastructure

No one is immune to cybercrime – not even operators of critical infrastructure. The Swiss Federal Office for Cybersecurity has published its first report on mandatory incident notifications. In just six months, 164 attacks were recorded against critical systems.

Top attack vectors: DDoS (18.1%), Hacking (16.1%), Ransomware (12.4%) and Credential theft (11.4%). Data leaks and generic malware each accounted for under 10%. In several cases, attackers combined methods – for example, ransomware coupled with data exfiltration. Financial services remain the most targeted sector, with 19% of all incidents.

Escalating Threat Landscape

Regardless of whether attackers target critical infrastructure or SMEs, one factor is constant: people. Humans are the gatekeepers criminals must trick or pressure to gain access. Email remains their main entry point for phishing. Increasingly, attackers also use social engineering via phone calls – impersonating police officers, for example – to apply psychological pressure and extort money.

The Federal Office for Cybersecurity recently warned about a particularly nasty scam: attackers call victims in a casual tone, claiming to be hired killers, and demand payment to abandon the alleged “contract”. On average, the office processes around 1,500 reports per week of phishing, fraud, and other digital crimes.

Emerging Threat Trends

Every business is a target if it is seen as both willing to pay and easy to compromise. Weak technical safeguards make organisations low-effort, high-reward victims.
AI now amplifies digital crime by enabling more sophisticated attacks. Deepfakes, increasingly difficult to spot, raise the risk of falling for a scam. Fortunately, AI also strengthens defence – analysing network traffic in the cloud and on-premises, detecting attack patterns. Microsoft integrates and continually expands such protections within Microsoft 365.

Yet, no technology is infallible. Poorly designed hybrid cloud architectures are increasingly targeted, as shown by the Storm ransomware group. Daily challenges for IT security teams include attacks on firewalls, GitLab instances, browsers, routers, Microsoft software, containers, operating systems, vehicles, thermostats, energy grids and more. In short: anything with software and a network connection is under constant threat.

How Baggenstos Protects

Large enterprises often have the resources to comply with complex security requirements. SMEs, however, typically benefit from the cloud as a more practical and secure option – complemented by on-premises installations where business processes or data protection demand it.

With Baggenstos M365 Cloud, customers benefit from robust, natively integrated security. Our carefully designed cloud architecture and b.secure triple-layer protection provide a strong baseline that can be further reinforced through training and fostering a security-first mindset across the organisation.

“It’s people who must close the loopholes that technology alone cannot cover,” says Sven Lüders, Cloud Solution Architect at Baggenstos.

Cybersecurity Tips for SMEs

  • Only operate systems in-house if you can secure them properly – otherwise, partner with a managed service provider specialising in hybrid cloud architectures.
  • Classify and protect your data.
  • Apply least privilege access controls.
  • Train your staff regularly, run attack simulations, and showcase the latest cyber-criminal tactics.
  • Recognise IT risks as business risks – downtime damages your brand.
  • Implement multi-factor authentication; adopt phishing-resistant passkeys wherever possible.
  • Always verify suspicious requests for sensitive data or payments through a second channel – even if the message appears to come from the CEO.

→ SME Cybersecurity Guidelines – Swiss Federal Office for Cybersecurity
Federal IKT Minimum Standards
Top Cyber Threats Overview


No items found.

Share article