Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
Swiss Information Security Act (ISG): 24 Hour Reporting Explained | Resilience Guard
The Swiss ISG in English

Switzerland's 24 hour cyber reporting duty, explained.

The Information Security Act binds operators of critical infrastructure, transport undertakings expressly included, to report cyberattacks to the federal authority within twenty four hours of discovery, with financial penalties now enforceable. Here is what the law requires and how to be ready for it.

The law

What is the Information Security Act?

The Swiss Information Security Act (Informationssicherheitsgesetz, ISG, SR 128) is Switzerland's framework law for information security in the federal sphere and for the protection of critical infrastructure. In force since 1 January 2024, it introduced, through its cybersecurity provisions, a legal obligation on operators of critical infrastructure to report cyberattacks to the Federal Office for Cyber Security (BACS) within twenty four hours of discovery, applicable since 1 April 2025.

The mechanics are precise. The clock starts when the attack is discovered, not when it is understood. The initial report is made via the Cyber Security Hub, and the operator then has fourteen days to complete it as the picture clarifies. Since 1 October 2025 non compliance is enforceable with fines of up to CHF 100,000. The scope covers the operators the country depends on, with transport undertakings expressly included, which places airports, railways and logistics operators squarely inside the duty.

The uncomfortable truth about a twenty four hour deadline is that no organisation meets it for the first time during a real crisis. Meeting it requires detection that works, an escalation path that has been rehearsed, clarity on who reports and on what authority, and a crisis structure that can produce an accurate initial picture while the technical response is still running. The reporting duty is, in effect, a legal test of your incident capability.

Instrument
ISG, SR 128
In force
Since 1 January 2024
Reporting
24h to BACS, since 1 Apr 2025
Sanctions
Up to CHF 100,000, since 1 Oct 2025
THE SWISS REPORTING COUNTDOWN, IN FORCE AND ENFORCED0hCyberattack on critical infrastructure discoveredThe clock starts at discoveryWithin 24 hoursReport to the Federal Office for Cyber Security (BACS)Via the Cyber Security Hub, since 1 April 2025Within 14 daysComplete the reportFull details supplied as the picture clarifiesNon complianceFines of up to CHF 100,000Enforceable since 1 October 2025Information Security Act (ISG, SR 128), in force since 1 January 2024; transport undertakings expressly included.
The ISG reporting countdown: discovery starts the clock, BACS is notified within twenty four hours via the Cyber Security Hub, the report is completed within fourteen days, and non compliance now carries fines.
Getting ready

The capability behind the deadline

Know whether you are in scope. The duty attaches to operators of critical infrastructure across the sectors Switzerland depends on, transport expressly included. Scope determination is a legal and operational question we resolve at the start of every engagement.
Detection and triage that work at 3 a.m. A duty that starts at discovery is unforgiving of monitoring gaps and slow triage; the reporting clock effectively audits your detection capability.
A rehearsed escalation and reporting path. Who decides an incident is reportable, who files via the Cyber Security Hub, and who completes the fourteen day report, agreed, documented and exercised before it is needed. Our exercise programmes test exactly this path.
Coherence with your other regimes. Swiss operators with EU exposure often carry NIS2 or DORA duties in parallel, and aviation operators carry Part-IS; one incident capability should serve every clock. See NIS2, DORA and Part-IS.
Questions

Frequently asked questions

Who must report under the Swiss ISG?+

Operators of critical infrastructure, across sectors including energy, transport, water, health, finance and public administration, with transport undertakings expressly included. If your organisation's failure would matter to Switzerland, assume you should verify your scope.

What exactly must be reported, and when?+

A cyberattack on the critical infrastructure must be reported to the Federal Office for Cyber Security within twenty four hours of discovery, via the Cyber Security Hub, with the report completed within fourteen days as details become clear.

What happens if we miss the deadline?+

Since 1 October 2025, non compliance is enforceable with fines of up to CHF 100,000, alongside the supervisory and reputational consequences of being unprepared in front of the federal authority.

How does the ISG relate to NIS2?+

They are parallel regimes: the ISG governs Swiss critical infrastructure operators domestically, while NIS2 governs essential and important entities in the EU. Swiss groups with EU operations or customers frequently carry both, and should build one incident capability mapped to both clocks.

Is this page available in German?+

Yes: our German language briefing at Informationssicherheitsgesetz covers the same ground for Swiss domestic readers.

Explore further

Related services

Cyber and security

Cyber Resilience

Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.

Explore the service ›
Continuity and resilience

Business Continuity Exercises

Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.

Explore the service ›
Regulation and crisis

Crisis Management

Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.

Explore the service ›
Regulation and crisis

NIS2 Compliance

From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.

Explore the service ›
Cyber and security

Information Security

Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.

Explore the service ›
Continuity and resilience

Business Continuity Management

BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.

Explore the service ›
Regulation and crisis

DORA Compliance

The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.

Explore the service ›
Cyber and security

Supply Chain Security

The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.

Explore the service ›
Sector framework

DAEDALUS Airport Resilience Framework

The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.

Explore the service ›
Continuity and resilience

Organisational Resilience

The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.

Explore the service ›
Risk and governance

Risk Management

From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.

Explore the service ›
Risk and governance

7A Risk Management Framework

Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.

Explore the service ›
Risk and governance

AI Governance and Resilience

Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.

Explore the service ›
Next step

Find out if you would make the 24 hours.

Ask us to exercise your detection to report path against a realistic scenario; you will know your true reporting time before BACS does.

Book a consultation
All consultations are treated with strict confidentiality.