SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisor

FINMA requires supervised institutions to document detection and response capabilities and demonstrate operational resilience. Institutions must report material cyber incidents within 24 hours of assessment. FINMA Circular 2023/1 Operational Risks and Resilience is the authoritative reference. It has been in force since 1 Jan 2024 and replaced Circular 2008/21. A SOC delivers 24/7 detection, a ticket and evidence trail and audit-ready evidence. Institutions need all three to meet the requirements reliably.

All

Delimitation: FINMA is not ISG and not revFADP

FINMA requirements target supervised financial institutions and financial-market infrastructures. The same incident can trigger these obligations in parallel with the ISG duty and a revFADP (revised Federal Act on Data Protection) notification to the FDPIC. The three regimes differ in addressee, deadline and trigger.

RegimeAddresseeNotifyDeadline
FINMA Circ. 2023/1 (successor to Circ. 2008/21)Supervised institutions (banks, insurers, FMI)FINMA24 hours after assessment as material
ISG Art. 74a-74fOperators of critical infrastructureBACS24 hours after discovery
revDSG Art. 24All controllersFDPICas soon as possible
A material ransomware event at a bank can trigger all three notifications at once. For the ISG page, see SOC & ISG 24h reporting duty.

What FINMA requires

  • Documented cyber risk governance at board and executive level, including responsibilities and reporting.
  • 24/7 detection with demonstrable processes. Office-hours-only monitoring is insufficient for supervised institutions.
  • Response capability with defined playbooks for ransomware, data exfiltration, compromise and third-party incidents.
  • Institutions must notify FINMA of material cyber incidents within 24 hours of discovery. They must submit a detailed report within 72 hours of the initial notification and provide follow-ups until closure.
  • Operational resilience: identification of critical functions, tolerance thresholds for disruption and regular testing under realistic scenarios.
  • Outsourcing and third-party risks fully in scope of detection and response, in particular cloud, IT providers and SaaS.
Important

This page is a practice-focused summary, not supervisory guidance. The authoritative sources are the FINMA circulars in their current version and institution-specific rulings.

What counts as a material cyber incident?

FINMA Circ. 2023/1 focuses on impact on critical functions, clients and market integrity. The actual or likely effect on operations determines materiality. The attack technique and toolstack do not determine it.

  • Failure or significant disruption of a critical function (payments, trading, custody, contract administration).
  • Compromise of client data with potential reputational or legal effect.
  • Unauthorised access to core production systems or systems with far-reaching entitlements.
  • Incident at a material third-party provider with knock-on effect on the institution.

What the SOC delivers in the FINMA context

  • 24/7 detection with documented rule and use-case catalogues, versioned and audit-grade.
  • Response processes with clear escalation to CISO, legal and executive management, including a template for the FINMA notification.
  • Ticket and evidence trail: every alert, action and decision with timestamp and owner.
  • Monthly reporting with MTTD, MTTR, false-positive rate and incident categorisation by FINMA-relevant impact.
  • Participation in resilience testing, tabletop exercises and scenario simulations, documented for internal and external audit.
Bottom line

The 24-hour deadline runs from discovery, and an initial criticality assessment is due within it; if an alert sits unhandled overnight or over the weekend, that time is lost. Without a ticket trail, the supervisor lacks the required evidence path. Both gaps are recurring findings in FINMA reviews.

Practice: what supervisors and internal audit typically want to see

  1. Proof of 24/7 staffing including shift plans and cover arrangements.
  2. Catalogue of detection use cases mapped to MITRE ATT&CK and to FINMA-relevant risks.
  3. Definition and evidence of materiality thresholds, including a decision tree identifying who assesses incidents as material.
  4. Outsourcing and cloud scope: which systems are monitored by the SOC and how the provider chain is covered.
  5. Documented testing regime for detection and response, including purple teaming, tabletops and live-fire.
  6. Reporting lines to the board and executive management with frequency and content.

For the economics, see SOC cost Switzerland and SOC ROI. For the neighbouring regulation, see SOC & ISG 24h reporting.

Legal basis and sources

  • FINMA Guidance 05/2020 on reporting cyber attacks (Art. 29 para. 2 FINMASA): finma.ch
  • FINMA Guidance 03/2024 refining the reporting duty: finma.ch
  • FINMA Circular 2023/1 «Operational risks and resilience»: finma.ch
  • FINMASA (SR 956.1): Fedlex
  • ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
  • Reporting data security breaches to the FDPIC: edoeb.admin.ch

Frequently asked questions

Does FINMA explicitly require a SOC?

The circulars require the capabilities a SOC provides: 24/7 detection, documented response and demonstrated resilience. They do not explicitly require the name 'SOC'. Institutions using another model must provide substantive evidence of equivalent capabilities.

When does the 24-hour clock start?

Under FINMA Guidance 03/2024, the 24-hour clock starts at discovery of the cyber attack. An initial criticality assessment must be made within that window, and the deadline takes precedence. The full report follows within 72 hours via the EHP; banking business days count, except for severe attacks.

Is a managed SIEM sufficient for FINMA purposes?

A managed SIEM operates the platform and produces alerts. Whether response and materiality assessment sit inside the mandate is a contractual question; FINMA purposes require both to be evidenced. See [MDR vs. Managed SIEM](/en/soc/soc-siem-edr-xdr-mdr-terms).

How does FINMA treat outsourcing to an external SOC provider?

FINMA treats this as outsourcing and applies the corresponding requirements. These cover due diligence in selection, contract design, instruction and audit rights, contingency arrangements and exit provisions. The institution retains full responsibility.

Does this apply only to banks?

No. FINMA Circ. 2023/1 covers banks, insurers, financial-market infrastructures and further supervised entities. The depth of the requirements is proportional to size and criticality.

Continue reading in this cluster
SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland
Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
What is a SOC? Definition, tasks and structure
A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.
SOC, SIEM, EDR, XDR, MDR: the terms explained
SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.
What a SOC costs: cost drivers, pricing models, in-house or service
SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.