FINMA
The Swiss Financial Market Supervisory Authority (FINMA) supervises financial institutions and sets their cybersecurity requirements.
The Swiss Financial Market Supervisory Authority (FINMA) supervises banks, insurance companies, stock exchanges and other financial institutions in Switzerland. It also sets requirements for cybersecurity and operational resilience.
How it works
The key requirements for banks and securities firms are in FINMA Circular 2023/1 'Operational Risks and Resilience: Banks', effective since January 2024. It requires cyber risk management, critical data protection, and effective attack detection and response. Additionally, Supervisory Communication 05/2020 obliges institutions to report significant cyber attacks within 24 hours of discovery.
The full report follows within 72 hours, refined by Supervisory Communication 03/2024. Circular 2018/3 applies to outsourcing.
A practical example: a regional bank finds that a privileged employee account in the e-banking back office has been taken over. It must quickly assess whether critical functions or data are affected. The deadline for the initial report runs from discovery. The assessment must therefore be available within hours. The SOC provides the timeline, affected systems and measures taken for the report.
What to look out for
- Define which functions and data are critical for your organisation. The circular's requirements build on this.
- Ensure that attacks are also detected at night. The reporting deadline runs around the clock.
- Record outsourced services, such as an external SOC, in an inventory and audit them.
- Test your resilience regularly, for example with scenarios for severe incidents.
Typical mistakes
Often, responsibility for the FINMA report is not clearly defined. In an emergency, it is then unclear who decides if an attack is significant. A second mistake is service provider contracts that lack audit and information rights for the institution and for FINMA.
Relevance for the SOC
FINMA does not prescribe a specific SOC model. An internal SOC is just as permissible as an outsourced one. The critical point is that detection, response, and evidence are effective. The institution must also retain full control.
How we implement it
We operate our SOC from Switzerland and supply the evidence for reports and audits. The responsibility for compliance remains with the institution.