Decoding the world of cybersecurity

· ·

Swiss cyber-unit inquiry leaves criminal questions open

A Swiss inquiry says earlier intelligence cyber-unit recommendations have largely been implemented, while unresolved questions about historic network-data sharing remain with federal prosecutors.

Swiss cyber-unit inquiry leaves criminal questions open
Summary
  • The administrative inquiry says previous organisational recommendations have largely been implemented and found no evidence of large-scale data deletion.
  • Earlier media allegations concerning classified information and Kaspersky are not treated by the inquiry as established facts.
  • Questions surrounding possible systematic network-data sharing remain subject to a federal criminal investigation.

Switzerland has closed another administrative chapter in a long-running examination of its intelligence service’s former cyber unit, while leaving a narrower but consequential set of questions with federal prosecutors.

The Swiss government said an independent administrative investigation into the former cyber division of the Federal Intelligence Service found that earlier organisational recommendations had largely been implemented and that the facts were sufficiently clarified for administrative purposes.

The review was commissioned by defence minister Martin Pfister and conducted by the law firm Lenz & Staehelin. It follows several investigations into concerns that emerged inside the intelligence service from 2021 onwards.

The latest inquiry found no evidence supporting claims that former members of the cyber unit deleted data on a large scale. It also concluded that earlier questions concerning the legality of obtaining certain data from internet service providers had been sufficiently clarified.

One issue remains unresolved. Swiss authorities said uncertainties persist around the former cyber unit’s relationship with Kaspersky and whether network data may have been shared systematically. Those concerns were referred to the Office of the Attorney General of Switzerland in 2025 and remain the subject of a criminal investigation.

Earlier media reports had gone further, alleging that classified information may have reached Russian intelligence through Kaspersky. The administrative inquiry does not establish that allegation as fact. Its public conclusion is narrower: questions remain about the historic cooperation and possible data-sharing arrangements, and prosecutors are still examining them.

The review also said it found no additional substantial evidence of prohibited political intelligence activity. The full report remains classified because it contains information about the operation of the intelligence service and names individuals, although the government has released a public summary.

The distinction between the administrative and criminal processes is important. The administrative inquiry examined organisational conduct, governance, earlier recommendations, and whether the service had corrected identified weaknesses. It did not determine criminal liability in matters that are now before federal prosecutors.

The history of the case illustrates the governance difficulty around cyber operations inside intelligence organisations. Technical teams may work with highly sensitive network information, commercial security vendors, classified material, and infrastructure telemetry that is not visible to ordinary oversight functions.

Controls therefore depend heavily on clear authority, documentation, supervision, and the ability of oversight bodies to reconstruct why particular data was obtained, shared, or retained. Reorganisations can make that harder when responsibilities, personnel, and reporting lines change repeatedly.

The new inquiry acknowledged that previous changes had affected the service’s internal culture of trust, even as it concluded that substantial improvements had since been made. Switzerland is continuing a wider transformation of the Federal Intelligence Service that is expected to conclude by the end of 2026.

The investigators recommended allowing the new structure to operate before assessing it again, with an evaluation no earlier than a year after the transformation has been completed. They also addressed internal mechanisms for reporting misconduct.

That leaves the service with two different measures of closure. Organisationally, the government considers most earlier recommendations implemented and the administrative facts sufficiently established. Legally, the question of possible historic network-data transfers remains open until prosecutors complete their work.

For an intelligence organisation whose cyber capabilities depend on access to sensitive infrastructure and information, that remaining question is narrow but significant. The eventual prosecutorial findings will determine whether the unresolved concerns amount to historic governance weaknesses alone or conduct with a more serious legal dimension.

×