Guide · GUIDE 20

Protection in a cyberattack

Last reviewed on 22.06.2026

Disconnect affected devices from the network immediately, don't open suspicious links or attachments, and never pay a ransom if hit by ransomware. Report the incident to the Federal Office for Cybersecurity (NCSC) via its online reporting form, and to the police via 117 if it's a criminal offence. For information, switch to official channels such as radio and Alertswiss.

A cyberattack is the deliberate disruption or takeover of IT systems. Common forms are ransomware (encryption with extortion), DDoS (overload) and supply-chain attacks. When it hits critical infrastructure, government services, hospitals or payment traffic fail. Private individuals are not helpless: offline backups, two-factor authentication, updates, phishing awareness and some cash make you resilient. In Switzerland, the Federal Office for Cybersecurity (NCSC) is the Confederation's official reporting and analysis body: it continuously publishes situation analyses and receives incident reports.

How do I protect myself from a cyberattack?

  1. Create offline backups of important data (3 copies, 2 media, 1 off-site)
  2. Enable two-factor authentication, use strong and unique passwords
  3. Install updates for devices and programs promptly
  4. Learn to recognise phishing (unexpected links, attachments, payment requests)
  5. Keep a small cash reserve in case payment traffic fails

Common types of attack – and what you can do about them

Almost all attacks that affect the public follow a few recurring patterns. Recognise them and you'll react correctly.

  1. Phishing: fake emails or texts lure you to imitation login pages. Never enter passwords or card details via a link from a message – type the address yourself and use two-factor authentication.
  2. Ransomware: malware encrypts your data and demands a ransom. Disconnect the device from the network immediately, do not pay (payment does not reliably restore your data), restore from an offline backup and file a police report.
  3. DDoS: a website or service is knocked out by overload. As a user there is nothing you can fix – wait it out, switch to official channels and distrust any supposed «outage hotlines».
  4. Phone tech-support scams: fake technicians want remote access or payments. Never grant remote access, never give out codes, hang up and call the company back on its official number.

During: in an incident

  1. Disconnect affected devices from the network
  2. Do not pay a ransom
  3. Report the incident: NCSC and – for criminal offences – the police 117
  4. Switch to official information channels (radio, authorities)
  5. If payment traffic fails, use the cash reserve

How and where do I report a cyber incident?

  1. Report the incident to the Federal Office for Cybersecurity (NCSC) via the online reporting form – even as a private individual and already on suspicion
  2. For a criminal offence (fraud, extortion, identity theft), also alert the police via 117 and file a report
  3. Preserve evidence before deleting anything: keep screenshots, suspicious emails, sender addresses and timestamps
  4. Operators of critical infrastructure have been subject to a reporting obligation since 1 April 2025: cyberattacks must be reported to the NCSC within 24 hours

After: clean up

  1. Change passwords, monitor accounts and transactions
  2. Restore systems from a clean backup
  3. Learn from the incident: improve backups and protective measures
  4. Expect phishing waves in the aftermath of major disruptions

Where can I keep up with the cyber situation?

The NCSC is the Confederation's official reporting and analysis body – originally known as MELANI – and continuously publishes situation analyses for the public.

  1. NCSC half-yearly report: an in-depth overview of the threat landscape and current attack patterns in Switzerland
  2. NCSC weekly review: a short weekly summary of reported incidents
  3. Current NCSC warnings about ongoing phishing and fraud waves at ncsc.admin.ch
  4. During a major disruption, also use Alertswiss and radio (FM/DAB+) as network-independent information channels

What do I need during a cyberattack?

The best protection is everyday preparation – the most important «equipment» is up-to-date backups and good passwords.

  1. External drive/medium for offline backups (3-2-1 rule)
  2. Password manager and a two-factor app or hardware token
  3. Up-to-date devices with automatic updates enabled
  4. Small cash reserve in small notes
  5. Important contacts and account hotlines on paper (if digital is unreachable)

Common mistakes

  1. No backup – or only one backup that is constantly connected to the device
  2. The same password for many services, no two-factor authentication
  3. Clicking phishing links/attachments or paying a ransom
  4. Permanently postponing updates
  5. Relying on cashless payment alone

Frequently asked questions

Where do I report a cyberattack in Switzerland?

The Federal Office for Cybersecurity (NCSC) is responsible; it has existed as an independent federal office since 1 January 2024. Report incidents via the NCSC's online reporting form – even as a private individual. If it's a criminal offence, also alert the police via 117.

Where can I find reliable information about the cyber situation?

At the NCSC: it publishes a half-yearly report on the threat landscape, a weekly review of reported incidents, and current warnings about ongoing phishing and fraud waves. During a major disruption, Alertswiss and the radio also provide information.

What's the difference between phishing, ransomware and DDoS?

Phishing is fake messages that steal passwords or card details. Ransomware encrypts your data and demands a ransom. DDoS knocks a website offline through overload. Two-factor authentication, updates and offline backups protect against the first two; against DDoS, only waiting it out and switching to official channels helps.

Is the authority still called NCSC, or was it renamed?

Since 1 January 2024, the authority has held federal-office status – in Switzerland's national languages it is officially called Bundesamt für Cybersicherheit (BACS) in German, Office fédéral de la cybersécurité (OFCS) in French, and Ufficio federale della cibersicurezza (UFCS) in Italian. English is not an official Swiss language, so the authority continues to present itself in English as the National Cyber Security Centre (NCSC). Its name before NCSC was MELANI (Reporting and Analysis Centre for Information Assurance). The website still runs at ncsc.admin.ch.

Official sources