Switzerland’s Federal Office of Cybersecurity (BACS) dedicated three consecutive weekly reviews in July to AI-generated content. Images, text, video – all manipulated, all disturbingly convincing. Three weeks straight on the same topic. That alone tells you something about how urgent this has become.
We went through the BACS publications, cross-referenced them with international studies, and asked ourselves: what does this actually mean for a Swiss SME with 20 to 200 employees? Not in theory. In practice.
What it’s about
Across weekly reviews 28 through 30, the BACS covered three areas: AI-generated images (week 28), AI-generated text and websites (week 29), and deepfake videos with face-swapping (week 30). The message is unmistakable. What used to be detectable by spelling mistakes or blurry faces now looks professional. Phishing emails in flawless German. Websites you can barely distinguish from legitimate businesses. Videos where faces are swapped and nobody notices.
And here’s the uncomfortable part: the BACS documents concrete cases from Switzerland. Fake videos of federal councillors used for investment fraud. Real-time face-swapping in video calls. If you’re still thinking “that wouldn’t happen to us” – it already is.
What the international numbers say
The BACS warnings don’t exist in a vacuum. A Keepnet study puts the share of companies that have already suffered financial damage from deepfake fraud at 92 percent. Let that sink in. Average costs per incident nearly doubled between 2022 and 2024, reaching USD 450,000. Gartner reports a deepfake incident rate of 62 percent. Pindrop tracked a 1,210 percent increase in AI-powered fraud in 2025.
But perhaps the most alarming number is this one: only five percent of companies have a documented strategy against deepfake attacks. Five. And 80 percent have no formal processes whatsoever for responding to such an attack. Keep in mind – these numbers come from surveys of large enterprises. For SMEs? You probably don’t want to know.
Three reasons Swiss SMEs make attractive targets
First: money. Swiss companies are perceived as wealthy – because they generally are. A CEO fraud via deepfake video call yields higher returns here than in most other countries, simply because the transaction amounts are larger. For an attacker, it’s straightforward arithmetic.
Second: trust. Swiss business culture runs heavily on personal relationships. If you’ve worked with the same supplier for ten years, you question a phone call less sceptically. That’s precisely what attackers exploit – and with deepfakes, they now have the tool to do it convincingly.
Third: missing resources. There’s no dedicated security analyst watching for new attack vectors. No structured awareness programme that goes beyond an annual email. We see this in practically every assessment we conduct.
The uncomfortable truth about detection
The BACS lists useful detection markers – and they’re genuinely practical. Unnatural transitions at the neck in face-swaps. Faulty hands in AI images. Overuse of bold text in AI-generated writing. One-pager websites with too many animations. Good tips that help in daily life.
But – and this needs saying – it won’t stay that way for long. AI models improve faster than our ability to spot what they produce. The BACS itself acknowledges that reliable detection usually requires combining multiple indicators. And even that gets harder month by month.
Which brings us to the crucial shift in thinking: stop trying to recognise the fake and start building processes that prevent a fake from causing damage. That’s a fundamentally different approach.
What SMEs should do now
Four-eyes principle for payments above a certain threshold. No exceptions – not even when the CEO calls personally. Especially not then. Think that’s overkill? That’s exactly how these attacks work.
Call back on a known channel when something feels off. Don’t use the number from the suspicious call or email – use the one stored internally. Sounds obvious? Still gets skipped all the time.
A shared code word for critical situations. Yes, it sounds like something from a spy film. But it’s one of the few things AI simply cannot replicate. Sometimes old-school beats high-tech.
Regular training – but keep it realistic. The goal isn’t teaching staff to spot deepfakes. That’s a race we lose in the long run. The goal is getting them to pause when something feels unusual and follow the defined verification process. Simulated social engineering attacks with AI elements are the best tool for this.
And one more thing: reduce the amount of photos and video footage of key personnel online. The less material available, the harder it is to create a convincing deepfake. A lot of people overlook this.
Our take
The BACS series is well worth reading and arrives at exactly the right moment. But the real challenge isn’t detecting manipulated content – that’s a rearguard action. The challenge is designing business processes that still hold up when the person on the other end of the line isn’t who they claim to be. The good news: the most effective measures cost little and can be implemented immediately. You just have to actually do it.
We support Swiss SMEs with social engineering assessments and phishing simulations – since 2025, including AI-powered attack scenarios. Talk to us if you want to find out how prepared your organisation really is.
Sources and further reading: BACS Weekly Review CW 28, CW 29, CW 30, Keepnet Deepfake Statistics 2026, Adaptive Security Report