ISG 30-day programme: reporting-ready in four weeks
The ISG 30-day programme helps Swiss critical-infrastructure operators and other organisations subject to ISG prepare for incident reporting in four weeks. They can then report notifiable cyber incidents to the National Cyber Security Centre (NCSC) within the statutory 24-hour window. The programme focuses on roles, reporting paths, playbooks and evidence, not tool procurement. It delivers a rehearsed process with a documented first notification, an escalation matrix and named responsible people.
Who this programme is for
Since 1 April 2025, Swiss critical-infrastructure operators must report notifiable cyber incidents to the National Cyber Security Centre (NCSC) within 24 hours. The guide ISG reporting duty (from 1 April 2025) explains the scope and defines notifiable incidents. This programme serves organisations subject to this duty that lack both a rehearsed 24-hour reporting chain and documented responsibilities.
- Energy, water, health and transport operators within the ISG scope.
- Suppliers and operators of critical digital services that the National Cyber Security Centre (NCSC) classifies as subject to reporting obligations.
- Cantons, cities and utilities with operational and control technology inside the ISG perimeter.
How this compares to neighbouring topics
| Model | What it is | Where it stops |
|---|---|---|
| ISG 30-day programme | Guided development of reporting paths, roles and playbooks over four weeks, including a tabletop exercise. | The programme excludes SOC operations and tool rollout. The SOC provides detection and response. |
| SOC onboarding | Integration of logs, EDR and playbooks over several weeks, leading to operational 24/7 coverage. | No statutory reporting governance; covers detection, not regulatory evidence. |
| Incident response 72h | Reactive retainer model for the acute incident. | Requires a working reporting path; does not replace it. |
| Security consulting | Project-based consulting on architecture, detection and identity. | Not a short programme with a fixed deliverable in four weeks. |
The four weeks in detail
| Week | Focus | Outcome |
|---|---|---|
| Week 1: scoping | Clarify scope, identify critical processes and systems, review existing reporting paths. | Scope document, stakeholder matrix, gap list against ISG duties. |
| Week 2: roles and reporting path | Assign reporting accountability, backups and escalation chains; set up the National Cyber Security Centre (NCSC) reporting form and communication templates. | Documented 24h reporting chain with RACI, contacts and templates for first, interim and final notifications. |
| Week 3: playbooks and evidence | Playbooks by incident class (ransomware, data exfiltration, critical availability), log and evidence preservation, coordination with the SOC and broker. | Four to six approved playbooks, an evidence plan and a description of interfaces with the SOC. |
| Week 4: tabletop and sign-off | Two tabletop exercises with realistic scenarios under time pressure; debrief, open items, sign-off by executive management. | Exercise minutes, evidence dossier, written sign-off by executive management. |
The programme requires no new platform. It uses existing email, ticketing and document storage. Where detection is missing, it points to [SOC operations](/en/soc/soc-as-a-service-switzerland) as a separate track.
What you get at the end
- Documented 24h reporting chain to the NCSC with named people and backups.
- Templates for first, interim and final notifications, signed off by legal and communications.
- Four to six incident playbooks with clear decision points and time windows.
- Evidence dossier with log, evidence and communication requirements for later audits.
- Two completed tabletop exercises with debrief and action list.
- Description of interfaces with the SOC and Incident response 72h for an actual incident.
Placement in SOC operations
The programme builds the regulatory reporting layer. The SOC provides continuous detection and response. The guide SOC as a Service Switzerland explains how both work together. ISG reporting duty (from 1 April 2025) explains the legal basis in detail.
Legal basis and sources
- ISG (SR 128), Art. 74a-74f: Fedlex
- Cybersecurity Ordinance (CSV, SR 128.51): Fedlex
- ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
- Reporting data security breaches to the FDPIC: edoeb.admin.ch
Frequently asked questions
Are four weeks enough for ISG reporting capability?
Four weeks are sufficient if detection and log foundations exist. The programme builds the reporting and governance layer; it does not replace a missing SOC. Without a log foundation we recommend starting the [SOC onboarding track](/en/soc/soc-onboarding-switzerland) in parallel.
Who ultimately notifies BACS?
Accountability stays with the operator. The programme names the responsible person and backup, provides templates and rehearses the process. ANOMAL can support an acute incident through [Incident response 72h](/en/services/incident-response-72h). The operator retains its statutory reporting obligation.
Does the programme also suit FINMA-supervised institutions?
The programme is partly suitable for FINMA-supervised institutions. FINMA reporting duties have their own criteria and deadlines; see [FINMA requirements](/en/soc/soc-finma-requirements). For institutions also within ISG scope, we combine both reporting paths in the same playbook to avoid duplicate reporting chains.
How much internal time do we need to plan for?
Plan for two to three person-days per week across IT leadership, communications, legal and operations. Executive management and operational teams each need half a day for the Week 4 tabletop.
What happens after the 30 days?
The process becomes part of routine operations. We recommend annual tabletop exercises and quarterly reviews of the contact chain. On request, our [security consulting](/en/services/security-consulting-switzerland) team manages this governance schedule.
Related terms
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- ISO 27001 ISO 27001 is the international standard for information security management systems. Certification confirms that risks are managed systematically.
- Log Source A log source is any system that provides security-relevant events to a SIEM or the SOC.
- Telemetry Pipeline A telemetry pipeline collects, filters, and routes logs and events before they are analysed in the SIEM or SOC.