A mandatory obligation to report cyber attacks comes into force today under Switzerland’s Information Security Act, applying to operators of critical infrastructure.
Key points
- Cyber attacks must be reported to the federal cyber security authority within 24 hours of discovery.
- Applies to critical infrastructure operators, including energy, healthcare, finance, transport and public authorities.
- Fines for failure to report can be imposed from 1 October 2025.
- Reports are made through a dedicated online reporting portal.
UK suppliers to Swiss critical infrastructure should expect clients to require prompt notification of incidents so they can meet the 24-hour deadline.
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.