When a Swiss commune or SME is hit.
The response plan.
In 2026, cyberattacks stopped being a distant threat for French-speaking Switzerland: from Valais communes to healthcare networks, they are hitting organisations that thought themselves too small or too local to interest anyone.
2026-09 · 8 MIN READ
The year was brutal and local. The Valais commune of Vétroz saw its administration entirely paralysed — "the administration no longer runs," its president admitted. Months later, the mailbox of Martigny-Combe's municipal secretariat was compromised and used to send fraudulent messages to its contacts. And the Réseau Radiologique Romand was hit by ransomware for the second time in twelve months, disrupting patient examinations across the region.
What do they have in common? None is a giant. They are exactly the kind of organisations — communes, SMEs, practices, health networks — that make up the fabric of French-speaking Switzerland. Across 2025 the OFCS received nearly 65,000 reported cyberattacks; in 2026 reported incidents jumped by roughly a third, and ransomware attacks on SMEs rose by more than half. The question is no longer "can this happen to us" but "will we be ready when it does."
Before the attack: the four foundations that change everything
The difference between a contained incident and weeks of paralysis is decided almost entirely before the attack:
- Offline, tested backups. Ransomware seeks out and encrypts your connected backups too. A backup that isn't isolated — and whose restore has never been tested — isn't a backup, it's a hope.
- MFA on every account, no exceptions. Most intrusions begin with a stolen or reused credential. MFA remains the highest-return control for closing that door.
- Detection that watches overnight. Vétroz and the others weren't attacked at 10am on a Tuesday. EDR on every endpoint and SOC monitoring shrink the gap between intrusion and discovery — often from weeks to minutes.
- A written response plan. Who decides to disconnect the network? Who notifies the OFCS and the FDPIC, and within what deadline? Who speaks to the media, residents, patients? Decided calmly, this plan fits on two pages. Improvised mid-crisis, it costs days.
During the attack: the first hours
If an attack happens, the order of actions matters. Isolate affected systems to stop the spread, without shutting everything down (forensic evidence lives in memory). Don't rush to pay: the position of the OFCS and experts is clear — paying the ransom guarantees nothing and feeds the criminal model. Document the incident from the first hour. And report it: depending on your nature, the 24-hour ISA duty and/or the nLPD notification to the FDPIC apply.
Vétroz, Martigny-Combe, the Réseau Radiologique Romand: the common thread isn't size or sector. It's that none of these attacks was prevented by luck. They were suffered because preparation was missing, or contained because it was there.
What we do for organisations in the region
InterHyve supports exactly these organisations from Geneva: SMEs, communes, foundations and administrations across the Lake Geneva region. In practice that means putting the four foundations above in place, monitoring your environment 24/7 from our Geneva SOC, and holding the response plan with you — so that the day an attack comes, you know exactly what to do, and someone is already watching alongside you.
Book a free auditWould you be ready if the attack came tonight?
Our free audit checks your backups, MFA, detection and response plan — and shows you exactly where you're exposed.