Liechtenstein — Cyber Threat Profile
Liechtenstein is a high-income EEA microstate whose financial-sector assets — roughly CHF 770 billion, about 100 times GDP across ten licensed banks and a large fund and trust industry — make it a premium target for financially motivated cybercrime and client-data extortion. Its cyber posture rests less on sovereign scale than on regulatory harmonization with the EU and Switzerland: the 2025 Cyber Security Law (CSG) transposes the EU NIS2 directive into national law, DORA has governed financial-sector ICT resilience under the Financial Market Authority (FMA) since February 2025, and the national CSIRT (CSIRT.LI, operational since 2023 and a FIRST member) coordinates incident response, with Liechtenstein institutions also tied into Switzerland's Financial Sector Cyber Security Centre. The most acute risk is ransomware and data-theft extortion against banks, funds and fiduciaries — a threat made concrete by the 2016 breach of Valartis Bank Liechtenstein, in which attackers stole client records and demanded Bitcoin ransoms. Sovereign capacity is small and the national cyber unit operates on business hours, but EU-grade private-sector controls materially offset this; Liechtenstein maintains no known offensive cyber programme.
Read the full analysis on IntelFusions