← All insights

Cyber Risks and Data Protection: External Service Providers as an Underestimated Threat

Published: 15 July 2025

Cyber Risks and Data Protection: External Service Providers as an Underestimated Threat

In conversations with executives, I often meet a dangerous misconception. Many consider their own company too small or too insignificant to be a target for cyberattacks. That assumption is deceptive. Small and medium-sized enterprises are squarely in focus, and the board carries the legal responsibility. A lack of technological competence offers no protection from liability.

Outsourcing: From Efficiency Gain to Risk Driver

Recent studies and supervisory reports are clear. Outsourcing core business processes to specialised IT providers, cloud vendors or SaaS platforms raises efficiency. At the same time, it markedly increases the complexity and vulnerability of the value chain. Attackers increasingly gain access to sensitive data and systems through external partners, often the weakest link in the chain. According to FINMA, in 2023 nearly one third of all cyber incidents in the financial sector were caused by external service providers or their subcontractors.

Financial service providers, fiduciaries and family offices are particularly exposed, because data protection and confidentiality sit at the core of their business. Yet the risks along the supply chain also keep rising in retail, industry and human resources. Attacks through service providers can have serious effects on operations, customer trust and reputation.

The Most Common Threats at a Glance

  • Concentration and cluster risks: Many companies depend on a few large providers such as Microsoft, AWS or specialised IT outsourcers. A failure or security incident at one of them can hit several companies at once and even trigger systemic risk. In my experience, the blind trust placed in large providers is deceptive, and the risks are underestimated. Precisely because of their importance, these platforms are prime targets for deliberate attacks.
  • Data leaks and loss of control: Outsourcing personal or confidential data brings the risk of weak protection or accidental disclosure, whether through cyberattacks, misconfigurations or poor standards at the provider.
  • Lack of transparency: The outsourcing company often cannot see clearly how and where data is processed, stored or passed on, especially with sub-outsourcing or international cloud providers.
  • Legal risks and reporting duties: Data protection breaches can lead to substantial fines, regulatory measures and reputational damage. Companies in Switzerland and the EU must report incidents without delay, even when they arise at a provider.
  • Inadequate data management: In practice, companies frequently lack an overview of which data is stored or processed by the outsourcer. Tasks can be outsourced. Responsibility for data protection stays with the company and cannot be delegated. The board is clearly accountable here.

Regulatory Requirements and Best Practices

Supervisory authorities keep tightening the requirements for outsourcing management. The expectation is unambiguous. Companies must know at all times which data, processes and systems are outsourced, how risks are monitored and which exit strategies exist. The following measures have proven especially effective:

  • Careful selection and regular review of providers, including their subcontractors
  • Binding contracts with clear requirements on information security, data protection and audit rights
  • Continuous monitoring, audits and review of safeguards, both technical and organisational
  • Cyber exercises and emergency drills to strengthen resilience and response capability
  • Compliance with all reporting and documentation duties (FADP, GDPR, FINMA)

Conclusion

Cyber risks and data protection breaches involving external service providers rank among the greatest challenges for management and the board today. This holds above all in sectors where trust, integrity and discretion are central values. Anyone who loses control over outsourced processes or underestimates the risks puts the company and their own reputation on the line. Responsibility always stays with the company, and above all with the board.

A change of thinking is therefore needed. Cybersecurity and data protection are strategic topics that belong on the board’s agenda. External service providers must be built systematically into cyber risk management and data protection, then documented and controlled.

Only in this way can a lasting balance between efficiency, innovation and security be achieved.