ThreatDesk — Primary Intelligence

Who is targeting
Swiss interests?

Structured, recurring adversary dossiers for organizations whose exposure to foreign state threat actors cannot be addressed by asking NDB to task foreign services. Finished intelligence, not raw feeds.

3
Primary adversary sets under active tracking
Monthly
Dossier production cadence
100%
Swiss-specific primary collection gap
OSINT+
Multi-source methodology
Request Access Limited intake — three positions remaining for new clients in Q2 2026.
The ThreatDesk Advantage

Why Swiss organizations
turn to us

NDB cannot task foreign services for Swiss-specific primary collection. ThreatDesk fills that gap with structured, recurring intelligence built for your exposure profile.

Swiss-Specific Collection

Primary collection focused exclusively on Swiss financial, pharmaceutical, and government IT sectors. No generic threat feeds — only actors with documented targeting patterns against your vertical.

Finished Intelligence, Not Data

Every product is analyst-written: adversary TTPs, contextualized IOCs, and assessment confidence levels. No raw SIGINT dumps, no vendor scorecards — intelligence you can act on.

Regulated Sector Expertise

Analysts with direct experience supporting Swiss private banks, pharma security teams, and federal IT programs. Reports are written for CISO and board-level consumption, not just technical teams.

Intelligence Products

Three products. One
coherent threat picture.

Each product serves a distinct decision-maker — from the analyst triaging an alert to the CISO presenting to the board. Together they form a complete intelligence lifecycle.

01 — Adversary Dossiers

Adversary Dossiers

Monthly deep-dives on the three primary adversary sets with documented intent against Swiss interests. Each dossier covers attribution confidence, capability assessment, infrastructure patterns, and recommended mitigations tailored to your sector.

Monthly · Per-Sector Edition
02 — Threat Briefs

Threat Briefs

Weekly 2-page briefs on emerging activity, notable shifts in adversary posture, and early-warning indicators relevant to your organization. Delivered as a readable PDF and searchable archive — no portal login required.

Weekly · Active Monitoring
03 — Indicator Feeds

Indicator Feeds

Structured IOC feeds (IP, domain, hash) sourced exclusively from Swiss-relevant collection, not aggregated from open-source aggregators. Delivered in STIX/CSV/JSON. Integrates with your SIEM or threat platform with a single import.

Daily · STIX/CSV/JSON
Client Sectors

Built for organizations that
cannot afford generic reports.

Every sector we serve has a specific intelligence gap. Our collection is scoped accordingly — and our reporting reflects that specificity.

Swiss Private Banks

Adversary intelligence scoped to financial-sector targeting: credential harvesting campaigns against banking infrastructure, supply chain compromise of core banking software vendors, and state-nexus financial espionage by actors with demonstrated interest in Swiss wealth management data.

Banking Wealth Management Private Equity

Pharmaceutical Companies

Collection on threat actors targeting R&D data, clinical trial information, and intellectual property. Scoped to actors with documented history of pharmaceutical espionage and APT groups with observed interest in Swiss life sciences — not generic healthcare sector reporting.

R&D Clinical Trials IP Espionage

Government IT Vendors

Intelligence on adversaries targeting Switzerland's federal IT supply chain. Covers software vendors with federal government contracts, managed service providers serving cantonal or federal agencies, and the specific TTPs of actors observed targeting Swiss government technology providers.

Federal Contracts MSPs Supply Chain

Critical Infrastructure

For organizations operating energy, transport, or telecommunications infrastructure in Switzerland. Scoped collection on actors with demonstrated intent against Swiss CNI — not generic critical infrastructure advisories. Includes sector-specific actor motivation analysis and physical-cyber convergence insights.

Energy Transport Telecoms
Limited Intake — Q2 2026

Three positions.
Swiss interests only.

ThreatDesk operates as a closed-access intelligence service. Intake is limited to organizations with a documented Swiss national interest exposure. Each client receives a sector-specific edition of every product — no shared generic reports.

3
Adversary sets under active tracking
Monthly
Dossier production cadence
4
Client sectors supported
2024
Operations established
Request Access Response within 2 business days. Confidentiality assured.