Cybersecurity Policy Report, Swiss Cyber Incident Reporting Law Takes Effect, (Apr 2, 2025)
Swiss authorities and organizations responsible for critical infrastructure are required to report cyber attacks to the National Cyber Security Centre (NCSC) under a law that went into effect yesterday.
Critical infrastructure sectors under the law include energy, finance, information and communication, public administration, public health, public safety, and transportation. Cyber attacks must be reported if they threaten infrastructure functionality, cause data manipulation or leakage, or involve extortion, NCSC said.
An initial report is due within 24 hours of the cyber attack and a complete report is due within 14 days. Non-compliance will not result in penalties until Oct. 1, after which fines will be implemented.
News: InternationalLegislation DataSecurity