Why do so many Swiss companies conceal cyberattacks, even though transparency could strengthen trust? How do you communicate a data leak without causing panic among your customers? What distinguishes successful IT crisis communication from PR disasters that continue to have an impact years later?
The figures are alarming: According to Check Point, Switzerland recorded a 113 percent increase in cyberattacks in the first quarter of 2025 – an average of 1,279 attacks per week and company. This puts Switzerland well above its neighbors Germany (up 55 percent) and Austria (up 69 percent). The education sector is particularly affected, with 4,484 attacks per week, followed by government organizations with 2,678 weekly attacks.
What these statistics don't show: The real challenge begins after the successful attack. That's when management and communications managers have to decide how to deal with the crisis. Remain silent and hope that nothing happens? Or communicate proactively and risk losing customer trust?
It is no longer just large corporations or banks that are targeted by cybercriminals. SMEs in Zurich, Basel, or Bern are just as vulnerable today as international companies. The monitoring platform Falconfeeds.io recorded 175 publicly known cyber incidents in Switzerland in 2024 alone– the number of unreported cases is likely to be many times higher.
The monitoring platform Falconfeeds.io recorded 175 publicly known cyber incidents in Switzerland in 2024 alone
The attack patterns have diversified. While DDoS attacks top the list with 60 cases, they are followed by data breaches (43), ransomware attacks (37), and access sales (22). Particularly worrying is that attackers are becoming more professional. Groups such as 8Base, Black Basta, and Lockbit operate like companies with their own PR departments, presenting stolen data on leak sites for maximum publicity.
This professionalization of attackers poses new challenges for communication. If criminals communicate faster than the affected companies, the latter lose control over how their own story is interpreted.
It's Monday morning, 7:30 a.m. The IT department reports: The servers are encrypted, nothing works anymore. The ransom demand is displayed on the screens. What happens next will determine the fate of the company.
In our consulting practice, we repeatedly see companies making fatal communication mistakes in these critical first hours. The natural impulse is secrecy—out of shame, fear of reputational damage, or the hope of being able to solve the problem internally. But it is precisely this delaying tactic that can become a trap.
The Swiss Data Protection Act requires high-risk data breaches to be reported "as soon as possible," as clarified by the Federal Data Protection and Information Commissioner (FDPIC) in its February 2025 guidelines. But what exactly does "high risk" mean? And when is "as soon as possible"?
Experience shows that companies that activate a clear communication plan within the first 24 hours are much better at managing the crisis. This does not mean revealing all the details immediately. Rather, a structured escalation must take place: inform internal stakeholders, notify authorities, prepare communication channels.
Transparency is the order of the day—but how much transparency can the crisis tolerate? This balancing act is one of the most difficult tasks in IT crisis communication.
A data leak at a Swiss online retailer may affect thousands of customer records. The legal obligation to provide information is clear. But how do you word a message that is serious enough to warn those affected, but not so alarming that it triggers a mass exodus of customers?
Successful crisis communication follows the principle of gradual transparency. The first phase involves communicating the facts: "We have been the victim of a cyberattack." This initial announcement should be made within 24 to 48 hours, even if not all the details are known yet.
The second phase provides clarity about the scope: What data is affected? Which systems have been compromised? Precision is crucial here. Vague wording such as "possibly some customer data" only fuels uncertainty. Better: "The names, email addresses, and delivery addresses of customers who placed orders between January 1 and March 15, 2025, are affected. Payment data was not affected."
The third phase involves specific instructions for action. What should affected customers do? Change their passwords? Check their account statements? These recommendations must be clear, feasible, and proportionate.
Direct communication with affected customers is the ideal approach to crisis management. However, it requires tact and perfect timing.
A large Swiss retailer recently had to inform 50,000 customers about a data breach. Instead of sending a mass email, the company opted for a phased approach: first, the most affected customers were contacted personally, then segmented emails were sent out depending on the degree of impact, and finally, general information was posted on the website.
It's all in the tone. Technical jargon causes uncertainty, while overly casual phrasing fails to convey the seriousness of the situation. The golden mean is achieved by communicating clearly, empathetically, and in a solution-oriented manner.
An example of successful wording: "We regret to inform you that our company has been the target of a cyberattack. Your personal data may have been accessed unlawfully. We have taken immediate action and are working hard to fully investigate the incident. Your security is our top priority."
On the other hand, avoid phrases such as: "A minor security incident" (downplaying), "Massive security breach" (scaremongering), or "We've been hacked" (too colloquial).
Swiss media are increasingly reporting on cyberattacks. What used to be a side note now makes it onto the front page. This media attention can be both a blessing and a curse.
Proactive media communication gives companies the opportunity to tell their side of the story. Those who wait for journalists to call have already lost control. A prepared media statement, clear language guidelines, and a designated spokesperson are essential.
But be careful: Swiss journalists are well connected and technically savvy. Contradictory statements or obvious attempts at concealment are quickly exposed. Honesty and transparency pay off—even if it means saying, "We don't know yet."
A practical tip: Prepare a "dark site" – a prepared but unpublished website with crisis information that can be quickly put online in an emergency. This allows you to refer the media and customers to a central source of information.
While all eyes are focused on external communication, internal communication is often neglected. This is a fatal mistake, because unsettled employees can become an uncontrolled source of information.
The National Cybersecurity Center (NCSC) recorded over 400 cases of fraud in the last week of December 2024 alone – many of them involving social engineering, i.e., the manipulation of employees. After an attack, they are particularly vulnerable to follow-up attacks.
Internal communication must therefore pursue several objectives: providing information about the incident, giving clear instructions on how to behave, offering psychological support, and strengthening defenses against subsequent attacks.
A three-step model has proven effective: immediate notification of management, briefing of all employees within 24 hours, regular updates on the progress of crisis management. Important: Employees need clear rules for external communication. Who is allowed to speak to the media? What can be shared on social media?
Ransomware attacks pose a particular communication challenge. Should the ransom demand be made public? How should the decision to pay or not to pay be communicated?
The Swiss authorities generally advise against paying ransom. But the reality is complex. When critical infrastructure is affected or human lives are at risk, companies face an ethical dilemma.
Maximum restraint is recommended in terms of communication. The information that a ransom is being demanded can be made public. However, the decision on whether to pay or not should remain internal. Phrases such as "We are in contact with the perpetrators" or "We are evaluating all options for restoring our systems" maintain the necessary flexibility.
After the crisis, transparency about how the blackmail was handled is appropriate—it can serve as a lesson to other companies and demonstrates a sense of responsibility.
There is a great temptation to conceal technical details—for fear of revealing weaknesses or inspiring imitators. However, a certain degree of technical transparency is necessary and builds trust.
Customers have a legitimate interest in knowing how the attack occurred. Was it a zero-day vulnerability? Was social engineering used? Or was it due to outdated software? This information helps them assess their own vulnerability.
The trick is to make the translation understandable. Instead of "SQL injection attack on unpatched Apache Struts installation," it would be better to say: "The attackers exploited a known security vulnerability in our web software that we had not closed in time."
At the same time, companies should communicate the countermeasures they have taken. This demonstrates their ability to act and their willingness to learn. "We immediately took all systems offline, called in external security experts, and initiated a forensic analysis."
In the digital world, news spreads at the speed of light. A tweet, a Reddit post, a leak on Telegram—and suddenly the news is everywhere. Companies are under enormous time pressure.
However, speed must not come at the expense of accuracy. Incorrect or contradictory information in the early stages of a crisis can cause more damage than a correct statement that is delayed by a few hours.
The solution: tiered communication. Initial confirmation ("We are aware of a security incident and are investigating it") can be provided within hours. Detailed information will follow as soon as it is available.
It is important to maintain the communication rhythm. Daily updates, even if there is nothing new to report, convey control and professionalism. "Today, we have continued to work intensively on restoring our systems. 70 percent of services are back online."
The acute crisis has been overcome and the systems are running again. But the communication work is not yet done. Now begins the phase of regaining trust.
A comprehensive final report that draws lessons from the incident is more than just a mandatory exercise. It shows that the company takes the incident seriously and is learning from it. What vulnerabilities were identified? What measures were taken? How will you ensure that the incident does not happen again?
Particularly effective: involving external experts. "We had an independent security audit carried out by [renowned security company]" creates credibility.
Positive communication is also important. When systems have successfully fended off an attack, when employees have recognized a phishing attempt—these are stories that strengthen trust.
Clear patterns can be identified from the analysis of successful and less successful crisis communications in Switzerland.
Successful companies are characterized by:
Prepared crisis communication plans with clear responsibilities and escalation levels. If you wait until a crisis hits to decide who is allowed to speak, you've already lost.
A dedicated crisis team that trains regularly. Cyber crisis simulations, known as table-top exercises, prepare them for emergencies.
Prepared communication materials. Templates for customer emails, press releases, and social media posts save valuable time.
Established relationships with relevant stakeholders. Those who already know journalists, government officials, and industry experts can act more quickly in a crisis.
Failed crisis communication, on the other hand, is characterized by:
Delay and obfuscation. Companies that only communicate once the media has already reported on something have lost their authority to interpret events.
Conflicting messages. When the CEO, CTO, and press spokesperson tell different stories, a loss of trust is inevitable.
Technocratic language. If you overwhelm customers with IT jargon, you will lose them emotionally.
Lack of empathy. Companies that only emphasize their own challenges forget about their customers' fears.
SMEs in particular often underestimate the complexity of IT crisis communication. The temptation to handle everything internally is great—after all, no one knows your company better than you do.
However, external experts offer decisive advantages: they are familiar with the legal requirements, have experience with authorities and the media, and—most importantly—they bring the emotional distance necessary for rational decisions.
Investing in professional crisis consulting pays off in many ways. Not only by avoiding mistakes, but also through faster crisis management and a more professional appearance.
Once the crisis has been overcome, there will be an opportunity to position cybersecurity as a competitive advantage. Customers reward companies that are open about security issues and invest in protective measures.
"Security by design" and "privacy by default" are not just technical concepts, but also communicative assets. Companies that proactively provide information about their security measures build trust.
This can take various forms: a security blog, regular updates on security investments, certifications, or bug bounty programs. All of this signals that we take security seriously.
The legal requirements for crisis communication are complex and constantly evolving. In addition to the GDPR, companies must also comply with industry-specific regulations.
Financial service providers are subject to FINMA regulations, healthcare providers must maintain patient confidentiality, and critical infrastructures have special reporting obligations.
Striking a balance between legal compliance and effective communication is an art. Too much legal jargon can be off-putting, while overly casual wording can have legal consequences.
A tip: Have your crisis communications reviewed by lawyers, but not written by them. The message must remain understandable while being legally watertight.
The threat landscape is evolving rapidly. Artificial intelligence is enabling increasingly sophisticated attacks. Deepfakes, AI-generated phishing, and automated attacks are becoming the norm.
For communication, this means that the credibility of information becomes a key challenge. If attackers can create perfect imitations of CEO voices, how can you prove the authenticity of your own communications?
Blockchain-based verification, multi-factor authentication for official communications, and new forms of digital signatures are becoming increasingly important. Companies need to start thinking today about how they will prove their authenticity tomorrow.
Would you like to professionalize your IT crisis communication and respond appropriately in an emergency? Brand Affairs supports you in developing a customized communication plan for cyber incidents. With over 18 years of experience in the Swiss market and our network of IT security and communication experts, we ensure that you remain capable of acting even in a digital crisis and maintain the trust of your stakeholders.
Contact us for a no-obligation consultation. Together, we will develop an IT crisis communication strategy that suits your company and prepares you optimally for cyber threats—transparent, legally compliant, and confidence-building.
You are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information