EU Cyber Resilience Act: Was Schweizer Unternehmen ab September 2026 beachten müssen

EU Cyber Resilience Act: Was Schweizer Unternehmen ab September 2026 beachten müssen

Am 11. September 2026 tritt die erste Durchsetzungsphase des EU Cyber Resilience Act (CRA) in Kraft. Ab diesem Datum müssen alle Hersteller von Produkten mit digitalen Elementen, die im EU-Markt vertrieben werden, aktiv ausgenutzte Schwachstellen innerhalb von 24 Stunden an die ENISA melden. Für Schweizer Unternehmen, die in die EU exportieren, Software entwickeln oder IoT-Geräte … Read more

Lieferkettenangriffe 2026: Wenn Ihr IT-Dienstleister zum Sicherheitsrisiko wird

Cyberangriffe über die Lieferkette haben sich seit 2020 fast vervierfacht, wie der IBM X-Force Threat Intelligence Index 2026 zeigt. Laut dem Verizon Data Breach Investigations Report 2025 sind mittlerweile 30 Prozent aller Datenschutzverletzungen auf Drittanbieter zurückzuführen – doppelt so viele wie im Vorjahr. Für Schweizer KMU, die stark auf IT-Dienstleister, Cloud-Plattformen und Softwareanbieter setzen, ist … Read more

AI Surveillance: Palantir, Pegasus, and the Boundaries of Legality

Palantir analyses data for intelligence agencies and law enforcement worldwide. Clearview AI has scraped over 60 billion facial images from the internet — without consent. Pegasus spyware infiltrates journalists’ and activists’ smartphones via zero-click exploits. And predictive policing algorithms disproportionately send patrols into minority neighbourhoods. AI-powered surveillance is not a future scenario — it is … Read more

DarkSword iOS Exploit Kit: What It Can Do, What It Cannot – and Why It Is Not a Jailbreak

On March 18, 2026, Google Threat Intelligence, iVerify, and Lookout jointly disclosed an iOS exploit kit called DarkSword. It affects iPhones running iOS 18.4 through 18.7 – an estimated 270 million devices worldwide, according to iVerify. Five days later, the full exploit code was leaked on GitHub. Here is what DarkSword means for iPhone users, … Read more

AI in Cyber Defence: What Works, What Doesn’t – and Where the Limits Are

Artificial intelligence is the current buzzword in IT security. Hardly any product launches without “AI-powered” in its marketing. But what does AI actually deliver in cyber defence — and where do its limitations lie? Where AI Delivers Real Value Machine learning and statistical models have produced demonstrable progress in certain areas of IT security. Not … Read more

Meldepflicht bei Cyberangriffen: Schweizer Unternehmen riskieren Bussen bis CHF 100’000

Seit dem 1. Oktober 2025 drohen Schweizer Unternehmen Bussen bis CHF 100’000, wenn sie einen Cyberangriff nicht fristgerecht melden. Die Meldepflicht nach dem Informationssicherheitsgesetz (ISG) ist seit April 2025 in Kraft – doch die Realität zeigt: Viele Betreiber kritischer Infrastrukturen kennen ihre Pflichten nicht oder sind nicht vorbereitet. Gleichzeitig läuft eine weitere Frist: Bis Ende … Read more

NIS2 Directive: What Swiss Companies with EU Business Need to Know

The NIS2 Directive (Network and Information Security Directive 2) is the most comprehensive cybersecurity regulation the EU has ever enacted. Since October 2024, it replaces the original NIS Directive from 2016 and massively expands its scope: from 7 to 18 sectors, with stricter requirements, shorter reporting deadlines and personal liability for senior management. Switzerland is … Read more

Insider Threats: When the Greatest Danger Comes from Within

The Verizon Data Breach Investigations Report 2025 delivers an uncomfortable figure: in the EMEA region, 29% of all confirmed data breaches are attributable to internal actors. Globally, people are the decisive factor in 60% of all breaches – through errors, manipulation or deliberate misuse. The greatest threat is not lurking somewhere on the dark web. … Read more