SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland

Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.

All

Delimitation: ISG is not FINMA and not revFADP

Three reporting duties exist in parallel in Switzerland. Organisations must distinguish between them. The same incident can trigger all three at once.

Legal basisNotifyDeadlineTrigger
ISG Art. 74a-74fThe NCSC24 hours after discoveryCyberattack on critical infrastructure
FINMA Guidance 05/2020 / 03/2024FINMA24 hours from discovery (initial notification); full report within 72 hoursCyber incident at supervised institutions
revDSG Art. 24FDPICas soon as possibleData security breach with risk to data subjects
A ransomware event at a bank can trigger all three duties simultaneously. This page covers the ISG duty only.

Who is required to report?

Under ISG Art. 74b, operators of critical infrastructure are subject to the reporting duty. The scope is deliberately broad.

  • Energy suppliers (electricity, gas, district heating, oil)
  • Drinking water and wastewater operators
  • Banks, insurers, financial-market infrastructures
  • Healthcare: hospitals, laboratories, medical care
  • Transport: rail, aviation, road and postal infrastructure
  • Federal, cantonal and municipal authorities
  • Telecoms, internet services and data centres with systemic relevance
  • Food supply, chemical and pharmaceutical production
Note

Even suppliers outside the direct scope of ISG may face contractual requirements to meet the same deadlines. Contracts with large operators increasingly demand this.

What exactly must be reported within 24 hours?

  1. Information on the reporting organisation and the responsible contact
  2. Time the attack was discovered
  3. Type of attack, affected systems and presumed impact
  4. Immediate measures taken and planned
  5. Available information on attacker, tactics and indicators

Organisations must submit a supplementary report within 14 days as further details emerge. They must file electronically via the official the National Cyber Security Centre (NCSC) reporting portal at bacs.admin.ch.

Why the 24-hour deadline is practically impossible without continuous detection

The clock starts at discovery, not at confirmation. If an alert sits unhandled overnight or over the weekend, there is little time left for a well-founded initial report. Continuous detection and assessment ensure that discovery, assessment and reporting follow each other closely. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. Continuous detection shortens this to minutes or hours and simultaneously produces the evidence needed for the report.

  • 24/7 detection: attacks happen at night and at weekends; organisations without 24/7 detection cannot reliably meet the deadline.
  • Documented response: the SOC ticket trail provides timestamps, indicators and mitigations for the notification.
  • Contextualisation: whether an event meets the reporting threshold under ISG Art. 74c depends on context and impact. Assessing that requires processes and accountable people, not just tooling.
  • Auditability: supervisors can request retrospective proof that the 24-hour deadline was met.
Important

This page provides a practical summary. It does not provide legal advice. The authoritative sources are the statute itself (SR 128) and the current the National Cyber Security Centre (NCSC) publication at bacs.admin.ch.

Preparation: what must be in place today

  1. Named reporting officer and deputy, reachable 24/7
  2. Defined reporting channel to the NCSC, portal access tested
  3. SOC or equivalent 24/7 detection with response rights
  4. Playbooks for ransomware, data exfiltration and system compromise
  5. Legal pre-assessment of which parallel duties (FINMA, revFADP (revised Federal Act on Data Protection)) are also triggered
  6. Annual drill of the reporting flow within a tabletop exercise

For manufacturing and OT operators, see SOC Manufacturing. For the broader regulatory picture with FINMA and related supervision, see SOC & FINMA requirements.

Legal basis and sources

  • FINMA Guidance 05/2020 on reporting cyber attacks (Art. 29 para. 2 FINMASA): finma.ch
  • FINMA Guidance 03/2024 refining the reporting duty: finma.ch
  • FINMA Circular 2023/1 «Operational risks and resilience»: finma.ch
  • FINMASA (SR 956.1): Fedlex
  • ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
  • Reporting data security breaches to the FDPIC: edoeb.admin.ch
  • Cybersecurity Ordinance (CSV, SR 128.51): Fedlex

Frequently asked questions

Since when has the 24-hour duty applied?

The reporting duty under ISG Art. 74a-74f entered into force on 1 April 2025. It is the first general, cross-sector reporting duty for cyberattacks on Swiss critical infrastructure.

What happens if a report is missed?

Authorities can impose fines under the ISG for breaches of the reporting duty. Organisations may also face supervisory consequences and reputational damage. The statute (SR 128), supplemented by the National Cyber Security Centre (NCSC) publication, determines the specific legal consequences in each case.

Does every security incident count as reportable?

Only cyberattacks that threaten the functioning of the critical infrastructure operated or compromise data require reporting. Pure anomalies without impact typically fall outside this scope. Organisations should be able to classify events within a few hours.

Must the report be filed in German?

Organisations can file reports in any Swiss official language. The National Cyber Security Centre (NCSC) portal supports German, French and Italian, plus English for international operators.

Is a managed SIEM sufficient to meet the duty?

A managed SIEM alone is insufficient. It delivers alerts and lacks 24/7 response and rapid triage. Meeting the duty requires detection plus response. See [MDR vs. Managed SIEM](/en/soc/soc-siem-edr-xdr-mdr-terms).

Continue reading in this cluster
SOC for manufacturing: monitoring IT and OT together
During an incident, manufacturers lose production, not data. A SOC for manufacturing monitors the IT network and OT environment (PLC, HMI, legacy systems). It stops ransomware before the production line goes down. The core risk is not encryption; it is downtime.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
What is a SOC? Definition, tasks and structure
A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.
SOC, SIEM, EDR, XDR, MDR: the terms explained
SOC is the function; SIEM, EDR and XDR are tools; MDR is a service. The label matters less than whether response happens and in whose mandate. At ANOMAL, SOC as a Service covers detection and response and is often called MDR; a managed SIEM is part of the SOC with analysts and response in the mandate. Customers keep their existing tools.
What a SOC costs: cost drivers, pricing models, in-house or service
SOC costs arise from the response scope first, not the platform licence. What counts are endpoint and identity counts, log sources and data volume, the response scope you choose, onboarding and licences. Swiss providers rarely publish prices; offers differ widely by scope. Your own calculation starts by holding the cost drivers against your organisation.