3 min read

Between flexibility and control

Between flexibility and control

How Swiss companies securely manage their digital workspace

 

Hybrid working has become the norm in Swiss companies. Before the pandemic, around 7% of the workforce worked from home – by the end of 2025, that figure had risen to around 25%. According to the UBS Outlook Switzerland (nau.ch), no reversal of this trend is expected: the vast majority of companies are sticking with the current model.

For IT leaders, the question is no longer whether or to what extent flexible working models make sense, but rather an operational one: how can a work environment that is distributed across multiple locations, devices, and access paths be reliably managed and secured?

41
%

 of all cyberattacks worldwide in 2025 targeted remote or hybrid employees. (itdeskuk.com)

The traditional security model, which ends at the perimeter of the corporate network, no longer protects where employees actually work today.

For Swiss companies, the threat landscape is particularly pronounced. For IT leaders in Switzerland, cloud security (49%), hack-and-leak operations (41%), and ransomware (39%) are, according to the PwC Global Digital Trust Insights 2025, the three biggest risks – all of them above the global average. Awareness of the threat landscape is therefore already high. What is needed now is the structural foundation on which security measures can actually take effect.

Where does your work environment stand today?

 

The Axians Digital Workspace Maturity Model 2026 shows the development stage that Swiss companies’ digital work environments typically are at – and what steps are needed to move towards a secure, manageable digital workspace. Download it for free now and assess your own maturity level.

workspace-01-EN_quadrat

 

Where risks actually emerge

Risks arise primarily where the governance of the digital workspace still has gaps today: 

 Unmanaged devices

Unmanaged devices without automated patching and security policies pose a security risk. If you don’t know which devices have access, you can’t effectively protect them. 

 Unsafe access paths 

Home networks and public Wi-Fi connections do not provide the same level of protection as controlled corporate environments. 

 Inconsistent access rights

Lack of control over access rights, especially during role changes as well as onboarding and offboarding, leads to security gaps.

 Shadow IT

Overly complex or slow solutions encourage the use of unauthorized tools and cloud services.

 Distributed data storage

Information is often spread across multiple systems and cloud storage solutions – frequently without clear ownership or compliance control. In view of the Swiss FADP, this poses significant risks.  

What these risk sources have in common is that they stem from a lack of structure. And they cannot be resolved by adding another security tool, but only by a digital work environment that is designed to be manageable and controllable from the ground up.

Three levers for a manageable digital work environment

The key lies in the interplay of three core elements: identity, device management, and governance.

Identity as the new security foundation

In a hybrid setup, the traditional perimeter-based model no longer applies – user identity becomes the new perimeter. This means multi-factor authentication as a baseline requirement for every access attempt, context-based access decisions – considering device health, location, and user behaviour – and consistent enforcement of the least-privilege principle. This must be complemented by structured onboarding, role changes, and offboarding processes to ensure access rights always reflect the user’s actual status.

Devices: centrally managed, continuously controlled

Every device accessing the corporate environment is a potential attack vector. No device should therefore be granted access without compliance with defined policies, starting from the very first login, not only after manual IT setup. Automated patching and monitoring proactively close security gaps. Clear lifecycle management ensures that every stage – from provisioning to decommissioning – is defined and traceable.

Governance: the organisational prerequisite

Technical measures only work reliably when embedded in clear organisational structures. This includes binding usage policies for tools, data, and devices, clearly defined responsibilities for operations and further development, and an approach that incorporates the requirements of the Swiss Federal Act on Data Protection (FADP) from the outset, rather than adding them later.

Flexibility and control: not a contradiction – if the structure is right 

Axians supports Swiss companies in building exactly these structures, from initial assessment and architecture design through to ongoing operations. The focus is not on individual tools, but on how everything works together: identity and security concepts, centralized endpoint management, automated device provisioning, and governance models tailored to the organisation’s actual requirements.

As an ICT partner with a strong presence across Switzerland and its own local teams and offices, Axians is familiar with the concrete requirements around data protection, compliance, and operational stability. At the same time, it draws on the experience of the global VINCI Energies network – gained through projects across different industries and markets that demonstrate how secure hybrid work environments function in practice.