Switzerland’s Defence Chief Warns of Cyber and Foreign-Intelligence Pressure on Critical Infrastructure

Switzerland’s armed forces chief, Lieutenant General Benedikt Roos, has issued an unusually direct public warning: the country may be drawn into the strategic confrontation between Russia and the West because of the infrastructure it hosts and the role it plays in Europe.
In an interview reported by SWI swissinfo.ch on 9 September 2026, Roos said Switzerland should be regarded as a potential target for Moscow. His concern is not limited to a conventional military attack. He described a broader security problem involving cyber operations, sabotage, intelligence activity, unmanned aircraft and pressure on public confidence. 1
Roos’s central argument is geographical and functional. Switzerland is not only a neutral state in the middle of Europe. It is also a hub for systems that support neighbouring countries and the wider European economy. Electricity and gas networks, north-south transport routes and major data centres can carry consequences far beyond Swiss territory if they are interrupted.
“Switzerland has critical infrastructure that is vital to Europe as a whole,” Roos said, according to SWI swissinfo.ch. 1
That statement changes the usual way many people think about national protection. A disruption in Switzerland would not necessarily need to look like an invasion to produce international effects. A cyber intrusion against a network operator, a physical act of sabotage against a transport link or the manipulation of data could create delays, uncertainty and economic losses across borders.
Cyber operations are part of the security problem
The Swiss warning arrives alongside evidence that cyber incidents are already a persistent burden for citizens, companies and public institutions. The National Cyber Security Centre reported 34,789 cyber-incident reports during the first half of 2024, an increase of 15,740 reports compared with the same period a year earlier. Fraud, phishing and spam accounted for most reports, while ransomware continued to affect companies in different sectors. 2
Not every incident is an act of state aggression. Many are criminal schemes designed to steal money or credentials. The distinction matters, but it should not create false reassurance. Criminal campaigns can expose weak systems, steal data and provide access techniques that hostile intelligence services or proxy groups may later exploit.
The same official report recorded politically motivated distributed denial-of-service attacks against Swiss organisations and websites connected with major international events. The attacks caused limited disruption, yet they showed how public-facing digital services can become targets during moments of diplomatic or political attention. The report also discusses cyberespionage and cybersabotage in the context of geopolitical tension. 2
Switzerland’s Security Policy Strategy 2026 draft treats this challenge as a national-security issue rather than as a purely technical matter. It identifies the country’s electricity and gas exchanges, transport systems, financial services and international data connections as assets whose disruption could affect Switzerland and other states. The draft states that critical infrastructure may be attacked through cyber means, sabotage or, in extreme cases, long-range weapons. 3
The document also proposes stronger capabilities for detecting and analysing cyber threats at an early stage. It calls for timely technical information to be shared with operators of critical infrastructure. Another proposed measure would improve the state’s ability to counter espionage, infiltration and serious cyberattacks. 3
The intelligence dimension
Roos’s warning about foreign intelligence activity should be understood within this wider framework. Intelligence services do not need to destroy a facility to create strategic value. They may seek information about energy networks, defence procurement, transport schedules, industrial research, political decision-making or the resilience of a company’s digital controls.
The Swiss strategy draft explicitly links the protection of authorities, the economy, science and society with protection against infiltration by foreign intelligence services and organised crime. 3 In practice, that means security cannot be assigned to the armed forces alone. It requires coordination among the Federal Intelligence Service, police authorities, regulators, companies and local governments.
Espionage can also prepare the ground for a later operation. Information about network architecture, maintenance cycles or emergency procedures can help an attacker choose the most disruptive moment. A quiet intrusion may therefore be more consequential than a visible attack, especially if it remains undetected until a crisis begins.
Attribution remains a difficult problem. A server, account or drone may be linked to an intermediary rather than to the organisation that planned the operation. Roos’s comments reflect this uncertainty: he said that in roughly 20% of unauthorised drone cases over military sites, investigators could not identify the responsible actor clearly. 1
Drones, surveillance and the physical world
The chief of the armed forces also pointed to increased drone activity near critical infrastructure. He said no explosives had been found in the Swiss cases cited in the interview, while warning that this could change. Some flights may be recreational or careless. Others may involve surveillance, testing or preparation. The challenge is to distinguish among these possibilities without treating every unidentified object as proof of hostile action.
Roos acknowledged that the armed forces have a capability gap in counter-drone defence. At the same time, he said the number of small reconnaissance drones issued to Swiss troops had increased tenfold during the previous year. 1 The two developments illustrate an important asymmetry: acquiring low-cost surveillance technology can be quicker than building a reliable system to detect, classify and stop it.

Building a more integrated response
Switzerland has already taken steps to strengthen its cyber organisation. Parliament approved the creation of a larger cyber command structure, with a planned staff of up to 575 members by 2026. The rapid-response capacity is intended to provide subsidiary support to critical-infrastructure operators and private companies facing attacks. The sectors named in the earlier reporting included electricity, railways and telecommunications. 5
The official profile of Roos places Cyber Command inside the structure he leads, alongside the Armed Forces Staff, Joint Operations Command, Logistics Organisation and Training and Education Command. 6 That arrangement recognises that cyber defence is connected to logistics, communications, intelligence, training and operational planning.
Still, organisational reform is not the same as complete protection. Effective resilience requires tested backup systems, segmented networks, trained personnel, rapid reporting and clear decision rights. It also depends on companies being willing and able to share information about incidents before the damage spreads. The state can improve coordination, but each operator must understand which services are essential and how they would function during a prolonged outage.
Public communication is another part of readiness. Roos’s concern that public awareness remains too low is not a call for panic. It is a warning that democratic societies can be weakened by denial, confusion and delayed action. Citizens, journalists and businesses need enough information to recognise suspicious messages, verify claims and report incidents without amplifying unconfirmed accusations.
What does this actually mean?
It means Switzerland’s security debate is moving from a narrow question—whether the country might face a conventional attack—to a wider question about how an adversary could pressure the country without crossing an obvious military threshold.
The possible methods range from credential theft and espionage to ransomware, service disruption, surveillance drones and sabotage. They may be carried out by criminals, proxies, intelligence services or actors whose links remain unclear. The immediate task is not to label every incident as Russian or state-directed. It is to reduce vulnerability, improve detection and preserve the ability to attribute actions based on evidence.
For ordinary residents, the consequences may appear first as unreliable online services, fraudulent messages, transport interruptions or uncertainty about official information. For companies, the issue includes the security of suppliers, cloud services, remote access and industrial control systems. For the government, the challenge is to protect national interests while maintaining legal safeguards and public trust.
What is the true implication of this?
It matters because Switzerland’s importance extends beyond its borders. Energy transfers, rail routes, financial services and data connections make the country part of a network on which other European states depend. An incident inside Switzerland could therefore create effects elsewhere, even if the immediate damage were local.
It also matters because neutrality does not remove strategic relevance. A state can avoid joining a military alliance and still be valuable to an attacker because of its infrastructure, technology, financial system, diplomacy or position in regional supply chains.
Finally, the warning matters because resilience is cheaper and safer when built before a crisis. Better cyber monitoring, stronger intelligence coordination, counter-drone systems, protected communications and public preparedness can reduce the chance that a single breach becomes a wider emergency. The goal is not to predict every threat. The goal is to make hostile action harder, less rewarding and easier to contain.
Closing Thoughts
Roos’s message should be read as a request for seriousness, not as a forecast of inevitable war. Switzerland has strong institutions, skilled technical communities and a long tradition of civil protection. Those advantages are meaningful only when they are connected in practice.
The most useful response is disciplined preparation. Authorities should explain risks without exaggerating them. Operators of essential services should test how they would work during an extended outage. Companies should treat cyber security as an operational responsibility rather than an information-technology expense. Citizens should learn how to verify messages and report suspicious activity.
The debate will remain difficult because defensive investment competes with other public priorities and because attribution is often incomplete. Yet the cost of ignoring interconnected risks can be much higher. Switzerland’s protection will depend not only on weapons or networks, but also on trust, cooperation and the ability to act quickly when evidence is still incomplete.
References





Comments