Why Municipalities Need Better Cybersecurity Now

by Priyanka Patel

Bern, June 19, 2025 – Every second community in Switzerland is shockingly unprepared for cyberattacks, leaving them vulnerable to digital threats.

Swiss Communities Face Cyber Security Crisis

A recent survey reveals a widespread lack of preparedness, putting critical infrastructure at risk.

  • Half of Swiss communities are insufficiently prepared for cyberattacks.
  • A third lack a complete overview of their digital assets.
  • Smaller communities struggle due to time and resource constraints.

What’s the state of cyber security in Swiss communities? according to a recent survey, a staggering number of Swiss communities are ill-equipped to handle cyber threats. This lack of preparation puts vital services and sensitive data at serious risk.

“It was a Wednesday morning,” recalls Daniel Bichsel, President of the Bernese municipality of Zollikofen, “we drove up the computers and immediately noticed that something was wrong.” In November 2023, the municipality of Zollikofen was hacked. At the time, cybersecurity wasn’t a priority.

Did you know?-Cyberattacks on municipalities can disrupt essential services like water, electricity, and emergency response systems, impacting residents’ daily lives and safety.

Manuela Sonderegger from the Federal Office for Cyber ​​Security noted, “We certainly know that there is a need to catch up with the communities.” The federal government has been focusing on the cyber security of municipalities for three years. Despite this, improvements are slow.

Smaller Communities Struggle with Cyber Security

Alexander Sollberger from the Myni Gmeind association, which is committed to digital conversion among the Swiss communities, points out the challenges faced by smaller communities. “there is hardly any time to familiarize yourself with a municipal administration with only a few peopel,” he says.

Pro tip:-Regularly back up critical data to an offsite location. this ensures that even if systems are compromised, essential details can be restored quickly and efficiently.

Sollberger recommends that the communities come together in cyber security, however, this doesn’t always work. “Personal sensitivities play a major role here, certain communities don’t want to be said to be said by the neighboring community.”

Sollberger is convinced that the abstract nature of the topic is a problem. “Sadly, good cyber security cannot be won.The residents of the community don’t get anything from that.” Many municipalities only prioritize cyber security after an attack.

Cyber Security Comes at a Cost

In Zollikofen, there was no cyber emergency concept in place. “Today we would of course be better prepared,” Mayor Daniel Bichsel is convinced.The hackers entered the municipal system via the mail server.

According to Bichsel,the municipal administration now regularly hacks its own cyber system to identify gaps. Employees complete courses to be sensitized to cyber risks.

CHF 18,000 annually for cyber security

a11y-open h-offscreen”>Box open
body js-expandable-box–body”>

Since the hacker attack, Zollikofen spends CHF 18,000 for cyber security every year. However, this is still much less than the costs incurred by the hacker attack itself, says Mayor Daniel Bichsel. At that time, the municipality had to pay over CHF 130,000 in order to get the systems up and to be able to resume work. None flowed to the hackers, so the attack was not worth it for them.

The Crucial Role of Cybersecurity Awareness: Beyond Technology in Swiss Communities

The vulnerability of Swiss communities to cyberattacks, as highlighted by the recent survey [[1]], underscores the urgency of strengthening cybersecurity measures.While technological solutions are essential, fostering cybersecurity awareness among municipal employees and residents plays a pivotal role in bolstering defenses. This proactive approach can considerably minimize the impact of potential attacks and reduce the occurrence of incidents like the one experienced in Zollikofen.

The focus needs to shift beyond simply implementing security software and hardware to establishing a culture of digital responsibility. This includes providing regular training, promoting best practices, and encouraging vigilance in the face of online threats. The abstract nature of cybersecurity,as mentioned by Alexander Sollberger [[2]],can make it challenging for communities to prioritize. Though, by making the risks and preventive measures tangible and relatable, communities can better safeguard themselves.

Key Components of a Robust Cybersecurity Awareness Programme

To build a strong defense, swiss municipalities should focus on several key areas, ensuring that cybersecurity awareness becomes ingrained within their operations and the community they serve:

  • Regular Training: Implement mandatory training sessions for all municipal employees, covering topics such as phishing, password security, social engineering, and recognizing malicious software. Refresher courses should be provided periodically to keep knowledge current and adapt to evolving threats.
  • Clear Dialog: Establish clear communication channels for reporting suspicious activities and incidents. This could include an internal reporting system for employees and public awareness campaigns outlining how residents can identify and report potential cyber threats.
  • Community Engagement: Extend cybersecurity awareness initiatives to the broader community through workshops, webinars, and informational materials. Focus on practical tips, such as securing personal devices and recognizing phishing attempts, to empower residents to protect themselves and their families.
  • Simulated Attacks: conduct simulated phishing campaigns and other vulnerability assessments to identify weaknesses in employee behavior and assess the effectiveness of training programs. This provides valuable insights for improving preparedness.
  • Incident Response planning: Maintain a regularly updated incident response plan that clearly outlines procedures for handling cyberattacks, including containment, recovery, and communication strategies. This plan should be regularly tested through simulations.

Actionable Steps for Swiss Communities:

To improve cyber-preparedness,Swiss communities can adopt the following practical measures:

  • Conduct a Security Audit: Perform a comprehensive audit of the municipality’s digital assets,identifying vulnerabilities and areas for advancement.
  • Develop a Cybersecurity Policy: Establish and enforce a comprehensive cybersecurity policy that covers data protection, access controls, acceptable use, and breach response procedures.
  • Implement Multi-Factor authentication (MFA): Enforce MFA for all sensitive systems and accounts to add an extra layer of protection against unauthorized access.
  • Educate Vendors: Ensure third-party vendors and service providers understand their role, follow your cybersecurity policies and have the appropriate security measures in place.
  • Encourage Information Sharing: Participate in information-sharing forums and networks to stay updated on the latest threats and best practices.

What level of digital preparedness should Swiss communities strive for? A high level of preparedness, including staff training and a strong security culture, is vital to protect citizen data and critical services. Proactive defense of municipal systems is as crucial, if not more so, than a reactive approach to the problem.

By prioritizing cybersecurity awareness alongside technological safeguards, Swiss communities can significantly reduce their vulnerability to cyberattacks.Focusing on proactive defenses, educating residents, and fostering a culture of digital responsibility will be key to a more resilient and secure future.

Frequently Asked Questions

how ofen should municipalities update their cybersecurity training for employees?

Regularly. At a minimum, cybersecurity awareness training should be updated annually or when major threats or technological changes occur.Frequent refreshers help keep information at the forefront and enhance employee response.

How can smaller communities,that suffer from time and resources constraints,improve cybersecurity awareness?

Leverage free online resources,collaborate with neighboring communities,and prioritize staff education. Consider using vendor-provided awareness materials and seeking assistance from government cybersecurity agencies for streamlined training.

What is the role of residents in improving community cybersecurity?

Residents can help protect themselves by staying informed about cybersecurity threats, following best practices like securing their devices, and reporting any suspicious activities or communications to their municipality or the proper authorities.

You may also like

Leave a Comment