The Swiss Cyber Threat Index 2026 records 187 confirmed cyberattacks on Swiss healthcare organisations — hospitals, clinics, imaging centres, and medtech manufacturers — representing a 41% increase from 2025. That headline figure deserves disaggregation before it is cited in a board report or a regulatory filing, because the trend inside the number is more instructive than the aggregate. This is not a story about a single threat actor or vulnerability class. It is a story about structural exposure that accumulates faster than remediation budgets, legacy infrastructure that resists patching, and a supply-chain attack surface that grew steadily through the medtech boom without a commensurate investment in third-party security governance. The ISA mandatory reporting regime that came into force in 2026 will, for the first time, produce comparable longitudinal data on Swiss healthcare incidents. Reading the 2026 index carefully now — before that data becomes normative — is the only way to understand what the baseline actually looks like.
Breaking Down the 41% Surge
A 41% year-on-year increase in confirmed attacks does not necessarily mean the threat landscape deteriorated by 41%. Part of the increase reflects improved detection. Swiss hospitals that deployed EDR solutions and network monitoring in 2025 detected attacks in 2026 that their previous tooling would have missed. Part of it reflects improved reporting: NCSC's mandatory incident reporting guidance created an expectation that significant events would be disclosed, and organisations that previously absorbed incidents quietly began reporting them. The actual increase in attacker activity targeting Swiss healthcare is, by any measure, significant — but interpreting a jump from 132 to 187 as a pure threat-intensity metric overstates the case.
The more useful signal is the distribution by attack type. Ransomware accounts for the largest single category: roughly 60% of confirmed attacks involved encryption of clinical or administrative systems, data exfiltration, or a combination of both. The Akira group's attack on Groupe 3R's network of 20 imaging centres earlier in 2026 — the second major incident against Swiss healthcare infrastructure within twelve months — fits this pattern precisely. EMEA-wide data from Help Net Security's July 2026 ransomware analysis confirms the trend: healthcare absorbed 35% of all EMEA ransomware activity in July, making it the single most targeted sector on the continent, ahead of financial services and government.
The remaining 40% of Swiss incidents divides roughly evenly between credential-theft and business email compromise (common against hospital procurement and finance functions), medical-device exploitation (primarily legacy imaging and infusion systems exposed to hospital networks), and supply-chain compromise through clinical software vendors. The last category is growing fastest in absolute terms — not because it is new, but because Swiss hospitals have expanded their vendor ecosystems significantly since 2020 without consistently extending security due diligence to clinical software providers that handle patient data.
Where Swiss Healthcare Remains Structurally Exposed
Three structural vulnerabilities dominate the incident data in ways that have not materially changed despite increased awareness at the leadership level.
Legacy clinical systems connected to enterprise networks. Imaging equipment, patient monitoring systems, infusion pumps, and laboratory automation that were manufactured before 2018 typically run unpatched operating systems, lack agent-based EDR support, and cannot be patched without disrupting clinical workflows — which hospital engineering teams are unwilling to accept during patient-care hours and unable to guarantee during maintenance windows. The standard advice — network segmentation — is correct but partially implemented in most Swiss hospitals. The segment boundaries are defined; the enforcement is inconsistent. Lateral movement from an enterprise endpoint to a clinical VLAN through a misconfigured switch remains the most common escalation path in Swiss healthcare incidents.
Procurement functions targeted by BEC without phishing-resistant authentication. Hospital procurement teams process high-value supplier payments, manage vendor onboarding, and coordinate with clinical engineering on equipment orders. They are precisely the functions that business email compromise targets. Swiss hospitals that have deployed FIDO2 or certificate-based authentication on their clinical systems have frequently not extended the same controls to the administrative functions that handle financial transactions. The credential theft cases in the 2026 index disproportionately affect administrative staff in procurement and finance — not clinical users.
Clinical software vendors with inadequate security programmes. The Swiss medtech and hospital sector relies on a dense ecosystem of specialised clinical software vendors: PACS operators, electronic health record providers, clinical trial management platforms, and diagnostic-algorithm vendors. These firms are typically small, clinically focused, and operating under the assumption that their hospital customers handle security at the network perimeter. The assumption is wrong in both directions: hospitals trust vendor software to be secure, vendors trust hospital networks to be segmented. When neither assumption holds, a compromise of a clinical software vendor propagates across every hospital in its customer base simultaneously — the exact pattern that drives the supply-chain category growth in the 2026 index.
ISA Reporting as a Data-Quality Event
The ISA mandatory reporting regime that came into force in 2026 will transform the quality of Swiss healthcare incident data in ways that matter for how the 2027 index will read. Under ISA, operators of critical information infrastructure — which includes hospital groups above certain size thresholds and Swiss medtech manufacturers whose products support critical care functions — must report significant incidents to BACS within 24 hours and follow up with detailed reports within specified timeframes. This is not a recommendation. Failure to report carries sanctions, and BACS has indicated it will use the first enforcement cycle to establish the reporting standard clearly.
The practical consequence is that the 2026 index reflects a transition year: some organisations reported under the new obligation, others did not because they were uncertain whether their threshold classification was correct, and a third group reported through informal channels to BACS without formally filing under ISA. The 187-attack figure almost certainly understates actual incidents. The 2027 edition will have mandatory reports as its primary data source, and the number will be higher — not because the threat increased, but because the reporting universe expanded to its true size.
Swiss healthcare security teams and their CISOs need to prepare for this shift. An organisation that has never filed an ISA report, has not determined whether it meets the critical-infrastructure threshold, and has no incident-response procedure that includes a notification decision tree will face a difficult choice when the next incident occurs: file late, file incorrectly, or explain to BACS why they concluded no filing was required. Each of those outcomes carries different risk profiles, and none of them is comfortable in a regulatory environment where the enforcement machine is now operational.
◆ Key Takeaway
The 41% surge in Swiss healthcare cyberattacks reflects both genuine threat escalation and improved detection. The structural exposures — legacy clinical systems, under-protected procurement functions, and weak clinical software vendor governance — have not materially improved. ISA mandatory reporting will make the true incident volume visible in 2027. Swiss healthcare organisations that have not yet completed their ISA threshold assessment, built a notification chain, and closed the segmentation gaps in their clinical networks are running out of time to do so outside an active incident.
- Determine formally whether your organisation meets the ISA critical-infrastructure threshold for healthcare operators; document the legal basis of your conclusion and review it annually as the organisation's scale and systems change.
- Build an incident notification decision tree that identifies who decides whether an event meets ISA reporting criteria, who drafts the 24-hour notification to BACS, and who owns the follow-up report; test it in a tabletop exercise before year-end.
- Map all clinical VLAN boundaries against current switch and firewall configurations; validate that clinical devices cannot reach enterprise endpoints through any misconfigured path — assumption-based segmentation is not a control.
- Extend phishing-resistant authentication (FIDO2 or certificate-based) to procurement, finance, and vendor-onboarding functions; these users process the highest-value financial transactions and are the primary BEC targets in the 2026 incident data.
- Audit all clinical software vendors for security programme maturity: request their last penetration test report, their incident notification policy, and their data-processing agreement; vendors that cannot produce these documents within ten business days should be escalated for contract review.
- For legacy clinical devices that cannot be patched or agent-monitored, implement compensating controls: network access control that enforces device identity before VLAN admission, anomaly-based detection on clinical network traffic, and documented decommissioning timelines.
- Publish the Swiss Cyber Threat Index 2026 healthcare data at board level; use it to drive the investment case for the controls above — not as a generic risk statement but as a sector-specific benchmark against which board members can assess the organisation's relative position.
The Swiss healthcare sector is entering a period in which mandatory reporting, ENISA's NIS360 maturity data, and FINMA's emerging expectations for health-adjacent financial entities will together make the security posture of every significant hospital group and medtech manufacturer visible to multiple regulators simultaneously. Organisations that use the 2026 index as a diagnostic tool rather than a communications document will be better positioned when that visibility arrives — and better equipped to demonstrate that the investment decisions they made in 2026 and 2027 were proportionate, documented, and effective.