top of page
Switzerland’s neutrality is becoming an operational exposure

25. Juni 2026

Richard Krauss

The Essentials in 30 Seconds
  • Russia remains the most acute threat actor affecting Switzerland. Intelligence collection, cyber-enabled activity, influence operations, sanctions evasion and suspected sabotage preparation form a connected hybrid threat environment.

  • Switzerland is not only a target area. Its role as a financial centre, research hub, digital infrastructure location and host of international organisations provides access opportunities for operations directed against European third states.

  • China presents a different risk profile: long-term access to technology, research, industrial capabilities and economic dependencies.

  • The NDB assessment on Iranian guided missiles is prospective. It describes a possible future expansion of Iranian strike reach into Europe, not a current direct missile threat to Swiss territory.

The 2026 assessment by Switzerland’s Federal Intelligence Service identifies a further deterioration in the national security environment. Russia remains the principal acute threat actor. Espionage, cyber activity, influence operations, sanctions evasion, terrorism and violent extremism do not operate as separate risk categories. They overlap within the same European operating environment.

Switzerland remains politically neutral. Operationally, it is embedded in the European hybrid threat space. Its international institutions, financial systems, research capacity and digital infrastructure create intelligence access, technical dependencies and disruption opportunities with effects beyond Swiss territory.

Switzerland as an intelligence access environment


Switzerland contains a dense concentration of diplomatic missions, international organisations, financial institutions, research centres and technology companies. This creates a target environment of European and global relevance.

The NDB identifies Russia and China as the principal sources of foreign intelligence activity. Russian services use diplomatic and consular cover to maintain operational access in Switzerland. The public assessment refers to dozens of suspected intelligence officers operating under diplomatic cover.


A substantial part of this activity is not directed solely against Swiss state institutions. Swiss territory provides access to international organisations, diplomatic communications, multilateral decision-making, sanctions coordination, technology relationships and transnational personnel networks.

The intelligence value of Switzerland therefore lies not only in national information. It lies in its proximity to actors and systems with European and international relevance.

Swiss territory functions as part of an expanded intelligence collection environment. Foreign services can use it to support targeting against third states, international organisations and transnational economic structures.


Russian hybrid activity reaches Swiss systems


Russia generates the most immediate hybrid pressure on Switzerland. The NDB assessment covers espionage, influence operations, cyber activity, sanctions evasion and the suspected preparation of sabotage activity.

The NDB does not report confirmed completed Russian sabotage attacks against critical infrastructure in Switzerland. It does assess that Switzerland may be used in the preparation of sabotage operations elsewhere in Europe. The report also identifies the misuse of Swiss IT infrastructure for cyber sabotage directed against targets outside Switzerland.

The public assessment does not disclose tasking chains, intermediary networks or specific operational structures. It does not permit reliable public attribution to particular Russian services, procurement cells or criminal facilitators.

The operational finding nevertheless carries weight. Swiss territory can provide concealment, infrastructure, technical access and logistical depth for activities whose intended effects occur in other European states.

Three sectors carry particular transnational relevance.


Digital infrastructure can provide routing capacity, technical cover and staging functions for cyber-enabled collection or disruptive activity against third-country targets.


Financial infrastructure creates access points for payment flows, corporate structures, strategic transactions and sanctions-evasion networks.


International organisations and diplomatic representation create a high-value intelligence environment. Information on personnel, communications, decision-making and coordination can generate effects far beyond Switzerland.


Influence operations target institutional resilience


The NDB assesses Russian influence activity as an effort to weaken confidence in democratic institutions and the transatlantic security framework.

The report notes increased German-language reporting by the Russian state outlet RT on Switzerland. The recurring narrative presented Switzerland as a country in decline.

This finding establishes the presence and intensification of hostile messaging. It does not quantify audience reach, penetration into Swiss public debate or direct political effect. The public report therefore does not support a conclusion that Russian information activity has measurably influenced elections, legislation or executive decision-making in Switzerland.

The report also does not publicly demonstrate how such narratives are disseminated through secondary channels or whether they have amplified existing domestic conflict lines.


Neutrality, sanctions, migration, energy policy, social tensions and distrust in political institutions may constitute potential narrative entry points. This remains an analytical assessment of vulnerability, not evidence of proven Russian influence effects in those fields.

The operational significance lies in persistent access to information spaces. Foreign actors can maintain narratives, prepare future influence operations and exploit political or social tensions when circumstances create favourable conditions.


China: strategic access to technology and economic structures


China occupies a different position in the threat hierarchy. Russia applies immediate hybrid pressure. China operates primarily through long-term access to research, technology, industrial capability and economic dependencies.


The Swiss research environment is attractive because of its precision industry, life sciences, advanced materials research, data-intensive innovation, artificial intelligence and dual-use technology base.


The risk is not restricted to traditional espionage. Technology access may occur through research cooperation, investment structures, corporate participation, talent recruitment, supply-chain relationships and data access.


The public NDB assessment does not identify individual Swiss cases or institutions. It describes structural exposure within the Swiss research and innovation ecosystem.

China’s use of economic dependencies as a political instrument adds a second operational dimension. The issue is not limited to technology transfer. It affects market access, procurement autonomy, strategic supply relationships and corporate decision-making.


Russian procurement networks and sanctions evasion


Russia remains the central actor affecting Switzerland in proliferation-relevant procurement and sanctions evasion. Russian networks obtain goods and technologies through third countries for defence-industrial production.

The NDB refers to machine tools acquired in Switzerland and subsequently transferred to Russia through indirect channels. This connects Swiss industrial capability to the regeneration of Russian defence production capacity.

The operational challenge lies in concealed end use. Third-country intermediaries, layered corporate structures, opaque financial flows and unreliable end-user documentation can obscure the final destination of controlled goods.

The relevant security question is therefore not limited to formal export-control compliance. It concerns the identification of intermediary companies, financing routes, procurement brokers and technical supply chains before controlled items enter Russian military-industrial networks.


Terrorism and protected-target risk


The NDB continues to assess the terrorism threat as elevated. The immediate risk is shaped primarily by jihadist-inspired individuals, online radicalisation and attack planning with limited logistical requirements.

The European threat environment is characterised by short preparation cycles, simple means and decentralised radicalisation pathways. These factors reduce warning time and complicate early detection.

Online radicalisation remains a central driver. The NDB also identifies the potential role of artificial intelligence in propaganda production and the adaptation of extremist content. Recommendation algorithms can accelerate exposure to radicalising material and reinforce closed ideological environments.

The conflict in the Middle East increases the risk of violence against American, Jewish and Israeli targets in Europe and Switzerland. This creates an immediate protection and intelligence requirement.

Relevant threat categories include jihadist-inspired individuals, surveillance activity against protected sites, state-linked or proxy-linked structures and the possible use of criminal facilitators. The public NDB assessment does not identify specific attack plots or operational cells.

Violent extremism also remains relevant. The NDB assesses the violence potential of the violent left-wing extremist milieu as high. The Middle East conflict may intensify mobilisation. Violent right-wing extremism remains a continuing security concern.


Iranian guided missiles: prospective capability development


The NDB states that Iranian guided missiles could reach larger parts of Europe within several years. This is a prospective, scenario-based capability assessment.

The public report does not provide technical range data, deployment patterns, target plans or evidence of an existing Iranian strike capability against Switzerland. Switzerland is not described as a current direct missile target.

The assessment indicates a possible future expansion of Iran’s strike envelope. It does not establish an imminent long-range missile threat to Swiss territory.

Iran’s more immediate relevance for Switzerland lies in protected-target risk, intelligence activity, cyber operations, potential terrorism financing and regional destabilisation effects.


Net assessment


Russia produces the most immediate security pressure on Switzerland. Intelligence activity, influence operations, suspected sabotage preparation, cyber-enabled misuse of Swiss infrastructure and proliferation-related procurement form a connected hybrid threat environment.

China presents a structurally different challenge. Its primary relevance lies in long-term access to research, technology, industrial capability and economic dependencies.

Iran-related risks are currently concentrated in protected-target security, radicalisation dynamics, cyber activity and regional spillover effects. The NDB missile assessment describes possible future capability development. It does not establish a current direct missile threat to Switzerland.

Swiss exposure does not arise primarily from conventional territorial vulnerability. It arises from the strategic functions concentrated on Swiss territory. Digital infrastructure, financial connectivity, research capacity and international institutions provide operational access for actors whose objectives extend beyond Switzerland.

Neutrality remains politically and legally relevant. It does not prevent foreign intelligence access, limit the use of Swiss-based systems for operations against European third states or remove Switzerland from Europe’s hybrid conflict environment.


Glossary


NDB

Federal Intelligence Service. Switzerland’s civilian intelligence service responsible for strategic warning, threat assessment and counterintelligence.


NDG

Federal Intelligence Service Act. The legal framework governing the mandate, authorities, oversight and information-collection powers of Switzerland’s Federal Intelligence Service.


VBS

Federal Department of Defence, Civil Protection and Sport. The Swiss federal department responsible for defence policy, national security coordination and oversight of the Federal Intelligence Service.


References

Federal Intelligence Service

Security Switzerland 2026. Public annual assessment covering espionage, cyber activity, sabotage, terrorism, violent extremism and proliferation.
www⁠.vbs⁠.admin⁠.ch/dam/de/sd-web/tfhqKbM8ZL5k/VBS-DDPS-NDB-Sicherheit-Schweiz-2026-de.pdf


Federal Department of Defence, Civil Protection and Sport

Official publication statement outlining the 2026 threat assessment and the Federal Intelligence Service’s principal security findings.
www⁠.vbs⁠.admin⁠.ch/de/newnsb/jyRmuld1hBVy


Swiss Radio and Television

Reporting on the publication of the 2026 intelligence assessment and the deterioration of Switzerland’s security environment.
www⁠.srf⁠.ch/news/schweiz/ndb-bericht-2026-ndb-sicherheitslage-der-schweiz-weiter-verschlechtert


Expertise Tags (no search)
bottom of page