Thirteenth place can sound reassuring, but this list has no safe end. Before Swiss IT teams relax, or anyone else starts drawing conclusions about national security posture, it helps to know what the ranking measures and what it doesn't.
What the ranking measures
The ranking comes from Microsoft customer data. It is not a count of every attack in Switzerland, and it is not a per-capita rate or a judgment on how well Swiss infrastructure is defended. Microsoft's MDDR 2026 landing page says its customer-impact map uses Microsoft Threat Intelligence data on how frequently customers are targeted by malicious activity in each country. Each country is compared with others in its region, both as a share of regional activity and as a regional rank.
There's also a timing detail worth noting:
- The Swiss release says the result covers the first half of 2026.
- The report's map methodology covers a 12-month window, July 1, 2025 to June 30, 2026.
- The Swiss release doesn't explain how these two periods relate, so they shouldn't be treated as the same thing.
The release also doesn't give Switzerland's share of European activity, the number of affected customers, or how far apart the ranked countries are. So 13th tells you Switzerland's position, not how much activity is behind it.
A sister release from Microsoft France fills in one comparison: France ranked 17th globally and 6th in Europe. In Microsoft's telemetry, then, Switzerland sits clearly below its larger neighbours France and Germany. That fits the general pattern that bigger economies with more Microsoft customers produce more visible activity, but that's my analysis, not a Microsoft finding.
Section summary: Switzerland is 13th in Europe and 39th worldwide by how often Microsoft customers there were targeted. It's a useful signal about Microsoft's customer base, not a national risk score.
The five themes Microsoft stresses for Swiss organizations
The Swiss release boils the 2026 report down to five findings:
- AI is speeding up both attack and defense. Criminals use AI to work faster and at larger scale, and defenders use it to find, investigate and disrupt threats sooner.
- Identity is the main way in. Attackers go after people, accounts and credentials.
- Risk is interconnected. One compromised account, supplier, platform or service provider can cause damage well beyond a single organization.
- Speed matters. Organizations need to shorten the gap between detection and response and test their incident response regularly.
- Resilience is a business requirement. Keeping critical operations running during disruption, and recovering quickly, now counts as much as prevention.
Marc Holitscher, National Technology Officer at Microsoft Switzerland, framed it this way: "cyber risks rarely exist in isolation." He argued that cybersecurity, resilience and digital sovereignty are becoming inseparable priorities. Digital sovereignty is a pointed choice of words in the Swiss market, where data location and control come up often in cloud discussions. Readers should remember this is a Microsoft executive's view in a Microsoft press release promoting a Microsoft report, not independent confirmation of the ranking.
How the 2026 numbers compare with 2025
The year-over-year comparison of the telemetry figures Microsoft publishes about its own operations is revealing. The MDDR 2026 page lists more than 165 trillion security signals processed daily, 4.7 million net-new malware file blocks per day, 31 million identity-risk detections analyzed on an average day, and 5.2 billion emails screened daily.
Here's the 2025 edition, as summarized on Microsoft's own security blog: Microsoft processed more than 100 trillion security signals, blocked approximately 4.5 million new malware attempts, analyzed 38 million identity risk detections, and screened 5 billion emails for malicious content each day.
| Metric (daily) | MDDR 2025 | MDDR 2026 |
|---|---|---|
| Security signals processed | 100+ trillion | 165+ trillion |
| New malware blocks | ~4.5 million | 4.7 million |
| Identity risk detections analyzed | 38 million | 31 million |
| Emails screened | 5 billion | 5.2 billion |
Signal volume rose about 65%. Identity-risk detections fell. Microsoft doesn't explain the drop in the material reviewed here, and the wording differs slightly between editions, so it can't be read as identity attacks declining. The 2026 report actually puts identity at the center of its argument. Possible explanations include changed counting methods, better upstream filtering, or a real change in activity, but those are guesses, not facts.
These are vendor-reported numbers about Microsoft's own visibility. They show how much Microsoft can see, not how much happens across the whole internet.
Section summary: Microsoft says it sees more signals than a year ago. The one metric that went down, identity-risk detections, has no explanation in the published material.
Global findings that matter in Bern, Basel and beyond
The Swiss release is short, but the full MDDR 2026 page adds detail that applies to any Windows and Microsoft 365 environment:
- 63% of intrusions involved data theft.
- Exposed cloud workloads were attacked after an average of 5.3 hours. For contrast, Protiviti's summary of the 2025 report said attackers can compromise exposed cloud assets in 48 hours, often faster. The two figures may not be measured the same way, so treat this as a direction of travel rather than an exact comparison.
- 52.2% of intrusions using valid accounts led to further credential theft. One stolen identity tends to lead to more.
- 89–95% of email phishing attachments led to a credential-theft attempt.
- More than 145 million QR-code phishing attacks were detected by Microsoft Defender for Office 365 between July 2025 and June 2026.
- Ransom detonations against enterprises rose 15.8% year over year.
- 78% of observed attack techniques against critical infrastructure involved cloud identity abuse.
In a same-day post, Microsoft's Mike Yeh wrote that government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025. He also noted that dwell time, the period between when an attacker gains access and when defenders detect and stop them, also increased this year across multiple sectors. The same post says phishing made up 23% of observed intrusions in 2026, up from 7% in 2025.
None of these figures are Switzerland-specific, and they shouldn't be read as Swiss results.
For forward-looking risk, Microsoft names three threats it expects to matter most over the next year: open-source supply-chain compromise, attacks on edge devices, and AI as a force multiplier for malicious activity. It also points to a December 2025 case in which a malicious browser extension with more than 600,000 installs collected ChatGPT and DeepSeek conversation history, affecting nearly 10,000 organizations before it was stopped.
AI agents: a new kind of identity
Terrell Cox, Microsoft's CVP and Deputy CISO, wrote a same-day explainer (published in French by Microsoft France) that pushes the identity theme somewhere many IT teams aren't ready for: AI agents. He describes agents as entities that interact with enterprise data, apps, APIs and tools, with different levels of access and autonomy. That raises questions about agent identity, appropriate permissions, agent-to-agent authentication, attributing actions, and revoking access.
Cox also urges some caution. He says attackers do use AI for reconnaissance, social engineering, malware and exploit development, and post-compromise work, but that use is still concentrated in particular stages of existing attack chains. The MDDR page lists five risk areas for agents: prompt and intent manipulation, sensitive data exposure, identity and privilege compromise, excessive agency, and operational integrity. So yes, AI is changing things, but the old attack methods are still doing most of the damage.
What admins should do now
Microsoft's recommendations, combined with standard industry practice (the general practice items are my synthesis, not Microsoft's wording), come down to a short list:
- Move to phishing-resistant MFA and passkeys. The report names these, together with disciplined identity hygiene, tiered administration and strong privileged-access enforcement, as the best safeguards.
- Inventory non-human identities. Service principals, app registrations, automation accounts and now AI agents all belong in the same governance process as people.
- Cut standing privilege. The report says attackers consistently exploit unnecessary privileges and persistent access.
- Reduce data oversharing before rolling out AI assistants. Microsoft recommends sensitivity-aware access and least-privilege controls across AI, cloud and app environments.
- Correlate your telemetry. The report calls signal correlation across endpoint, identity, cloud, app, email and network data one of the highest-leverage choices defenders control.
- Patch and harden edge devices. They're on Microsoft's short list of the biggest threats for the next year.
- Measure exposure, not patch counts. Microsoft recommends tracking exposure reduced, detection coverage gained and time-to-mitigate shortened.
- Run incident-response exercises. If dwell times are rising, finding out how long your detection really takes during a tabletop exercise is much better than finding out during a ransomware attack.
Bottom line
For Swiss organizations, the 13th-place ranking is a useful data point but a weak basis for decisions. It reflects how often Microsoft customers were targeted, it covers a time window the release doesn't fully reconcile with the report's methodology, and it comes without the underlying counts. The broader report is the more useful read: identity is how attackers get in, AI agents bring new identities to govern, and dwell time is getting longer. Wherever Switzerland lands on the list, the defensive work is the same.
References
- Switzerland ranks 13th among the countries most impacted by cyber activity in Europe - Microsoft Source Microsoft Source · 2026-10-01T14:18:33+00:00
- Preparing governments for an era of interconnected cyber risk - Microsoft On the Issues blogs.microsoft.com
- Microsoft Digital Defense Report 2026 | Microsoft microsoft.com