BCV-net and BCV Mobile will be unavailable on Saturday 08 March from 10h30 pm until Sunday 09 March 05:00 am due to server maintenance. We apologize for the inconvenience, and thank you for your patience.

Cybersecurity – mitigating the risk for your business

Cyberattacks can do extensive damage to a company’s finances, operations, and reputation. Find out how you can shield your business.

Use our online services securely

Following these simple steps will significantly lower your risk of falling victim to fraud when accessing BCV-net on the web or BCV Mobile on your phone.

Protect your business against cyberattacks

Cybersecurity for businesses rests on four pillars: governance and organizational structures, employees, technology, and business continuity.

Talk to the experts

Improve your security profile by harnessing the services offered by different types of specialists.

Respond swiftly in the event of a cyberattack

If you suspect a cyberattack or other security incident, the priority is to limit the impact, while preserving the information needed to analyze the incident.

Use our online services securely

Following these simple steps will significantly lower your risk of falling victim to fraud when accessing BCV-net on the web or BCV Mobile on your phone.

Our recommendations

  • Never share your log-in credentials (user ID, password, text message code, etc.) with another person, even if they claim to represent BCV or an IT service provider.

  • Only access BCV-net via our official channels, either by typing the URL directly in your browser or using your favorites. Do not click on links received via email or text message.

  • Only log in to BCV-net or BCV Mobile on workstations or mobile devices managed by your organization, with up-to-date antivirus software, security patches installed, and the firewall switched on.

  • Activate mandatory two-factor authentication for all users with access to your company’s online banking and other critical systems.

  • Assign your employees different access profiles (enter, approve, check) to avoid cases in which the same person can enter and then approve a payment.

Governance and organizational structures

  • Appoint a cybersecurity lead, even if the position is part-time, and work with your IT service provider to define clear roles and responsibilities.
  • Conduct regular IT security audits and intrusion tests to help pinpoint critical weak spots, then prioritize remedial measures.
  • Allocate the necessary budget to these functions.

Raising awareness among employees and suppliers

  • Hold regular training sessions to raise awareness about phishing, suspicious email attachments, fake tech support, and payment fraud scams.
  • Put in place an official set of simple procedures, such as for verifying requests to update banking details or for reporting incidents.
  • Make sure these measures are applied across the entire service chain. One weak link in a supplier’s ecosystem could endanger your own operations.
  • Remember, everyone has a part to play in keeping data secure: your company, your service providers, and your customers.

Key technical measures

  • Keep an updated inventory of your systems, ensure regular security updates are carried out, and deactivate any unnecessary services.
  • Segment your network (servers, workstations, production systems) and limit administrator rights by applying the ‘principle of least privileges,’ whereby users are given only the access they need to do their specific jobs.
  • Schedule and regularly verify encrypted backups that are at least partially ringfenced so that data can be restored in the event of an incident.

Business continuity

  • Draw up clear incident-response and business-continuity plans. These should include the names of responders, timetables for taking action, and the key priorities for critical functions.
  • Conduct exercises at least once a year to keep up with evolving threats, for example by simulating a ransomware attack or a hacked bank account. Update action plans based on what you learn from these exercises.

Talk to the experts

Improve your security profile by harnessing the services offered by different types of specialists.

Your IT provider

Your IT provider knows your systems and software and can help you implement practical measures such as keeping system inventories, managing updates, configuring backups, and setting up a firewall or multi-factor authentication.

Cybersecurity experts

  • Specialist companies can provide cybersecurity audits, intrusion tests, 24/7 surveillance (Security Operations Center - SOC), and advisory services, tailored to the needs and scale of your business.
  • They can also help you create multi-year roadmaps to steadily improve your level of protection.

National authorities and platforms

  • The Swiss National Cyber Security Centre (NCSC) issues recommendations and alerts and provides incident report forms that are available to all businesses.
  • Swiss authorities have published guides and aide-memoires that indicate the best practices that SMEs can implement step by step.

Respond swiftly in the event of a cyberattack

If you suspect a cyberattack or other security incident, the priority is to limit the impact, while preserving the information needed to analyze the incident.

Shore up the situation

  • Quickly isolate potentially compromised systems from the rest of the network (network cable, Wi-Fi, VPN), preferably without turning them off so that technical evidence can be preserved.
  • Immediately change passwords on critical accounts (e-banking, email, servers, administration) and shut down any access that appears suspect.
 

Get the right people involved

  • Inform senior management, the head of cybersecurity, and your IT provider right away.
  • Contact your cybersecurity business partner to request system diagnostics and crisis-management support.
 

Inform the competent authorities

  • Report the incident to the Swiss National Cyber Security Centre via their dedicated portal. This will help prevent future incidents, and you will receive a list of recommended measures to take.
  • If personal data has been compromised, consult your legal team (or outside advisor) to assess whether data protection authorities should be informed.
 

Communicate with stakeholders and keep records

  • Keep a chronological record of what happened, including the initial clues that something was amiss, the measures and decisions taken, and your communication with the parties involved.
  • Prepare a clear, factual message to your employees (and to your customers and business partners, if necessary), in conjunction with your legal and communications teams.

Common cyberattacks and possible solutions

Here are some common cyberattacks faced by businesses:

Arnaques aux faux conseiller
  • An employee opens an email attachment containing malware that gradually encrypts the entire network, making it impossible to access data or systems for several days.
  • Regularly tested, segregated backups and business continuity planning enable businesses to restore their systems and restart operations more quickly.

Fraude au paiement via compromission de messagerie
  • A hacker takes control of an internal email account and amends an invoice so that the payment – often for a large amount – is made to an account outside Switzerland.
  • By using dual authorization and requiring independent verification of changes to banking details, businesses can flag anomalies like these before the payment can be executed.

Tentative de phishing ciblant l’e-banking
  • An employee receives an email that appears to be from the company’s bank, asking them to click on a link to ‘secure’ their online banking access. The link redirects to a fraudulent website that records the employee’s login details for the scammers.
  • If businesses train their employees to watch out for phishing scams and systematically check links before clicking, employees will be much more likely to identify such emails as malicious and not disclose any login details.

Learn more about cybersecurity for businesses

Entreprises: la cybersécurité en question

Cybersecurity for SMEs (article in French)

Making your company cyberattack-proof (article in French)

Attaques visant le versement des salaires sur de faux comptes

Malicious attempts to redirect salary payments (article in French)

Useful links

Standing with you

Your BCV advisor is trained to advise you about cyber threats in connection with your business activities and how to securely use our online banking channels. For help implementing technical or organizational measures, we recommend that you contact your IT provider and other specialists as needed. The competent Swiss authorities can also provide useful information.

Write to us

If you are a BCV client with BCV-net, we suggest you log in to BCV-net and contact us using the secure messaging service.

Call us

We’re available Monday to Friday, from 8:00am to 6:00pm.

 

 

Visit us

Come to one of our branch offices.

FAQ

Carefully check the domain name. Even if one letter is wrong, this indicates fraud.

Disconnect immediately from the internet, change your passwords, and contact your internet service provider.

Yes, you can report suspicious emails at cybercrimepolice.ch (website in French, German, or Italian).