SOC & FINMA: What a Swiss financial institution needs to satisfy the supervisor
FINMA requires supervised institutions to document detection and response capabilities and demonstrate operational resilience. Institutions must report material cyber incidents within 24 hours of assessment. FINMA Circular 2023/1 Operational Risks and Resilience is the authoritative reference. It has been in force since 1 Jan 2024 and replaced Circular 2008/21. A SOC delivers 24/7 detection, a ticket and evidence trail and audit-ready evidence. Institutions need all three to meet the requirements reliably.
Delimitation: FINMA is not ISG and not revFADP
FINMA requirements target supervised financial institutions and financial-market infrastructures. The same incident can trigger these obligations in parallel with the ISG duty and a revFADP (revised Federal Act on Data Protection) notification to the FDPIC. The three regimes differ in addressee, deadline and trigger.
| Regime | Addressee | Notify | Deadline |
|---|---|---|---|
| FINMA Circ. 2023/1 (successor to Circ. 2008/21) | Supervised institutions (banks, insurers, FMI) | FINMA | 24 hours after assessment as material |
| ISG Art. 74a-74f | Operators of critical infrastructure | BACS | 24 hours after discovery |
| revDSG Art. 24 | All controllers | FDPIC | as soon as possible |
What FINMA requires
- Documented cyber risk governance at board and executive level, including responsibilities and reporting.
- 24/7 detection with demonstrable processes. Office-hours-only monitoring is insufficient for supervised institutions.
- Response capability with defined playbooks for ransomware, data exfiltration, compromise and third-party incidents.
- Institutions must notify FINMA of material cyber incidents within 24 hours of discovery. They must submit a detailed report within 72 hours of the initial notification and provide follow-ups until closure.
- Operational resilience: identification of critical functions, tolerance thresholds for disruption and regular testing under realistic scenarios.
- Outsourcing and third-party risks fully in scope of detection and response, in particular cloud, IT providers and SaaS.
This page is a practice-focused summary, not supervisory guidance. The authoritative sources are the FINMA circulars in their current version and institution-specific rulings.
What counts as a material cyber incident?
FINMA Circ. 2023/1 focuses on impact on critical functions, clients and market integrity. The actual or likely effect on operations determines materiality. The attack technique and toolstack do not determine it.
- Failure or significant disruption of a critical function (payments, trading, custody, contract administration).
- Compromise of client data with potential reputational or legal effect.
- Unauthorised access to core production systems or systems with far-reaching entitlements.
- Incident at a material third-party provider with knock-on effect on the institution.
What the SOC delivers in the FINMA context
- 24/7 detection with documented rule and use-case catalogues, versioned and audit-grade.
- Response processes with clear escalation to CISO, legal and executive management, including a template for the FINMA notification.
- Ticket and evidence trail: every alert, action and decision with timestamp and owner.
- Monthly reporting with MTTD, MTTR, false-positive rate and incident categorisation by FINMA-relevant impact.
- Participation in resilience testing, tabletop exercises and scenario simulations, documented for internal and external audit.
The 24-hour deadline runs from discovery, and an initial criticality assessment is due within it; if an alert sits unhandled overnight or over the weekend, that time is lost. Without a ticket trail, the supervisor lacks the required evidence path. Both gaps are recurring findings in FINMA reviews.
Practice: what supervisors and internal audit typically want to see
- Proof of 24/7 staffing including shift plans and cover arrangements.
- Catalogue of detection use cases mapped to MITRE ATT&CK and to FINMA-relevant risks.
- Definition and evidence of materiality thresholds, including a decision tree identifying who assesses incidents as material.
- Outsourcing and cloud scope: which systems are monitored by the SOC and how the provider chain is covered.
- Documented testing regime for detection and response, including purple teaming, tabletops and live-fire.
- Reporting lines to the board and executive management with frequency and content.
For the economics, see SOC cost Switzerland and SOC ROI. For the neighbouring regulation, see SOC & ISG 24h reporting.
Placement in SOC operations
The SOC as a Service Switzerland page describes how operations meet supervisory requirements.
Legal basis and sources
- FINMA Guidance 05/2020 on reporting cyber attacks (Art. 29 para. 2 FINMASA): finma.ch
- FINMA Guidance 03/2024 refining the reporting duty: finma.ch
- FINMA Circular 2023/1 «Operational risks and resilience»: finma.ch
- FINMASA (SR 956.1): Fedlex
- ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
- Reporting data security breaches to the FDPIC: edoeb.admin.ch
Frequently asked questions
Does FINMA explicitly require a SOC?
The circulars require the capabilities a SOC provides: 24/7 detection, documented response and demonstrated resilience. They do not explicitly require the name 'SOC'. Institutions using another model must provide substantive evidence of equivalent capabilities.
When does the 24-hour clock start?
Under FINMA Guidance 03/2024, the 24-hour clock starts at discovery of the cyber attack. An initial criticality assessment must be made within that window, and the deadline takes precedence. The full report follows within 72 hours via the EHP; banking business days count, except for severe attacks.
Is a managed SIEM sufficient for FINMA purposes?
A managed SIEM operates the platform and produces alerts. Whether response and materiality assessment sit inside the mandate is a contractual question; FINMA purposes require both to be evidenced. See [MDR vs. Managed SIEM](/en/soc/soc-siem-edr-xdr-mdr-terms).
How does FINMA treat outsourcing to an external SOC provider?
FINMA treats this as outsourcing and applies the corresponding requirements. These cover due diligence in selection, contract design, instruction and audit rights, contingency arrangements and exit provisions. The institution retains full responsibility.
Does this apply only to banks?
No. FINMA Circ. 2023/1 covers banks, insurers, financial-market infrastructures and further supervised entities. The depth of the requirements is proportional to size and criticality.
Related terms
- FINMA The Swiss Financial Market Supervisory Authority (FINMA) supervises financial institutions and sets their cybersecurity requirements.
- DORA The Digital Operational Resilience Act (DORA) is an EU regulation for the digital resilience of the financial sector.
- ISO 27001 ISO 27001 is the international standard for information security management systems. Certification confirms that risks are managed systematically.
- Incident Response Incident Response is the structured process of containing, eradicating, and recovering from a security incident.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.