Skip to Primary Navigation

Switzerland announces new cyber-attack reporting requirement for financial institutions

Modern cityscape at City of Zürich.
Photo: Getty Images

Ordinance sets out obligation to report cyberattacks on critical infrastructure.

On May 22, 2024, the Swiss Federal Council released its draft ordinance implementing the reporting requirement in the event of cyber-attack as set out in the Information Security Act. The public consultation will last until September 13, 2024. This new reporting requirement is expected to apply from January 1, 2025.

The Information Security Act contains a

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience