The Information Security Act binds operators of critical infrastructure, transport undertakings expressly included, to report cyberattacks to the federal authority within twenty four hours of discovery, with financial penalties now enforceable. Here is what the law requires and how to be ready for it.
The Swiss Information Security Act (Informationssicherheitsgesetz, ISG, SR 128) is Switzerland's framework law for information security in the federal sphere and for the protection of critical infrastructure. In force since 1 January 2024, it introduced, through its cybersecurity provisions, a legal obligation on operators of critical infrastructure to report cyberattacks to the Federal Office for Cyber Security (BACS) within twenty four hours of discovery, applicable since 1 April 2025.
The mechanics are precise. The clock starts when the attack is discovered, not when it is understood. The initial report is made via the Cyber Security Hub, and the operator then has fourteen days to complete it as the picture clarifies. Since 1 October 2025 non compliance is enforceable with fines of up to CHF 100,000. The scope covers the operators the country depends on, with transport undertakings expressly included, which places airports, railways and logistics operators squarely inside the duty.
The uncomfortable truth about a twenty four hour deadline is that no organisation meets it for the first time during a real crisis. Meeting it requires detection that works, an escalation path that has been rehearsed, clarity on who reports and on what authority, and a crisis structure that can produce an accurate initial picture while the technical response is still running. The reporting duty is, in effect, a legal test of your incident capability.
Operators of critical infrastructure, across sectors including energy, transport, water, health, finance and public administration, with transport undertakings expressly included. If your organisation's failure would matter to Switzerland, assume you should verify your scope.
A cyberattack on the critical infrastructure must be reported to the Federal Office for Cyber Security within twenty four hours of discovery, via the Cyber Security Hub, with the report completed within fourteen days as details become clear.
Since 1 October 2025, non compliance is enforceable with fines of up to CHF 100,000, alongside the supervisory and reputational consequences of being unprepared in front of the federal authority.
They are parallel regimes: the ISG governs Swiss critical infrastructure operators domestically, while NIS2 governs essential and important entities in the EU. Swiss groups with EU operations or customers frequently carry both, and should build one incident capability mapped to both clocks.
Yes: our German language briefing at Informationssicherheitsgesetz covers the same ground for Swiss domestic readers.
Oltre la prevenzione: la capacità di resistere, reagire e riprendersi, garantendo al contempo la continuità dei servizi essenziali.
Esercitazioni da tavolo, funzionali, informatiche e su vasta scala che verificano i piani e le prove di conformità alle norme ISO 22301, NIS2 e DORA.
Dottrina, strutture e comunicazioni che contengono il picco e abbreviano i tempi di recupero, basate sulla norma ISO 22361.
Dalla determinazione dell'ambito di applicazione alle misure previste dall'articolo 21 e alla prontezza di presentazione dei rapporti entro 24 ore ai sensi della direttiva (UE) 2022/2555.
Riservatezza, integrità e disponibilità garantite da un ISMS dinamico e conforme alla norma ISO 27001.
Strategia, piani e validazione conformi alla norma BIA e ISO 22301: un programma di continuità operativa progettato per resistere a un'interruzione reale.
I cinque pilastri del Regolamento (UE) 2022/2554 attuato per gli enti finanziari e i loro fornitori di infrastrutture ICT critiche.
Il rischio che ereditate dai fornitori e dalle piattaforme condivise: mappato, garantito, contrattualizzato ed esercitato, secondo le norme ISO 28000, NIS2 e DORA.
Il Framework per la Resilienza Aeroportuale: cinque ambiti come un unico modello operativo per l'intero aeroporto, basato sul motore 7A, nelle edizioni per l'aviazione commerciale, cargo e business.
La struttura sopra i piani: rischio, continuità, crisi, sicurezza informatica e persone su un'unica base di governance, secondo ISO 22316.
Dall'universo dei rischi al rischio gestito: identificazione, valutazione consapevole dello stress, trattamento personalizzato e monitoraggio in tempo reale.
Il nostro modello operativo proprietario incentrato sulle decisioni: esposizione e affidabilità delle decisioni misurate separatamente, per il consiglio di amministrazione.
La governance ha avvolto ogni livello dei sistemi intelligenti, dal comportamento dei modelli alla responsabilità del consiglio di amministrazione e alla norma ISO 42001.
Ask us to exercise your detection to report path against a realistic scenario; you will know your true reporting time before BACS does.
Prenota una consulenza