Companies and authorities
Information for companies and authorities on protection and how to respond to cyber incidents, as well as on the obligation to report.
Report a cyberincident
Report the incident here
Information on the reporting obligation
On 7 March, the Federal Council introduced a reporting obligation for cyberattacks on critical infrastructure, which will come into force on 1 April. Operators of critical infrastructure will be required to report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of discovery. After submitting the initial report within 24 hours of discovering the incident, they have 14 days to complete their report.
Information on the reporting obligation
Cyber Security Hub
The Cyber Security Hub (CSH) is an important information system of the National Cyber Security Centre (NCSC). It is used to share and manage information on cyber threats, cyber incidents and cybersecurity practices.
What should you do in the case of a cyber incident?

A data leak – what next?
Generally, when a data leak occurs, the aim is to limit the damage, find the vulnerability and remove it, and prevent further data leaks.

Cyberattack – how to communicate?
Good crisis communication helps the company/organisation/authority to position themselves as a central and trustworthy source of information and prevent speculation, indiscretions and false reporting. Cyberattacks therefore require prompt, coordinated and well-thought-out crisis communication in order to reassure and regain the trust of stakeholders.

DDoS attack – what next?
When facing a DDoS attack, the main aim is to show the attackers that they have not achieved their objective. If you withstand the attempt long enough, the attackers will typically turn their attention to someone else.

Hacked website – what next?
There are two common points of entry which hackers and cybercriminals use to gain access to a website: Stolen credentials and Outdated CMS. The NCSC instructions provide a brief overview of how you can to clean up and secure your website.

Ransomware – What next?
Encryption Trojans (ransomware) can cause considerable damage, especially if your data backups are also affected. In the event of such an incident, remain calm and act with caution.
How can you protect yourself against a cyber incident?

Getting started
Cyberattacks affect micro-enterprises, too. Five essential measures can significantly improve your cybersecurity levels: multi-factor authentication, daily backups, updates, caution when opening emails, and secure passwords.

Strong cybersecurity foundations for businesses and public authorities
Cyberattacks can affect any business or public authority, regardless of size, sector or technical expertise. The consequences range from temporary system failures and the loss of confidential data to liability issues and reputational damage. Effectively protecting against such threats therefore requires both technical and organisational measures that work in tandem. The following section outlines how businesses and public authorities can take targeted steps to tighten their cybersecurity.

Standards and methods
The NCSC provides standards and methods to improve cyber resilience: the Cybersecurity and Resilience Method (CSRM) for process security, ICT minimum standards for critical infrastructure and, in future, an assessment tool that will enable organisations to measure their cyber resilience maturity levels.

Implement protective measures
Specific protective measures complement baseline protection; they are determined based on identified risks and consistently implemented to specifically protect information assets, systems, and data against relevant cyber threats.

Cooperation with service providers
Cyber security also involves collaboration with IT service providers, cloud providers and other external partners. The NCSC offers a number of resources to ensure that this collaboration is successful.
Stay informed

Hot topics
The latest news on cybersecurity and BACS

Current Incidents
Overview of NCSC warnings.

Newsletter
The NCSC publishes a monthly newsletter covering the most important topics.
Follow us on LinkedIn and get all the NCSC news.

Semi-Annual Reports
The NCSC publishes a report entitled ‘Cybersecurity: The Situation in Switzerland and Internationally’ half-yearly.

Technical reports
The reports explore various topical issues relating to incidents and developments in information and communication technologies (ICT) and will address the corresponding set of problems and put them in a major context.
