Since 1 April 2025, a new rule has applied in Switzerland: operators of critical infrastructures must report the cyberattacks they fall victim to, to the Federal Office for Cyber Security (the body that runs the NCSC, the National Cyber Security Centre). At first glance, this does not concern the small company in the industrial park. In reality, the effect spreads far further than one might think.
What the law actually says
The obligation stems from the Information Security Act. It targets what are known as critical infrastructures: organisations whose failure would have serious consequences for the country. The NCSC identifies several sectors, among them public administration, energy, finance, health, telecommunications, transport, and food supply.
When one of these organisations suffers a significant cyberattack, it has 24 hours to report it to the NCSC, followed by an additional period to complete its report. The aim is not to punish the victim, but to allow the Confederation to gain an overall view of the threats and to alert quickly the other players exposed to the same type of attack.
Sanctions, but a running-in phase
During the first six months, no sanction was provided for: the point was to give organisations time to get organised. Since 1 October 2025, by contrast, the sanctions mechanism of the Information Security Act has entered into force. An organisation that fails to report an attack faces a fine of up to 100,000 francs.
The mechanism remains measured. The NCSC states that it must first contact the defaulting operator before considering a criminal complaint. The stated objective is transparency, not repression.
The first figures
The NCSC published a review after six months: 164 reports had been filed by operators of critical infrastructures. According to its half-yearly report published on 30 March 2026, this total had reached 325 reports since entry into force, 145 of them in the second half of 2025 alone.
Over this period, the most frequently reported types of attack were hacking (unauthorised intrusion into a system, 20%), denial-of-service or DDoS attacks (a technique that consists of flooding an online service with requests to make it inaccessible, 16%), credential theft (12%), and ransomware (software that encrypts your data and demands a ransom to unlock it, 9%).
Why an SME should take an interest
Here is the point that many executives miss. Your company may not be a critical infrastructure. But if it provides a service to one of them, for example an IT provider, a software supplier, a maintenance office, or a subcontractor with remote access to the network of a hospital, a municipality, or an energy distributor, you are part of its attack surface.
In practice, this plays out in two ways. First, an attack that hits you may have to be reported by your client, which assumes that they demand precise information from you, quickly. Second, these same clients are tightening their contractual requirements: security clauses, an obligation to notify any incident within a tight deadline, evidence of protective measures. An SME unable to meet these expectations loses contracts, quite simply.
What you can do, and what that is not enough to cover
Many useful measures are within your reach without a large budget: keeping an inventory of your accesses and those of your providers, enabling two-factor authentication, backing up your data in an isolated way, and above all knowing who to call and what to document the day an incident occurs. These reflexes already limit the damage considerably.
But let us be clear: these basic steps are not enough on their own to secure a company. Every organisation has its own data flows, its own technical dependencies, and its own contractual obligations. Knowing precisely whether you are affected by the reporting obligation, what your contracts really impose on you, and how to structure a compliant incident response calls for a case-by-case analysis.
In perspective
This reporting obligation is part of a deeper movement: cybersecurity is becoming a requirement of the chain, and no longer the isolated concern of each individual company. For a French-speaking Swiss SME, the good news is that there is no need to master everything in-house. What matters is understanding your position in this chain and your real responsibilities. That is precisely the starting point of professional support: mapping your exposure before a client, or an attack, does it in your place.