ANOMAL service

ISG 30-day programme: reporting-ready in four weeks

The ISG 30-day programme helps Swiss critical-infrastructure operators and other organisations subject to ISG prepare for incident reporting in four weeks. They can then report notifiable cyber incidents to the National Cyber Security Centre (NCSC) within the statutory 24-hour window. The programme focuses on roles, reporting paths, playbooks and evidence, not tool procurement. It delivers a rehearsed process with a documented first notification, an escalation matrix and named responsible people.

All

Who this programme is for

Since 1 April 2025, Swiss critical-infrastructure operators must report notifiable cyber incidents to the National Cyber Security Centre (NCSC) within 24 hours. The guide ISG reporting duty (from 1 April 2025) explains the scope and defines notifiable incidents. This programme serves organisations subject to this duty that lack both a rehearsed 24-hour reporting chain and documented responsibilities.

  • Energy, water, health and transport operators within the ISG scope.
  • Suppliers and operators of critical digital services that the National Cyber Security Centre (NCSC) classifies as subject to reporting obligations.
  • Cantons, cities and utilities with operational and control technology inside the ISG perimeter.

How this compares to neighbouring topics

ModelWhat it isWhere it stops
ISG 30-day programmeGuided development of reporting paths, roles and playbooks over four weeks, including a tabletop exercise.The programme excludes SOC operations and tool rollout. The SOC provides detection and response.
SOC onboardingIntegration of logs, EDR and playbooks over several weeks, leading to operational 24/7 coverage.No statutory reporting governance; covers detection, not regulatory evidence.
Incident response 72hReactive retainer model for the acute incident.Requires a working reporting path; does not replace it.
Security consultingProject-based consulting on architecture, detection and identity.Not a short programme with a fixed deliverable in four weeks.

The four weeks in detail

WeekFocusOutcome
Week 1: scopingClarify scope, identify critical processes and systems, review existing reporting paths.Scope document, stakeholder matrix, gap list against ISG duties.
Week 2: roles and reporting pathAssign reporting accountability, backups and escalation chains; set up the National Cyber Security Centre (NCSC) reporting form and communication templates.Documented 24h reporting chain with RACI, contacts and templates for first, interim and final notifications.
Week 3: playbooks and evidencePlaybooks by incident class (ransomware, data exfiltration, critical availability), log and evidence preservation, coordination with the SOC and broker.Four to six approved playbooks, an evidence plan and a description of interfaces with the SOC.
Week 4: tabletop and sign-offTwo tabletop exercises with realistic scenarios under time pressure; debrief, open items, sign-off by executive management.Exercise minutes, evidence dossier, written sign-off by executive management.
No tool purchase within the programme

The programme requires no new platform. It uses existing email, ticketing and document storage. Where detection is missing, it points to [SOC operations](/en/soc/soc-as-a-service-switzerland) as a separate track.

What you get at the end

  • Documented 24h reporting chain to the NCSC with named people and backups.
  • Templates for first, interim and final notifications, signed off by legal and communications.
  • Four to six incident playbooks with clear decision points and time windows.
  • Evidence dossier with log, evidence and communication requirements for later audits.
  • Two completed tabletop exercises with debrief and action list.
  • Description of interfaces with the SOC and Incident response 72h for an actual incident.

Placement in SOC operations

The programme builds the regulatory reporting layer. The SOC provides continuous detection and response. The guide SOC as a Service Switzerland explains how both work together. ISG reporting duty (from 1 April 2025) explains the legal basis in detail.

Legal basis and sources

  • ISG (SR 128), Art. 74a-74f: Fedlex
  • Cybersecurity Ordinance (CSV, SR 128.51): Fedlex
  • ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
  • Reporting data security breaches to the FDPIC: edoeb.admin.ch

Frequently asked questions

Are four weeks enough for ISG reporting capability?

Four weeks are sufficient if detection and log foundations exist. The programme builds the reporting and governance layer; it does not replace a missing SOC. Without a log foundation we recommend starting the [SOC onboarding track](/en/soc/soc-onboarding-switzerland) in parallel.

Who ultimately notifies BACS?

Accountability stays with the operator. The programme names the responsible person and backup, provides templates and rehearses the process. ANOMAL can support an acute incident through [Incident response 72h](/en/services/incident-response-72h). The operator retains its statutory reporting obligation.

Does the programme also suit FINMA-supervised institutions?

The programme is partly suitable for FINMA-supervised institutions. FINMA reporting duties have their own criteria and deadlines; see [FINMA requirements](/en/soc/soc-finma-requirements). For institutions also within ISG scope, we combine both reporting paths in the same playbook to avoid duplicate reporting chains.

How much internal time do we need to plan for?

Plan for two to three person-days per week across IT leadership, communications, legal and operations. Executive management and operational teams each need half a day for the Week 4 tabletop.

What happens after the 30 days?

The process becomes part of routine operations. We recommend annual tabletop exercises and quarterly reviews of the contact chain. On request, our [security consulting](/en/services/security-consulting-switzerland) team manages this governance schedule.

Continue reading in this cluster
SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland
Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.
Incident response within 72 hours
The outcome of a serious cyber incident is decided in the first hours. ANOMAL provides a Swiss incident response team that works within the 72-hour notification window of cyber insurance. It covers first analysis, containment, evidence preservation and communication with insurer, regulator and executive leadership. A retainer is not mandatory but recommended so the clock does not start with the first phone call.
Security consulting: architecture expertise from live SOC operations
ANOMAL security consulting provides engineering and architecture advisory from people who run a 24/7 SOC every day. We do not provide abstract strategy consulting. We work across four disciplines: Elastic and SIEM engineering, SOC build and consulting, IAM/PAM, and Zero-Trust and NIST audits. Engagements are time-boxed projects with a clear deliverable. We do not provide ongoing staffing or a fractional-CISO model. We scope every mandate individually and provide a dedicated quote.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.