1 min read
Why Swiss companies need to treat IT security as a leadership responsibility
Over the past year, 73% of Swiss SMEs affected by a cyberattack suffered at least some significant financial damage (Mobiliar Studies). Behind this figure lie disrupte supply chains, disabled systems, and lost customer data – as well as executives who, in the moment of crisis, realize they were not prepared. Not because the threat was unknown, but because Cyber Security has too long been treated as a purely IT issue.
Nearly two-thirds of Swiss executives name cyber risks as their top concern, even ahead of inflation. And yet fewer than half of CEOs discuss how cybercrime concretely impacts their business strategy (PWC insights). This is not a contradiction born of ignorance – it is a structural gap. The three biggest threats to Swiss companies – cloud attacks (49%), hack-and-leak operations (41%), and ransomware (39%) – make no distinction between IT infrastructure and business operations.
of Swiss business leaders say that cyber risks are their biggest concern
of CEOs address the impact of cybercrime on their business strategy
On top of that comes a new level of escalation: artificial intelligence is fundamentally reshaping the threat landscape. It makes attacks faster, more targeted, and harder to detect. At the same time, AI workloads within organizations are creating new attack surfaces that traditional security models can barely cover.
When security becomes a secondary concern
In practice, however, security teams report risks, while executive leadership prioritizes other issues, and budgets are released reactively—after an incident, not before. As a result, more than one in ten Swiss companies had to abandon planned security measures last year due to a lack of budget.⁴ Budget decisions are made at executive level, and this is precisely where strategic alignment is often missing. This development can largely be explained by the fact that Cyber Security is still perceived as a cost factor rather than what it truly is: a strategic business investment in operational resilience.
As long as there is no shared risk picture between IT, executive management, and the board of directors, Cyber Security remains reactive. Measures are not driven by strategy but emerge as responses to incidents. Acting this way means giving up initiative and leaving the next move to the attackers.
Cyber Security is a leadership responsibility
What is often overlooked is that the risk does not remain confined to the operational level. It rises directly to the executive suite. In Switzerland, the Federal Act on Data Protection holds board members directly accountable for failures in Cyber Security, even if responsibility has not been formally assigned internally. Executive management carries responsibility for the company’s entire Cyber Security framework - not only in times of crisis, but on a daily basis. Those who do not actively manage cyber risks are, by default, managing them passively - and remain liable in the event of an incident.
The shift in perspective Swiss companies now need is clear: Cyber Security belongs in business strategy, not in the IT department. This requires a shared risk understanding at board and executive level, clear accountability, budget decisions based on risk prioritization, and a security culture that is not only established after an incident. Companies that take this step do not just protect their systems—they protect their operational capability, customer trust, and competitive position. Properly understood, Cyber Security is not a cost factor. It is a strategic advantage.
Cyber Security implemented strategically with Axians
This is exactly where Axians comes in. As a 360° ICT provider with over 1,000 Cyber Security specialists worldwide and deep roots in the Swiss market, Axians helps organizations shift cybersecurity from an IT topic to a leadership responsibility. The starting point is always a strategic assessment: What needs to be protected? What level of protection is appropriate? Where are the greatest risks - and how can measures be aligned with available resources?
The Axians-Portfolio covers the full spectrum - from strategy, governance, and compliance to the protection of identities, endpoints, and cloud environments, all the way to ongoing operations in an ISO 27001-certified Security Operations Center that monitors, detects, and responds around the clock. The secure and controlled use of AI is also a core component, as new technologies require new security approaches. Axians combines local expertise with international know-how: Swiss points of contact, Swiss data centers - backed by a global network. This applies equally to IT and OT environments, for organizations of all sizes that want to anchor Cyber Security where it belongs: at the leadership level.