On the morning an incident breaks out, the question is not technical. It is much simpler: who do I call, and in what order?

The answer depends on what happened, but the logic stays the same. Some contacts help you regain control. Others are of no use in the emergency, but everything still plays out in the first few days, because deadlines run without anyone warning you.

Here is what each one can actually do for you, and what they will not do.

Your IT provider, the first call

In the vast majority of cases, this is who gets called first, and it is the right decision. They know your setup, they have the access, they can isolate a machine, cut a connection, or check the state of your backups while you are still trying to understand what happened.

What they can do: assess the scale, contain the spread, restore what can be restored, and tell you whether your backups are usable. That is already considerable.

What they may not be able to do: incident response in the strict sense. Understanding how the attacker got in, whether they are still present, what they viewed or copied, and preserving the technical evidence needed for an investigation requires a different trade. A generalist IT technician, even an excellent one, is not an incident response specialist, in the same way a general practitioner is not a surgeon.

The reflex that destroys evidence

The instinctive reaction is to reinstall everything as fast as possible to get back to work. That is understandable, but reinstalling a server erases the traces that would have shown how the attacker got in, and whether they still have access. Ask your provider to keep a copy of the affected systems before any restoration.

When should you notify your insurer?

This is the point almost no one anticipates, and the one that costs the most when ignored.

Insurance contracts, whether a dedicated cyber policy or cover built into your general liability or business interruption policy, set short reporting deadlines. A few days, sometimes less. Once that deadline passes, cover can be refused even though the loss was covered.

Even trickier: some policies require notification before any technical intervention. The insurer wants to be able to send its own expert, assess the state of the systems, and prevent manipulations that would make the file impossible to process. If your provider wipes everything on Saturday and you report on Monday, you risk having your claim refused.

Do not look for this information on the day of the attack. Open your contract now, find the reporting clause, and note the emergency number on the list we are preparing below. If you are still unsure what your policy covers, our article on what cyber insurance actually covers details the covered items, the usual exclusions, and the policyholder’s obligations.

Should you report the incident to the NCSC?

The National Cyber Security Centre provides an online reporting form, accessible from its official website. Reporting takes a few minutes and is done in writing.

Let’s be clear about what it offers. The NCSC is not a response service that shows up to fix your servers. It is not a repair hotline. It does, however, feed the national picture of the threat, can earn you useful technical recommendations, and allows the office to spot when the same wave hits several companies at once.

This collective dimension is not incidental. It is because tens of thousands of organisations report that the actual state of the threat in Switzerland is known: the NCSC received 64,733 voluntary cyber incident reports in 2025, against 62,954 in 2024.

A common confusion about the reporting duty

Since 1 April 2025, a duty to report certain cyberattacks to the NCSC does exist, with sanctions applicable since 1 October 2025. But it targets only operators of critical infrastructure: energy, health, transport, public administrations, and a few other categories defined by law. An ordinary SME is not concerned. For them, reporting remains voluntary.

Should you file a complaint with the cantonal police?

Many business owners give up, telling themselves the perpetrator will never be found. That is often true, and yet the complaint keeps three concrete benefits.

First, it produces an official document. Your insurer will ask for it, sometimes your partners too, and a board of directors or an auditor appreciates finding a formal record in the file.

Second, it feeds the statistics. The resources allocated to specialised units depend on the volume reported. An unreported attack does not exist in the figures, and will therefore have no effect on future resources.

Third, your case may complement an ongoing investigation. Criminal groups strike in series, with the same tools and the same wallet addresses. The seemingly insignificant detail in your file may be the missing piece of a case opened elsewhere, something you have no way of knowing.

Contact the police of your canton. Some forces have units dedicated to computer crime. Bring everything you have: messages, screenshots, technical logs, bank details used, timestamps.

When should you inform the FDPIC?

The Federal Data Protection and Information Commissioner does not need to be informed of every cyberattack. It must be when personal data has been affected and the breach is likely to result in a high risk for the people concerned.

A production server encrypted without any personal data leaking does not trigger this obligation. A customer file with contact details, health data, or financial information exfiltrated, however, does.

Swiss law requires a report as soon as possible. It sets no fixed deadline. The famous 72-hour deadline comes from the European regulation, not from Swiss law, and confusion between the two regimes is very common. Reporting is done via the FDPIC’s dedicated portal. The details of the procedure are covered in our article on reporting a data breach.

Your customers, your partners, your bank

If a payment is at stake, a diverted transfer, changed bank details, a fraudulent invoice paid, call your bank immediately, before everything else. A recent transfer can sometimes be blocked or recalled, but this window is measured in hours, not days. This is the only case where a call comes before your IT provider. The mechanics of these frauds are detailed in our article on CEO fraud.

Your customers and partners come next. They must be informed if their data is involved, if your service is interrupted, or if your compromised mailbox may have been used to send fraudulent messages in your name. The timing, the channel, and the wording deserve preparation: that is the subject of our article on crisis communication.

The list to print today

On the day of the attack, your e-mail may be inaccessible, your file server encrypted, and the address book on your work phone may not be up to date. A contact list stored only on the network is a list you will not have.

WhoWhen to callWhat they bring
IT providerImmediatelyAssessment, isolation, backup status, restoration
InsurerWithin the first hours, before any technical intervention if the contract requires itCost coverage, expert, sometimes legal assistance
BankImmediately if a payment is involvedPossible blocking or recall of a recent transfer
Cantonal policeIn the days that followComplaint, official document, investigation, statistics
NCSCOnce the situation is stabilisedRecommendations, national picture of the threat
FDPICAs soon as possible, if personal data and high riskLegal compliance, advice on informing individuals
One A4 sheet, two paper copies

Fill in this table with real contact details: the name and direct number of your contact at the provider, your insurer's emergency and policy number, your bank advisor's line, the police station of your municipality. Print it in two copies, one at the office and one at the manager's home. Review it once a year: providers change, and so do contracts.

Knowing who to call does not tell you what to do

Preparing this list takes an hour and saves you considerable time on the day it matters. It is an exercise you can carry out alone, with no budget, and there is no reason to put it off.

But a list of phone numbers does not answer the questions that actually arise while you wait for your provider to call back. Should you unplug the server or leave it running? What do you tell employees arriving at the office? What data may have left, and how do you check? Who decides, if the manager is unreachable?

These answers depend on your setup, your workflows, and your own obligations. They are prepared calmly, tested, and revised. That is exactly what an incident response plan sets out, a one- to two-page document that extends your phone list with roles, decisions, and expected actions. A company that has rehearsed its scenario once in advance does not live through the same first hours as a company that improvises. That is where the gap widens, far more than on the quality of the phone list.

To go further, see the right reflexes for the first hours, the whole Respond to an attack pillar, and the cyber check-up to gauge your current level of preparedness.