Beyond Gravity, the aerospace supplier owned by the Swiss Confederation, announced on Friday that it had been the target of a targeted cyberattack. The case is a reminder that Swiss companies, including state-owned ones, are exposed. To understand what makes IT systems vulnerable and what helps protect them, an interview with Professor Mathias Payer published by EPFL at the end of September offers general insight, with no direct connection to this case.
What we know about the attack
According to SWI swissinfo.ch, Beyond Gravity detected the first signs of malicious activity in its IT environment on 12 August. The company believes a "highly professional" actor is behind the attack. That is its own assessment: as of Friday, the identity of the perpetrators was not known.
The investigation is being conducted with the Federal Office for Cybersecurity and the IT security firm Mandiant. Beyond Gravity says it has filed a criminal complaint and strengthened its security measures. A spokesperson told the AWP news agency that specialists were specifically searching for traces of the attackers and carrying out forensic analyses of the affected devices.
The company only went public several weeks after the first signs. The spokesperson explained this as follows: in the event of a cyberattack, thoroughness takes precedence over speed, and premature communication would have compromised the investigations.
Much remains unknown at this stage. The available sources say nothing about the method used by the attackers, which systems or data may have been affected, or any possible consequences for the company's operations. As a reminder, Beyond Gravity is owned by the Swiss Confederation and was separated from the defence group Ruag in 2022.
Why no system is flawless
In the interview published by EPFL, Mathias Payer, a professor at the HexHive Laboratory, starts from a technical observation. The software on a smartphone can comprise up to 100 million lines of code, written by thousands of people over several decades. Guaranteeing that such a body of code contains no vulnerabilities is, in his view, "impossible for now". Many flaws arise from interactions between components: an element that is correct in isolation can become problematic when combined with another.
The researcher also describes an asymmetry: the defender would like to find and fix every vulnerability, whereas the attacker only needs to discover one. The goal is therefore to eliminate the most accessible flaws quickly, forcing the attacker to invest ever more time, skill and money.
Several approaches exist to make hackers' work harder:
- Fuzzing: programs automatically and repeatedly test a piece of software in countless random situations, in order to trigger unexpected behaviour and reveal bugs.
- Mitigations: protections that do not remove the flaw but make it harder to exploit, for example by randomly changing the location of information in memory each time a program starts. They come at a cost, such as a slight slowdown, but provide additional protection.
- Compartmentalisation: isolating a library or component makes it possible to analyse and test it far more thoroughly than a 100-million-line whole.
What AI changes
For the researcher, artificial intelligence is "certainly" changing vulnerability research. He recounts revisiting a problem related to USB flaws that he had studied some ten years earlier: with several AI agents, he was able to automate a large part of a fuzzing campaign on a recent Linux kernel in about two days.
He adds a caveat, however. For simple vulnerabilities, the level of skill required is falling. But his good results also stem from his years of experience: "For now, AI mainly makes experts much more efficient." He expects a huge number of flaws to be discovered in the coming years, which will force software vendors to devote more resources to security.
On the Swiss side, the EPFL News article notes that the Federal Office for Cybersecurity received more than 27,000 voluntary reports in the first half of 2026, and AI makes it possible to further personalise fraud attempts.
Simple but effective measures
Mathias Payer's advice is aimed primarily at the general public. For the vast majority of attacks the public faces, he says, simple measures are "extremely effective":
- install updates, not only for your phone or computer, but also for your apps, Wi-Fi router, printer and other connected devices;
- back up your data regularly;
- use a password manager, with a different, strong password for each service;
- stay alert: if the manager suddenly refuses to fill in a password on a page, it may be a phishing site;
- for a sensitive call, for example from your bank, hang up and call back yourself, especially since AI can imitate a familiar voice.
The researcher also believes that responsibility should not rest on users alone. In his view, the market does not always push companies to invest enough in security, and a minimum level of regulation would be necessary: manufacturers of connected devices should, for example, be required to provide updates for a certain period.

