Gestisci i cookie
Questo sito utilizza i cookie per raccogliere informazioni sulle tue attività di navigazione al fine di fornirti contenuti e materiale promozionale più pertinenti, e per aiutarci a comprendere i tuoi interessi e a migliorare il sito. Visita la nostra informativa sui cookie per saperne di più.
Gestisci i cookie
Impostazioni dei cookie
I cookie necessari al corretto funzionamento del sito sono sempre abilitati.
Gli altri cookie sono configurabili.
Cookie essenziali
Sempre attivi. Questi cookie sono essenziali per consentirti di utilizzare il sito web e le sue funzionalità. Non possono essere disattivati. Vengono impostati in risposta alle tue richieste, come ad esempio l'impostazione delle preferenze sulla privacy, l'accesso o la compilazione di moduli.
Cookie analitici
Disabile
Questi cookie raccolgono informazioni che ci aiutano a capire come vengono utilizzati i nostri siti web o quanto sono efficaci le nostre campagne di marketing, oppure ci aiutano a personalizzare i nostri siti web per te. Consulta qui l'elenco dei cookie analitici che utilizziamo.
Cookie pubblicitari
Disabile
Questi cookie forniscono alle società pubblicitarie informazioni sulla tua attività online per aiutarle a mostrarti annunci pubblicitari più pertinenti o a limitare il numero di volte in cui visualizzi un annuncio. Queste informazioni possono essere condivise con altre società pubblicitarie. Consulta qui l'elenco dei cookie pubblicitari che utilizziamo.
Swiss Information Security Act (ISG): 24 Hour Reporting Explained | Resilience Guard
The Swiss ISG in English

Switzerland's 24 hour cyber reporting duty, explained.

The Information Security Act binds operators of critical infrastructure, transport undertakings expressly included, to report cyberattacks to the federal authority within twenty four hours of discovery, with financial penalties now enforceable. Here is what the law requires and how to be ready for it.

The law

What is the Information Security Act?

The Swiss Information Security Act (Informationssicherheitsgesetz, ISG, SR 128) is Switzerland's framework law for information security in the federal sphere and for the protection of critical infrastructure. In force since 1 January 2024, it introduced, through its cybersecurity provisions, a legal obligation on operators of critical infrastructure to report cyberattacks to the Federal Office for Cyber Security (BACS) within twenty four hours of discovery, applicable since 1 April 2025.

The mechanics are precise. The clock starts when the attack is discovered, not when it is understood. The initial report is made via the Cyber Security Hub, and the operator then has fourteen days to complete it as the picture clarifies. Since 1 October 2025 non compliance is enforceable with fines of up to CHF 100,000. The scope covers the operators the country depends on, with transport undertakings expressly included, which places airports, railways and logistics operators squarely inside the duty.

The uncomfortable truth about a twenty four hour deadline is that no organisation meets it for the first time during a real crisis. Meeting it requires detection that works, an escalation path that has been rehearsed, clarity on who reports and on what authority, and a crisis structure that can produce an accurate initial picture while the technical response is still running. The reporting duty is, in effect, a legal test of your incident capability.

Strumento
ISG, SR 128
In force
Since 1 January 2024
Rapporto
24h to BACS, since 1 Apr 2025
Sanzioni
Up to CHF 100,000, since 1 Oct 2025
THE SWISS REPORTING COUNTDOWN, IN FORCE AND ENFORCED0hCyberattack on critical infrastructure discoveredThe clock starts at discoveryWithin 24 hoursReport to the Federal Office for Cyber Security (BACS)Via the Cyber Security Hub, since 1 April 2025Within 14 daysComplete the reportFull details supplied as the picture clarifiesNon complianceFines of up to CHF 100,000Enforceable since 1 October 2025Information Security Act (ISG, SR 128), in force since 1 January 2024; transport undertakings expressly included.
The ISG reporting countdown: discovery starts the clock, BACS is notified within twenty four hours via the Cyber Security Hub, the report is completed within fourteen days, and non compliance now carries fines.
Getting ready

The capability behind the deadline

Know whether you are in scope. The duty attaches to operators of critical infrastructure across the sectors Switzerland depends on, transport expressly included. Scope determination is a legal and operational question we resolve at the start of every engagement.
Detection and triage that work at 3 a.m. A duty that starts at discovery is unforgiving of monitoring gaps and slow triage; the reporting clock effectively audits your detection capability.
A rehearsed escalation and reporting path. Who decides an incident is reportable, who files via the Cyber Security Hub, and who completes the fourteen day report, agreed, documented and exercised before it is needed. Our exercise programmes test exactly this path.
Coherence with your other regimes. Swiss operators with EU exposure often carry NIS2 or DORA duties in parallel, and aviation operators carry Part-IS; one incident capability should serve every clock. See NIS2, DORA and Part-IS.
Domande

Domande frequenti

Who must report under the Swiss ISG?+

Operators of critical infrastructure, across sectors including energy, transport, water, health, finance and public administration, with transport undertakings expressly included. If your organisation's failure would matter to Switzerland, assume you should verify your scope.

What exactly must be reported, and when?+

A cyberattack on the critical infrastructure must be reported to the Federal Office for Cyber Security within twenty four hours of discovery, via the Cyber Security Hub, with the report completed within fourteen days as details become clear.

What happens if we miss the deadline?+

Since 1 October 2025, non compliance is enforceable with fines of up to CHF 100,000, alongside the supervisory and reputational consequences of being unprepared in front of the federal authority.

How does the ISG relate to NIS2?+

They are parallel regimes: the ISG governs Swiss critical infrastructure operators domestically, while NIS2 governs essential and important entities in the EU. Swiss groups with EU operations or customers frequently carry both, and should build one incident capability mapped to both clocks.

Is this page available in German?+

Yes: our German language briefing at Informationssicherheitsgesetz covers the same ground for Swiss domestic readers.

Scopri di più

Servizi correlati

Sicurezza informatica

Resilienza informatica

Oltre la prevenzione: la capacità di resistere, reagire e riprendersi, garantendo al contempo la continuità dei servizi essenziali.

Scopri il servizio ›
Continuità e resilienza

Esercitazioni di continuità operativa

Esercitazioni da tavolo, funzionali, informatiche e su vasta scala che verificano i piani e le prove di conformità alle norme ISO 22301, NIS2 e DORA.

Scopri il servizio ›
Regolamentazione e crisi

Gestione delle crisi

Dottrina, strutture e comunicazioni che contengono il picco e abbreviano i tempi di recupero, basate sulla norma ISO 22361.

Scopri il servizio ›
Regolamentazione e crisi

Conformità NIS2

Dalla determinazione dell'ambito di applicazione alle misure previste dall'articolo 21 e alla prontezza di presentazione dei rapporti entro 24 ore ai sensi della direttiva (UE) 2022/2555.

Scopri il servizio ›
Sicurezza informatica

Sicurezza delle informazioni

Riservatezza, integrità e disponibilità garantite da un ISMS dinamico e conforme alla norma ISO 27001.

Scopri il servizio ›
Continuità e resilienza

Gestione della continuità operativa

Strategia, piani e validazione conformi alla norma BIA e ISO 22301: un programma di continuità operativa progettato per resistere a un'interruzione reale.

Scopri il servizio ›
Regolamentazione e crisi

Conformità DORA

I cinque pilastri del Regolamento (UE) 2022/2554 attuato per gli enti finanziari e i loro fornitori di infrastrutture ICT critiche.

Scopri il servizio ›
Sicurezza informatica

Sicurezza della catena di approvvigionamento

Il rischio che ereditate dai fornitori e dalle piattaforme condivise: mappato, garantito, contrattualizzato ed esercitato, secondo le norme ISO 28000, NIS2 e DORA.

Scopri il servizio ›
Quadro settoriale

Quadro di riferimento DAEDALUS per la resilienza aeroportuale

Il Framework per la Resilienza Aeroportuale: cinque ambiti come un unico modello operativo per l'intero aeroporto, basato sul motore 7A, nelle edizioni per l'aviazione commerciale, cargo e business.

Scopri il servizio ›
Continuità e resilienza

Resilienza organizzativa

La struttura sopra i piani: rischio, continuità, crisi, sicurezza informatica e persone su un'unica base di governance, secondo ISO 22316.

Scopri il servizio ›
Rischio e governance

Gestione del rischio

Dall'universo dei rischi al rischio gestito: identificazione, valutazione consapevole dello stress, trattamento personalizzato e monitoraggio in tempo reale.

Scopri il servizio ›
Rischio e governance

7A Quadro di riferimento per la gestione del rischio

Il nostro modello operativo proprietario incentrato sulle decisioni: esposizione e affidabilità delle decisioni misurate separatamente, per il consiglio di amministrazione.

Scopri il servizio ›
Rischio e governance

Governance e resilienza dell'IA

La governance ha avvolto ogni livello dei sistemi intelligenti, dal comportamento dei modelli alla responsabilità del consiglio di amministrazione e alla norma ISO 42001.

Scopri il servizio ›
Passo successivo

Find out if you would make the 24 hours.

Ask us to exercise your detection to report path against a realistic scenario; you will know your true reporting time before BACS does.

Prenota una consulenza
Tutte le consulenze sono trattate con la massima riservatezza.