The Information Security Act binds operators of critical infrastructure, transport undertakings expressly included, to report cyberattacks to the federal authority within twenty four hours of discovery, with financial penalties now enforceable. Here is what the law requires and how to be ready for it.
The Swiss Information Security Act (Informationssicherheitsgesetz, ISG, SR 128) is Switzerland's framework law for information security in the federal sphere and for the protection of critical infrastructure. In force since 1 January 2024, it introduced, through its cybersecurity provisions, a legal obligation on operators of critical infrastructure to report cyberattacks to the Federal Office for Cyber Security (BACS) within twenty four hours of discovery, applicable since 1 April 2025.
The mechanics are precise. The clock starts when the attack is discovered, not when it is understood. The initial report is made via the Cyber Security Hub, and the operator then has fourteen days to complete it as the picture clarifies. Since 1 October 2025 non compliance is enforceable with fines of up to CHF 100,000. The scope covers the operators the country depends on, with transport undertakings expressly included, which places airports, railways and logistics operators squarely inside the duty.
The uncomfortable truth about a twenty four hour deadline is that no organisation meets it for the first time during a real crisis. Meeting it requires detection that works, an escalation path that has been rehearsed, clarity on who reports and on what authority, and a crisis structure that can produce an accurate initial picture while the technical response is still running. The reporting duty is, in effect, a legal test of your incident capability.
Operators of critical infrastructure, across sectors including energy, transport, water, health, finance and public administration, with transport undertakings expressly included. If your organisation's failure would matter to Switzerland, assume you should verify your scope.
A cyberattack on the critical infrastructure must be reported to the Federal Office for Cyber Security within twenty four hours of discovery, via the Cyber Security Hub, with the report completed within fourteen days as details become clear.
Since 1 October 2025, non compliance is enforceable with fines of up to CHF 100,000, alongside the supervisory and reputational consequences of being unprepared in front of the federal authority.
They are parallel regimes: the ISG governs Swiss critical infrastructure operators domestically, while NIS2 governs essential and important entities in the EU. Swiss groups with EU operations or customers frequently carry both, and should build one incident capability mapped to both clocks.
Yes: our German language briefing at Informationssicherheitsgesetz covers the same ground for Swiss domestic readers.
Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.
Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.
Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.
From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.
Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.
BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.
The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.
The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.
The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.
The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.
From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.
Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.
Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.
Ask us to exercise your detection to report path against a realistic scenario; you will know your true reporting time before BACS does.
Book a consultation