Cybersecurity in the Swiss Pharmaceutical and Healthcare Sector: Essential Measures to Protect Data and Operations

Pharmacies, pharmaceutical companies, and other organizations in the healthcare and life sciences sectors are increasingly reliant on IT systems, cloud applications, email, document management platforms, third-party providers, and digital infrastructure.

This evolution increases efficiency and the ability to manage complex processes, but it also creates new operational dependencies. A compromised account, a neglected update, or an unavailable cloud service can jeopardize access to personal data, regulatory and quality documentation, management systems, or information necessary for critical activities.

In a pharmacy, the unavailability of a management system can quickly disrupt day-to-day operations. In a pharmaceutical company, the same principle can apply to a document management system, access to GxP or regulatory documentation, personal data, platforms used by quality and supply chain departments, or services managed by IT and cloud providers.

This issue is particularly relevant in the healthcare sector. The Federal Data Protection Act (FDPA) classifies health-related data as personal data deserving special protection and requires that the data controller and data processor ensure, through appropriate technical and organizational measures, a level of security commensurate with the risk.

Note: This article is intended for informational and organizational purposes only and does not constitute legal advice. The applicability of specific obligations must be assessed on a case-by-case basis, taking into account the organization, the activities carried out, the data processed, the systems used, and applicable regulations.

Cybersecurity in the Pharmaceutical and Healthcare Sectors: What Are the Real Risks?

The most dangerous attacks do not necessarily require extremely sophisticated techniques. Many incidents begin by exploiting normal daily activities or dependencies on external parties.

An email that appears to be from a vendor may contain a phishing link. An employee may reuse a compromised password. An application may continue to run without receiving the necessary updates. An IT vendor may be attacked and indirectly become a point of entry for multiple client organizations.

The most recent available semi-annual report from the UFCS confirms that ransomware and data extortion remain a serious threat to Swiss organizations of all kinds and also draws attention to digital dependencies and software supply chain compromises. In the second half of 2025, 57 ransomware incidents were reported to the UFCS.

For a healthcare/life sciences company, the scenarios to consider therefore include:

  • phishing and social engineering;
  • ransomware and malware;
  • theft, misuse, or unauthorized sharing of credentials;
  • unauthorized access;
  • loss, corruption, or unavailability of data;
  • outdated software and systems;
  • compromise of the IT or cloud provider;
  • deletion or encryption of backups;
  • unavailability of the management system;
  • unauthorized use of laptops, smartphones, or other personal devices.

The risk does not only concern data confidentiality. The integrity and availability of information can also be critical to the continuity and reliability of business processes.

Legal requirements, official recommendations, and best practices: What’s changing?

Clearly distinguishing between these categories is essential to avoid both underestimating and overinterpreting the applicable requirements.

Obligations Under the LPD

The LPD requires risk-based security for personal data through appropriate technical and organizational measures. However, the law does not mandate that all organizations have an identical IT configuration.

The adequacy of the measures must be assessed by considering, among other factors, the type and sensitivity of the data, the purposes of the processing, the systems involved, the likelihood of an incident, and the possible consequences.

UFCS Recommendations for the Healthcare Sector

The Federal Office for Cybersecurity recommends that healthcare service providers implement minimum cybersecurity requirements, explicitly describing them as “best current practice.” The recommendations include both technical and organizational measures.

The areas mentioned include patch and lifecycle management, offline backup and disaster recovery, authentication protection, segmentation, and monitoring.

These guidelines serve as an official reference that is particularly useful for assessing the maturity of security measures, but they should not automatically be presented as legal obligations that apply uniformly to every pharmacy or pharmaceutical company.

Regulatory requirements, official recommendations, and voluntary measures must therefore be analyzed separately and considered within the specific context of the organization.

Real-World Scenario: When an Incident Disrupts Systems and Operations

Let’s consider a pharmaceutical company that receives an email that appears to be from a regular supplier. The message requests urgent authentication for a platform used for business operations.

An employee enters their credentials on a fraudulent page. The attackers then gain access to a company system, and the incident escalates to the point where some resources become unavailable.

In a pharmacy, the management software could be affected. In a pharmaceutical company, a document management system, quality documentation, regulatory information, or other applications used in internal processes could become temporarily inaccessible.

At that point, the organization must assess the scope of the incident, determine which data and systems have been affected, involve the appropriate parties, and ensure the continuity of priority operations.

This scenario illustrates why cybersecurity, data protection, supplier management, incident management, and business continuity should not be treated as completely separate disciplines.

What aspects should be included in the quality system?

The goal is not to turn the QMS into a technical cybersecurity manual. Rather, it is necessary to ensure that the main digital risks are managed, assigned, and documented in a manner consistent with the organizational system.

1. Define roles and responsibilities

The organization should know who is responsible for cybersecurity, who manages the systems, who assesses data protection implications, and who takes action when an incident could have operational or compliance consequences.

It is not necessary for all of these responsibilities to be assigned to the same department, but it should be clear where they begin and where they end.

2. Access Management

Access, privileges, and authentication should be commensurate with the activities performed and the criticality of the systems.

Measures such as multi-factor authentication can be a particularly important control for remote access, administrative accounts, and critical services. The UFCS includes it among the recommended measures for the healthcare sector.

3. Updates and Lifecycle

Software, systems, and components cannot be considered static.

Governance should make it possible to determine which systems are in use, who manages their updates, and how issues such as end-of-life products or significant vulnerabilities are addressed.

The most recent UFCS report also highlights ransomware incidents in which the failure to consistently apply the corrective measures recommended by the vendor contributed to the compromise.

4. Backup and Business Continuity

The existence of backups alone is not sufficient to demonstrate recoverability.

It is necessary to consider data protection, separation from operating systems, recovery capabilities, and alignment with the business continuity requirements of critical processes.

5. Train staff

Phishing, credentials, and social engineering demonstrate just how much security also depends on behavior.

Training should therefore be commensurate with the risks, roles, and systems involved and should be integrated into the regular process of raising awareness and providing updates to staff.

6. Devices and Access Methods

Laptops, smartphones, remote access, and personal devices can expand the scope of what needs to be managed.

The organization should determine which uses are permitted and under what conditions, thereby preventing informal operating practices from circumventing the measures established for the company’s systems.

Evaluate IT vendors as well

Dependence on IT, software, hosting, and cloud service providers makes supplier management an important component of cyber governance.

However, outsourcing an activity to a third party does not automatically mean transferring all responsibility to the service provider. Similarly, a service provider is not automatically liable for any incident affecting the organization: roles and responsibilities depend on the activities actually outsourced, the processing performed, the access rights granted, and the applicable agreements.

When a party processes personal data on behalf of the data controller, the LPD governs the delegation of processing to a data processor. The IFPDT notes, among other things, that the data controller must adequately regulate outsourced processing and ensure that the data processor operates within the permitted limits.

Six Key Questions for Assessing Cyber Governance

An initial reflection should not turn into a universal checklist or a do-it-yourself technical assessment. It can, however, begin with some high-level governance questions.

Are the truly critical systems and processes clear?

The organization should know which systems, data, and digital services can have a significant impact on operations, quality, compliance, or data protection.

Have roles and responsibilities been defined?

It should be clear who makes decisions, who handles the technical aspects, and who is involved when a cyber risk affects regulated processes or personal data.

Are the access levels consistent with the risk?

Access management should reflect roles, system criticality, and the actual work methods used.

Are backup and business continuity aligned with operational needs?

It is not enough to know that a backup exists; you need to understand whether the organization would be able to withstand the unavailability of its critical systems.

Are critical digital suppliers regulated?

Hosting, cloud services, software, and IT services can create significant dependencies and should be taken into account in the qualification and monitoring process to an extent commensurate with the risk.

Are important decisions documented?

Assessments, responsibilities, exceptions, and key security decisions should be traceable, especially when they may affect compliance, data protection, or business continuity.

These questions are not a substitute for a structured assessment; rather, they are intended to help determine whether cyber risk is actually managed or simply left to technology.

Incident response: a process that must be defined before an incident occurs

An organization should have a documented process for identifying, assessing, and managing security incidents, defining responsibilities, escalation procedures, and links to relevant business processes.

The level of detail must be commensurate with the organization’s actual circumstances and the risks involved. What matters is ensuring that, during an incident, cybersecurity, data protection, quality, and business continuity are not managed in an uncoordinated manner.

The process should also be reviewed and, where appropriate, tested. Significant events can subsequently serve as the basis for investigative and improvement activities consistent with the principles of CAPA and root cause analysis.

Data Breaches and Reporting: Distinguishing Between Different Obligations

The FADP governs personal data breaches. When a breach is likely to pose a high risk to the privacy or fundamental rights of the individuals concerned, the data controller must notify the FDPIC as soon as possible. The FADP does not specify a general 24- or 72-hour deadline that applies uniformly to every incident.

The requirement to report cyberattacks to the UFCS, which took effect on April 1, 2025, is different.

The LSIn identifies the authorities and organizations subject to the reporting requirement; the Cybersecurity Ordinance sets forth the implementing provisions and, in particular, the relevant exceptions. For organizations that are actually subject to the law, cyberattacks that meet the specified criteria must be reported to the UFCS within 24 hours of their detection.

It is therefore incorrect to state that all pharmacies, all pharmaceutical companies, or all healthcare organizations are automatically required to file a report within 24 hours.

Before applying this term, it is necessary to verify whether the event is subject to the LSIn and the OCS, any exceptions, and the specific nature of the event.

Some Recurring Organizational Challenges

Some problems arise not so much from a total lack of technical tools as from a lack of governance.

Some of the most common examples include:

  • to view cybersecurity as the sole responsibility of the IT department or IT vendor;
  • not having a clear understanding of which systems and vendors are truly critical;
  • to assume that having a backup automatically ensures business continuity;
  • failing to document significant responsibilities, assessments, and exceptions.

The point is not to add procedures for every possible scenario, but to ensure that the truly relevant aspects are identified and addressed in a proportionate manner.

Business Continuity: Preparing for the Unavailability of Critical Systems

The question we need to ask is not only how to prevent an incident, but also how to continue operations if a critical system were to become unavailable.

For a pharmacy, this could be its management software or an essential service. For a pharmaceutical company, it could involve document management systems, quality applications, operational infrastructure, cloud platforms, or services on which regulatory and supply chain activities depend.

Business continuity management should therefore also take into account digital dependencies and external suppliers.

Cybersecurity and business continuity pursue complementary objectives: reducing the likelihood of incidents, limiting their impact, and ensuring the organization’s ability to maintain or restore priority operations.

Conclusion

Cybersecurity in pharmaceutical and healthcare organizations cannot be reduced to the purchase of technical tools, nor can it be managed using a one-size-fits-all checklist.

An independent pharmacy, a large pharmaceutical company, and another healthcare organization may have systems, data, suppliers, processes, and risk profiles that differ significantly.

For this reason , critical systems, responsibilities, security measures, suppliers, data protection, business continuity, and any reporting requirements must be assessed within their respective contexts.

The value of a structured approach lies precisely in linking these elements to the quality and compliance system by establishing proportionate, documented, and verifiable controls.

Pharmanomos does not position itself as a provider of technical cybersecurity services, but it can assist pharmacies and companies in the healthcare and life sciences sectors in managing cyber risk within their quality management systems, identifying how it intersects with data protection, supplier management, incident management, and business continuity.