2 min read

Using tools without a strategy is a waste of resources

Using tools without a strategy is a waste of resources

 

What Swiss Organizations Need to Address in Cybersecurity Now

Swiss companies and public authorities reported nearly 65,000 cyber incidents to the National Cyber Security Centre in 2025 (B2B Cyber Security). At the same time, more than one in ten Swiss organizations had to abandon planned security initiatives - not because the technology was unavailable, but because budgets fell short (swisscybersecurity.net).

The real challenge, however, goes beyond technology and funding. Organizations continue to acquire new tools, patch security gaps, and consume valuable resources, yet their overall security posture often improves only marginally. What is missing is not another solution, but a clear strategy and a structured approach.

As of February 2026, the Natianal Cyber Security Centre (NCSC) has recorded 260 cyberattacks against critical infrastructure since April 2025. Following such incidents, affected organizations often respond by searching for new products: a new tool is evaluated, purchased, and deployed—only to become another addition to an environment already shaped by dozens of similar isolated decisions.

The result is not a coherent security strategy, but a patchwork of solutions: numerous tools, limited integration, and little overall impact on the organization's security posture.

260

Attacks on Critical Infrastructure

(Reported between April 2025 and February 2026)

The real problem is not a lack of technology. It is the absence of a clear strategy that defines what needs to be protected, the level of protection that should be achieved, and how security measures are prioritized and aligned with available resources.

Structure Creates Impact

A security-strategy clearly defines which systems and data require the highest level of protection, where existing gaps lie, and in what order measures should be implemented - aligned with available budget and capacity. This alignment is critical: it is not the most extensive measure that delivers the greatest security gain, but the right measure at the right time.

Organizations that skip this step and move directly into architecture and implementation lose their sense of scale and prioritization. Security-Audits may provide findings, but they do not offer strategic context. As a result, individual measures are implemented, many risks remain unaddressed, and resources are wasted due to a lack of foundational direction.

What is essential is a clear separation across three distinct layers:

 

Strategy

 

What needs to be protected? What level of protection is the target? Which risks are acceptable? Learn more here. 

 

 

Architecture

 

How are layers of defense designed and systems structured? Learn more here. 

 

 

Design

 

How are layers of defense designed and systems structured? Learn more here. 

 

Only when these layers are properly aligned does a security system emerge that works in practice - and keeps organizations operational and capable of action.

 How an effective security strategy is built - and why it is the critical step before any architecture or design decision, including in the context of growing AI workloads - is outlined in the Axians AI Security Playbook for Swiss CIOs and CISOs.

AI is increasing the pressure to act

This requirement for strategic clarity is becoming even more urgent with the adoption of artificial intelligence. AI has arrived in Swiss organizations - as an assistant, an analytics tool, and an integral part of automated processes. As a result, new data flows, new dependencies, and new attack surfaces are emerging that traditional security models only partially address.

Organizations that deploy AI workloads without a clear understanding of which data is moving where, who has access to it, and who is accountable in the event of an incident introduce structural risks - regardless of how well their broader security architecture is designed. AI security is therefore not a separate discipline. It is the logical extension of a well-designed security-strategy: governance, transparency, and clear accountability apply to AI systems just as they do to any other critical infrastructure within the enterprise.

Strategy, Architecture, and Operations from a Single Source  

This is exactly where Axians comes in. As a 360° ICT provider with more than 1,000 Cyber Security specialists worldwide and a strong presence in the Swiss market, Axians supports organizations from strategic assessment and architecture design through to ongoing operations - backed by an ISO 27001-certified Security Operations Center and a modular portfolio that integrates seamlessly into existing environments.

The approach is risk-based: governance, architecture, and operations are brought together into a unified model - for both traditional IT and OT environments, as well as the secure and controlled use of AI. This ensures that measures are implemented exactly where they deliver the greatest impact.