SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland
Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.
Delimitation: ISG is not FINMA and not revFADP
Three reporting duties exist in parallel in Switzerland. Organisations must distinguish between them. The same incident can trigger all three at once.
| Legal basis | Notify | Deadline | Trigger |
|---|---|---|---|
| ISG Art. 74a-74f | The NCSC | 24 hours after discovery | Cyberattack on critical infrastructure |
| FINMA Guidance 05/2020 / 03/2024 | FINMA | 24 hours from discovery (initial notification); full report within 72 hours | Cyber incident at supervised institutions |
| revDSG Art. 24 | FDPIC | as soon as possible | Data security breach with risk to data subjects |
Who is required to report?
Under ISG Art. 74b, operators of critical infrastructure are subject to the reporting duty. The scope is deliberately broad.
- Energy suppliers (electricity, gas, district heating, oil)
- Drinking water and wastewater operators
- Banks, insurers, financial-market infrastructures
- Healthcare: hospitals, laboratories, medical care
- Transport: rail, aviation, road and postal infrastructure
- Federal, cantonal and municipal authorities
- Telecoms, internet services and data centres with systemic relevance
- Food supply, chemical and pharmaceutical production
Even suppliers outside the direct scope of ISG may face contractual requirements to meet the same deadlines. Contracts with large operators increasingly demand this.
What exactly must be reported within 24 hours?
- Information on the reporting organisation and the responsible contact
- Time the attack was discovered
- Type of attack, affected systems and presumed impact
- Immediate measures taken and planned
- Available information on attacker, tactics and indicators
Organisations must submit a supplementary report within 14 days as further details emerge. They must file electronically via the official the National Cyber Security Centre (NCSC) reporting portal at bacs.admin.ch.
Why the 24-hour deadline is practically impossible without continuous detection
The clock starts at discovery, not at confirmation. If an alert sits unhandled overnight or over the weekend, there is little time left for a well-founded initial report. Continuous detection and assessment ensure that discovery, assessment and reporting follow each other closely. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. Continuous detection shortens this to minutes or hours and simultaneously produces the evidence needed for the report.
- 24/7 detection: attacks happen at night and at weekends; organisations without 24/7 detection cannot reliably meet the deadline.
- Documented response: the SOC ticket trail provides timestamps, indicators and mitigations for the notification.
- Contextualisation: whether an event meets the reporting threshold under ISG Art. 74c depends on context and impact. Assessing that requires processes and accountable people, not just tooling.
- Auditability: supervisors can request retrospective proof that the 24-hour deadline was met.
This page provides a practical summary. It does not provide legal advice. The authoritative sources are the statute itself (SR 128) and the current the National Cyber Security Centre (NCSC) publication at bacs.admin.ch.
Preparation: what must be in place today
- Named reporting officer and deputy, reachable 24/7
- Defined reporting channel to the NCSC, portal access tested
- SOC or equivalent 24/7 detection with response rights
- Playbooks for ransomware, data exfiltration and system compromise
- Legal pre-assessment of which parallel duties (FINMA, revFADP (revised Federal Act on Data Protection)) are also triggered
- Annual drill of the reporting flow within a tabletop exercise
For manufacturing and OT operators, see SOC Manufacturing. For the broader regulatory picture with FINMA and related supervision, see SOC & FINMA requirements.
Placement in SOC operations
See SOC as a Service Switzerland for details on how SOC operations support the 24-hour reporting deadline.
Legal basis and sources
- FINMA Guidance 05/2020 on reporting cyber attacks (Art. 29 para. 2 FINMASA): finma.ch
- FINMA Guidance 03/2024 refining the reporting duty: finma.ch
- FINMA Circular 2023/1 «Operational risks and resilience»: finma.ch
- FINMASA (SR 956.1): Fedlex
- ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
- Reporting data security breaches to the FDPIC: edoeb.admin.ch
- Cybersecurity Ordinance (CSV, SR 128.51): Fedlex
Frequently asked questions
Since when has the 24-hour duty applied?
The reporting duty under ISG Art. 74a-74f entered into force on 1 April 2025. It is the first general, cross-sector reporting duty for cyberattacks on Swiss critical infrastructure.
What happens if a report is missed?
Authorities can impose fines under the ISG for breaches of the reporting duty. Organisations may also face supervisory consequences and reputational damage. The statute (SR 128), supplemented by the National Cyber Security Centre (NCSC) publication, determines the specific legal consequences in each case.
Does every security incident count as reportable?
Only cyberattacks that threaten the functioning of the critical infrastructure operated or compromise data require reporting. Pure anomalies without impact typically fall outside this scope. Organisations should be able to classify events within a few hours.
Must the report be filed in German?
Organisations can file reports in any Swiss official language. The National Cyber Security Centre (NCSC) portal supports German, French and Italian, plus English for international operators.
Is a managed SIEM sufficient to meet the duty?
A managed SIEM alone is insufficient. It delivers alerts and lacks 24/7 response and rapid triage. Meeting the duty requires detection plus response. See [MDR vs. Managed SIEM](/en/soc/soc-siem-edr-xdr-mdr-terms).
Related terms
- Incident Response Incident Response is the structured process of containing, eradicating, and recovering from a security incident.
- Digital Forensics Digital forensics secures and investigates digital traces so an incident can be reconstructed and used as evidence.
- Playbook A playbook is a predefined procedure describing how a SOC responds to a specific type of security incident.
- SOC A Security Operations Center (SOC) is the team that constantly monitors an organisation's IT for attacks and intervenes during incidents.