Skip to main content

Companies and authorities

Information for companies and authorities on protection and how to respond to cyber incidents, as well as on the obligation to report.

Report a cyberincident

We can identify possible trends in dangers on the internet and take targeted action against them. After answering a few questions, you will receive an automated initial assessment of your case with the measures to be taken and can then forward the case to the National Cyber Security Center NCSC for further processing.
Report the incident here

Information on the reporting obligation

On 7 March, the Federal Council introduced a reporting obligation for cyberattacks on critical infrastructure, which will come into force on 1 April. Operators of critical infrastructure will be required to report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of discovery. After submitting the initial report within 24 hours of discovering the incident, they have 14 days to complete their report.

Information on the reporting obligation

Cyber Security Hub

The Cyber Security Hub (CSH) is an important information system of the National Cyber Security Centre (NCSC). It is used to share and manage information on cyber threats, cyber incidents and cybersecurity practices.

Information about the CSH

What should you do in the case of a cyber incident?

A data leak – what next?

Generally, when a data leak occurs, the aim is to limit the damage, find the vulnerability and remove it, and prevent further data leaks.

Cyberattack – how to communicate?

Good crisis communication helps the company/organisation/authority to position themselves as a central and trustworthy source of information and prevent speculation, indiscretions and false reporting. Cyberattacks therefore require prompt, coordinated and well-thought-out crisis communication in order to reassure and regain the trust of stakeholders.

DDoS attack – what next?

When facing a DDoS attack, the main aim is to show the attackers that they have not achieved their objective. If you withstand the attempt long enough, the attackers will typically turn their attention to someone else.

Hacked website – what next?

There are two common points of entry which hackers and cybercriminals use to gain access to a website: Stolen credentials and Outdated CMS. The NCSC instructions provide a brief overview of how you can to clean up and secure your website.

Ransomware – What next?

Encryption Trojans (ransomware) can cause considerable damage, especially if your data backups are also affected. In the event of such an incident, remain calm and act with caution.

How can you protect yourself against a cyber incident?

Getting started

Cyberattacks affect micro-enterprises, too. Five essential measures can significantly improve your cybersecurity levels: multi-factor authentication, daily backups, updates, caution when opening emails, and secure passwords.

Strong cybersecurity foundations for businesses and public authorities

Cyberattacks can affect any business or public authority, regardless of size, sector or technical expertise. The consequences range from temporary system failures and the loss of confidential data to liability issues and reputational damage. Effectively protecting against such threats therefore requires both technical and organisational measures that work in tandem. The following section outlines how businesses and public authorities can take targeted steps to tighten their cybersecurity.

Standards and methods

The NCSC provides standards and methods to improve cyber resilience: the Cybersecurity and Resilience Method (CSRM) for process security, ICT minimum standards for critical infrastructure and, in future, an assessment tool that will enable organisations to measure their cyber resilience maturity levels.

Implement protective measures

Specific protective measures complement baseline protection; they are determined based on identified risks and consistently implemented to specifically protect information assets, systems, and data against relevant cyber threats.

Cooperation with service providers

Cyber security also involves collaboration with IT service providers, cloud providers and other external partners. The NCSC offers a number of resources to ensure that this collaboration is successful.

Stay informed

Hot topics

The latest news on cybersecurity and BACS

Current Incidents

Overview of NCSC warnings.

Newsletter

The NCSC publishes a monthly newsletter covering the most important topics.

LinkedIn

Follow us on LinkedIn and get all the NCSC news.

Semi-Annual Reports

The NCSC publishes a report entitled ‘Cybersecurity: The Situation in Switzerland and Internationally’ half-yearly.

Technical reports

The reports explore various topical issues relating to incidents and developments in information and communication technologies (ICT) and will address the corresponding set of problems and put them in a major context.