
ISO 42001 Audits in 2026: The AI Management System Evidence Playbook
ISO/IEC 42006 changed who can certify you, ISO 19011:2026 changed how the audit runs, and the Omnibus moved the AI Act deadlines. What an AIMS audit demands, evidence by evidence.
Swiss organisations are adopting artificial intelligence faster than they are hiring the people meant to secure it. A new Abilene Academy study across thirteen cantons finds nearly six AI roles for every cybersecurity role in the least-prepared canton.

Swiss organisations are adopting artificial intelligence faster than they are hiring the people meant to secure it. A new Abilene Academy study, which analysed job postings on Glassdoor across thirteen cantons, surfaces a gap that is getting hard to ignore: in the least-prepared canton there are nearly six open AI roles for every open cybersecurity role. As organisations widen their digital footprint, the security meant to protect it falls behind, and that is exactly where the risk begins.
At the top of the least-prepared ranking, Vaud posts a readiness score of 14.12 out of 100. Behind that number sits a telling ratio: 69 open cybersecurity roles against 393 AI roles, or nearly 5.7 AI hires for every security hire. A gap that wide suggests Vaud's organisations are extending their digital capability far faster than the skills meant to defend it, advancing with an exposure that grows quicker than their ability to watch over it.
At the other end of the table, Basel-Landschaft earns a perfect score of 100. It is the only canton where cybersecurity roles outnumber AI ones, at 1.24 security roles for every AI role, which makes it close to seven times better prepared than Vaud. Between the two extremes sits Zürich, the most populous canton and by far the largest employer in both fields, in fifth place with roughly 2.8 AI roles for every cybersecurity role, proof that a high volume of tech jobs does not guarantee balance.
The same imbalance runs from one sector to the next. Consumer goods comes out least prepared, with a single cybersecurity role for every nine AI roles, while tax and accounting services show the best balance at three security roles for every AI role. The context gives those numbers their weight: according to Deloitte, 53% of Swiss executives have already built AI into their workflows, so the exposure is widening across almost every organisation, prepared or not.
Every AI system that goes live widens an organisation's digital footprint, and with it the attack surface. When cybersecurity hiring fails to keep pace, blind spots multiply: data leaks, AI-assisted phishing, prompt-injection attacks and regulatory breaches all grow more likely at the very moment systems proliferate. The answer is not to slow AI down but to govern it, framing its adoption with recognised standards such as ISO 27001 for information security and with the obligations tightening across Europe, from the NIS 2 Directive to the Cyber Resilience Act.
The study's message is direct: cybersecurity can no longer be a secondary strand of digital transformation, it has to be designed into the AI strategy from the start. In practice that means bringing the pace of security hiring closer to the pace of AI adoption, and putting in place the skills, processes and governance to carry it. Five priorities stand out:
Closing the gap starts with people. As the only PECB Titanium Partner in Switzerland, Abilene Academy trains and certifies the roles most in demand: ISO 42001 Lead Implementer to govern the AI organisations are deploying, Lead AI Risk Manager to manage its specific risks, and Lead Cybersecurity Manager to build the defensive capability that has not kept pace.
Further listening: Alexis Hirschhorn, CEO of Acuna GRC in Morges, discussed these questions on Swiss radio LFM's programme Le 6-9 (in French), on the opportunities and dangers of artificial intelligence for Swiss companies.
Swiss companies are adopting AI at an unprecedented pace, but many are building their AI capability faster than they are investing in the people needed to secure it. Every new AI system widens the organisation's digital footprint, and with it its exposure. These findings are a reminder that cybersecurity can no longer be a secondary strand of digital transformation: security has to be built into the AI strategy from the design stage, with the skills, processes and governance to match.
Alexis HIRSCHHORN, Information security and cybersecurity trainer, Abilene Academy| Rank | Country | Cyber readiness score/100 | Cyber-to-AI hiring ratio% |
|---|---|---|---|
| 1 | VDVietnam | 14.12 | 18 |
| 2 | BSBahamas | 19.05 | 24 |
| 3 | SGSingapore | 25.40 | 32 |
| 4 | TITI | 27.04 | 34 |
| 5 | ZHZH | 28.41 | 35 |
| 6 | BEBelgium | 29.41 | 37 |
| 7 | ZGZG | 32.82 | 41 |
| 8 | TGTogo | 36.67 | 46 |
| 9 | GEGeorgia | 37.14 | 46 |
| 10 | GRGreece | 43.66 | 54 |
| 11 | AGAntigua & Barbuda | 44.00 | 55 |
| 12 | SOSomalia | 51.48 | 64 |
| 13 | BLSt. Barthélemy | 100.00 | 124 |
Abilene's own calculation, not endorsed by ITU, IMD or EuRepoC.
Abilene Academy collected job postings published on Glassdoor in Switzerland in April 2026 across cybersecurity, artificial intelligence and technology, to measure hiring imbalances by canton and by sector. Cybersecurity roles were defined as functions that protect an organisation's digital footprint, while AI and technology roles cover those that extend it, and that widen the potential attack surface in doing so.
Two indicators were calculated for each canton and sector. The cybersecurity-to-AI hiring ratio expresses the number of cybersecurity postings as a percentage of AI and technology postings: a ratio of 50% means one security role for every two AI roles. The cyber readiness score, out of 100, normalises that ratio against the best-prepared canton or sector, which is set to 100; a canton scoring 33.3 is therefore hiring cybersecurity talent at less than a third of the rate of the best-prepared canton.
The thirteen cantons with sufficient data were included. The data were collected in April 2026 and are accurate as at the time of collection.
Data collected April 1, 2026
Editions used: Abilene Academy analysis, Glassdoor data (April 2026)
Vaud, with a cyber readiness score of 14.12 out of 100. It has 69 cybersecurity roles against 393 AI roles, or nearly 5.7 AI hires for every security hire.
Basel-Landschaft, with a perfect score of 100. It is the only canton where cybersecurity roles outnumber AI ones (1.24 to 1), nearly seven times better than the lowest-ranked canton.
Every AI system that goes live widens the organisation's digital footprint and its attack surface. When cybersecurity hiring does not keep pace, the risk of data leaks, AI-assisted phishing, prompt injection and non-compliance rises.
Consumer goods, with one cybersecurity role for every nine AI roles. Tax and accounting services are best prepared, with three security roles for every AI role.
According to Deloitte, 53% of Swiss executives have already built AI into their workflows, widening the exposure across most organisations.
Build security into AI projects from the design stage, bring cybersecurity hiring closer to the pace of AI, govern AI with a dedicated framework (ISO/IEC 42001), assess AI-specific risks, and anchor security accountability at board level.
Abilene Academy, a PECB Titanium Partner, using job postings published on Glassdoor in Switzerland (cybersecurity, AI and technology) collected in April 2026, covering thirteen cantons.
Abilene's own calculation, not endorsed by ITU, IMD or EuRepoC.
Abilene Academy, AI vs cybersecurity: the hiring imbalance across Swiss cantons (2026). https://www.abileneacademy.ch/en/research/swiss-cantons-ai-vs-cybersecurity-hiringhttps://www.abileneacademy.ch/en/research/swiss-cantons-ai-vs-cybersecurity-hiringClick the citation to select it, then copy.
Abilene Academy is Switzerland's #1 PECB Titanium Partner — the highest accreditation level in the sector — offering certified training in information security, data protection, AI governance and GRC compliance. The only trilingual EN·FR·ES programme in Europe.

Abilene Academy as part of Abilene Group SA is proud to announce that our Information Security Management System (ISMS) has been certified to meet the requirements of the ISO/IEC 27001:2022 standard!

This achievement marks a significant moment in our journey, reflecting our unwavering commitment to excellence in professional training and certification. Our sincere gratitude goes out to all our course participants, whose trust and dedication have made this possible, as well as our valued trainers, and to PECB, for their continued support.
Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.