Don’t do SECURITY. Do business SECURELY.

Switzerland makes cyber attack reporting mandatory for critical infrastructure

Swiss critical infrastructure operators must now report cyber attacks to the National Cyber Security Centre within 24 hours.

A mandatory obligation to report cyber attacks comes into force today under Switzerland’s Information Security Act, applying to operators of critical infrastructure.

Key points

  • Cyber attacks must be reported to the federal cyber security authority within 24 hours of discovery.
  • Applies to critical infrastructure operators, including energy, healthcare, finance, transport and public authorities.
  • Fines for failure to report can be imposed from 1 October 2025.
  • Reports are made through a dedicated online reporting portal.

UK suppliers to Swiss critical infrastructure should expect clients to require prompt notification of incidents so they can meet the 24-hour deadline.

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights