Cyberattack reporting duty: who has to report in Switzerland

The question «do we have to report this?» comes up too late in most incidents. Not because nobody knows the law. Because nobody decided beforehand who answers it.

While the meeting room is still debating whether this is a matter for the authorities, a deadline is already running, and it did not start with the decision. It started when somebody discovered the attack. Probably the evening before, probably in IT, probably without management knowing about it.

That is what makes the reporting duty for a cyberattack in Switzerland less of a legal topic and more of an organisational one. It rarely fails on the wording of the law. It fails on ownership.

There are two clocks, not one

The most common mistake is treating the reporting duty as a single obligation. There are at least two, and they have nothing to do with each other.

The first comes from the Information Security Act (ISG). It applies to operators of critical infrastructure, goes to the Federal Office for Cybersecurity (BACS), and carries a hard deadline measured in hours.

The second comes from the Data Protection Act (DSG). It applies to anyone who processes personal data, goes to the Federal Data Protection and Information Commissioner (FDPIC), and has no deadline in hours at all. It has one measured in diligence.

On top of those come the clocks that are not in any statute and often run out first: the notification deadline in your cyber policy, the information duties in your customer contracts, and the question of when a customer would rather hear it from you than from somebody else. We covered the insurance side of this in our piece on buying cyber insurance.

Four clocks, different addressees, different triggers. Nobody sorts that out cleanly at three in the morning.

Does the ISG reporting duty apply to your company?

For the large majority of Swiss SMEs: no. The reporting duty under Art. 74b ISG applies to an exhaustively listed group, essentially public authorities, universities, energy and water supply, banks and insurers, hospitals on the cantonal hospital list, transport companies holding a concession, telecoms providers, and the supply of the population with essential everyday goods.

The list runs to twenty-one letters and refers out to other statutes in several places. It is no pleasure to read, and it was not built so that a management team could apply it to their own business in ten minutes.

If you build machines, run a fiduciary practice or sell furniture, you are not the target.

Two letters on the list are regularly overlooked, though, and they hit exactly the kind of company that would never describe itself as critical infrastructure.

Letter t covers providers and operators of cloud computing, digital security and trust services, and data centres, provided they have a registered office in Switzerland. That is the regional IT service provider with thirty people and one rack of their own, not only the hyperscaler.

Letter u covers manufacturers of hardware or software whose products are used by critical infrastructure, provided the hardware or software has remote maintenance access or is used to control and monitor operational technology systems. Translated: if you build controllers that run at an energy utility, and you connect remotely for maintenance, then you are in scope through your customer, even though by every other definition your business is an ordinary SME.

Two pieces of relief on that, because they get lost in the excitement. First, there is no reporting duty for cyberattacks that affect only activities outside the list (Art. 74b para. 2 ISG). Second, and this is the most practical sentence in the whole section: BACS will tell interested organisations whether they are subject to the reporting duty, and on request will issue a formal ruling to that effect (Art. 74a para. 2 ISG).

So you do not have to interpret this yourself. You can ask, and you can get it in writing.

What has to be reported, and what does not

Not every incident is reportable. Art. 74d ISG names four triggers. A cyberattack has to be reported if it endangers the functioning of the critical infrastructure concerned, if it led to manipulation or to a leak of information, if it went undetected over a longer period, or if it is connected with extortion, threat or coercion.

The third one is the uncomfortable one. You notice the first two because something stops working or something is missing. The fourth announces itself, usually by ransom note. The third is the case you discover months later, when you find something in old logs that has no business being there. And it is meant explicitly to cover situations where there are indications the attack was carried out to prepare further attacks.

The phishing attempt you blocked on Tuesday morning is not part of this. The law is not aiming at completeness but at patterns: under Art. 74a para. 4 ISG the reporting duty exists solely so that BACS can recognise attack patterns early and warn those who might be affected. It is an early warning system, not a register for questions of blame.

The 24 hours start at discovery

Art. 74e para. 1 ISG is short: the report has to be made within 24 hours of the discovery of the cyberattack.

After discovery, not after confirmation and not after the analysis is finished. In practice that means the deadline is already running while you are still working out what happened. That is exactly why the content of the report is deliberately kept light: it has to cover the organisation, the nature and execution of the attack, its effects and the measures taken, as far as these are known. If information is missing, BACS allows 14 days to complete the report.

Two sentences from the same article take some of the edge off. Whoever has to fulfil the reporting duty is not required to provide information that would incriminate them (Art. 74e para. 4). And BACS confirms once all the required details are in (para. 5). So you are not reporting into a black hole, and you are not incriminating yourself.

It still remains a deadline measured in hours, and deadlines measured in hours need a human being who notices them. That is the whole trick to this obligation.

The fine is not where you expect it

At this point the topic is usually sold with a number. Fines of up to CHF 100,000. And yes, the number is in the law.

It just is not where most people assume it is.

Art. 74g ISG describes what happens when there are indications that the reporting duty has been breached: BACS informs the organisation and sets it a reasonable deadline to comply. Only if it fails to do so does BACS issue a formal ruling, set a new deadline and point to the penalty. Art. 74h then imposes a fine of up to CHF 100,000 on anyone who wilfully fails to comply with a legally binding ruling. Both articles have been in force since 1 October 2025, six months after the reporting duty itself.

So the missed report is not what gets fined. What gets fined is failing to act after being told twice.

The architecture in the Data Protection Act is identical. Reporting a data security breach under Art. 24 DSG does not appear in the catalogue of offences in Art. 60 and Art. 61 DSG at all. Under Art. 63 DSG, fines of up to CHF 250,000 apply to anyone who wilfully fails to comply with a ruling of the FDPIC.

This is not a free pass. The legislator treats the reporting duty as cooperation that will be enforced if necessary, rather than as an offence. But if fear of fines is what motivates you to prepare, you are motivating yourself with the wrong risk, and that backfires, because you then prepare the wrong things: a legal opinion instead of a phone number.

The more expensive risk is more mundane: 24 hours are running, three people each assume it is not their job, and in the end you report late, incompletely and under supervision. In our experience the question «who decides this?» is considerably harder to answer during an incident than the question «do we have to report?», and it costs more time. We described the same mechanic in the context of the board of directors and the liability question: what counts in the end is not how much you spent, but whether you can show that you acted with diligence.

Even without the ISG: the reporting duty in the Data Protection Act

If the ISG list does not catch you, you are not done. Art. 24 DSG applies to every controller, regardless of sector and size.

The controller reports a breach of data security to the FDPIC as quickly as possible where it is likely to result in a high risk to the personality or the fundamental rights of the data subject. No number of hours, but an assessment you have to be able to justify when it matters. The report names at least the nature of the breach, its consequences and the measures taken or planned. And the data subject is informed where this is necessary for their protection or where the FDPIC demands it.

One paragraph in there is consistently overlooked, even though it hits many SMEs more directly than anything else: the processor reports a breach of data security to the controller as quickly as possible (Art. 24 para. 3 DSG).

If you process data for other companies, and more businesses do than realise it, then you have a statutory reporting duty towards your customers. The addressee here is not an authority but the people who pay you. Anyone who works this out during the incident makes a very uncomfortable phone call. We set out the groundwork in our pieces on the Swiss Data Protection Act and on liability for managing directors.

The note you write in advance

None of this can be solved during the incident, but it can be prepared in an hour. It does not take a process manual, it takes four decisions written down somewhere you can find them at three in the morning.

First: who decides whether to report? One person by name, one deputy by name. «Management» is nobody when it matters.

Second: which clocks actually run for us? ISG yes or no, DSG always, insurance per the policy, customer contracts per the contract. That list fits on half a page.

Third: where does the report go, and who has access? BACS provides a dedicated system for submitting reports electronically (Art. 74f ISG). Access that nobody has when it matters is not access.

Fourth: who keeps a record from minute one? The timestamp of discovery is the most important number in the whole incident, and after two days it can no longer be reconstructed. This is also the point where the ability to report meets the rest of your incident preparation, which we described in Incident Response Readiness and in ransomware protection for SMEs.

Once those four points are settled, the reporting duty is handled before it becomes relevant. It is no longer a legal question, just a line in a procedure.

That is exactly how we set it up in our mandates. Reporting paths are among the things that emerge anyway when you build an ISMS, because a management system without defined ownership does not work during an incident. If you want to know which of the four clocks run for you and which do not, that is a good topic for a first conversation. No obligation, and usually shorter than expected.

What you need first when it happens

The text of the law can be looked up, and it is shorter than its reputation suggests. That is the smaller worry when it matters.

What you need is the name of the person who decides, and the moment somebody noticed something. Everything else follows from those two. The 24 hours are not a legal problem. They are an ownership problem with a deadline attached.

If somebody at your company finds something unusual in the logs tonight, who do they call?

Frequently asked questions

Who has to report a cyberattack in Switzerland?

The reporting duty under Art. 74b ISG has applied since 1 April 2025 to operators of critical infrastructure: public authorities, energy and water supply, banks, insurers, hospitals, transport companies, and telecoms and cloud providers with a registered office in Switzerland. Most SMEs are not covered. Every company must still report data breaches to the FDPIC under Art. 24 DSG.

How long do you have to report a cyberattack?

The report to BACS has to be made within 24 hours of the discovery of the cyberattack (Art. 74e para. 1 ISG). What counts is the discovery, not the completed analysis. If information is still missing, BACS allows 14 days to complete it. The report to the FDPIC under Art. 24 DSG has no deadline in hours.

What happens if you breach the reporting duty?

The missed report itself is not what gets fined. BACS first informs the organisation and sets it a deadline (Art. 74g ISG). Only someone who then wilfully disregards a legally binding ruling is fined up to CHF 100,000 under Art. 74h ISG. In the Data Protection Act, Art. 63 DSG follows the same pattern.