IT specialists
Information on reporting obligations and vulnerabilities, key contacts and specific support measures in the field of cyber security for IT specialists.
Reporting obligation for cyberattacks on critical infrastructure
On 7 March 2025, the Federal Council brought into force the reporting obligation for cyberattacks on critical infrastructure, with effect from 1 April 2025. Operators of critical infrastructure will be required to report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of discovery. After submitting the initial report within 24 hours of discovering the incident, they have 14 days to complete their report.
Report to NCSC
The NCSC receives voluntary reports of cyberincidents from the public, companies and the authorities, and assists them in taking the necessary steps. The NCSC is also responsible for collecting reports of cyberincidents from operators of critical infrastructure, who have been subject to a reporting obligation since 1 April 2025. The NCSC also receives reports of vulnerabilities and assigns them a unique identification number in accordance with the international reference system.

Information on the reporting obligation
On 7 March, the Federal Council introduced a reporting obligation for cyberattacks on critical infrastructure, which will come into force on 1 April. Operators of critical infrastructure will be required to report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of discovery. After submitting the initial report within 24 hours of discovering the incident, they have 14 days to complete their report.
Exchange with the NCSC

Information about the CSH
The Cyber Security Hub (CSH) is an important information system of the National Cyber Security Centre (NCSC). It is used to share and manage information on cyber threats, cyber incidents and cybersecurity practices.

Information on GovCERT
The Government Computer Emergency Response Team (GovCERT) is the national specialist service responsible for the technical management of cyberincidents and technical analysis of cyberthreats. It supports critical infrastructure operators, the public sector and the Swiss business location with technical information on current cyberthreats and with the management of cyberincidents. GovCERT also works in close collaboration with the police authorities. This cooperation covers both the exchange of information and support with technical analyses.

Contact
Do you have any questions for NCSC? Here you'll find addresses, contact information, reporting centers, and encryption keys.
Vulnerabilities in IT systems
Have you discovered a vulnerability in an IT system or in commercially available applications, software or hardware and want to report it? The golden rule is to inform the vendor or system owner directly. However, if these organisations do not respond to you or if their response is insufficient, the NCSC can act as an intermediary to resolve such security issues.
Reporting a vulnerability (Coordinated Vulnerability Disclosure CVD)
Have you discovered a vulnerability in an IT system or in commercially available applications, software or hardware impacting Switzerland and want to report it? There are different ways to report a vulnerability.

CVE records
As part of its CNA duties, the NCSC maintains a catalog of CVE records published under its authority.

Bug bounty programme to increase cyber-resilience in the Federal Administration
In order to increase its cyber security and reduce cyber risks effectively and cost-efficiently, the Federal Administration runs bug bounty programmes under the leadership of the National Cyber Security Centre (NCSC) and in cooperation with other administrative units and Bug Bounty Switzerland AG.
Implement protective measures

Emergency planning is the key to cyber resilience
Cyberattacks that paralyse public services or result in the disclosure of sensitive data can undermine the public's trust in government institutions. Past incidents and the "2025 Myni Gmeind" survey on cybersecurity demonstrate that many communes could enhance their preparedness for cyberincidents. To help communes and organisations in Switzerland strengthen their cyber resilience in a simple and hands-on way, the NCSC has launched a project together with its partner network. As part of this project, an emergency planning model was developed to provide practical guidance on enhancing cyber resilience.

Measures to secure content management systems (CMS)
The number of websites has truly exploded over the past few years, not least because easy-to-use website creation tools are available that do not require any technical know-how and are increasingly affordable. Content management systems (CMS) can be used to design and launch a website with just a few clicks. There are now dozens of such CMS used by private individuals, SMEs and large companies alike.

Measures for security in the Internet of Things (IoT)
Smart devices, such as speakers, light switches and fridges, can be vulnerable to attack. The NCSC recommends taking preventive measures to improve the cybersecurity of your IoT devices.

Measures to protect industrial control systems (ICSs)
Securing industrial control systems (ICSs) protects data, infrastructure, processes and people. The NCSC has summarised the key measures.

Measures to counter DDoS attacks
A DDoS (distributed denial of service) is a type of attack on computer systems with the aim of making them unavailable. This can have far-reaching economic consequences for the victim.

Security.txt - Include your security contact on your website
In case of cybersecurity problems in a company or organisation, it is very important to quickly inform the relevant security contact. Often, however, these contacts are not easy to find on websites, or are not even listed. The "security.txt" standard provides a way to publish the security contact of an organisation or company in a uniform way, thus making it quicker to find.

Secure use of remote access
An increasing number of companies are using remote methods to access their corporate networks. However, this technology also increases the risk of cyberattacks.
Technology considerations and reports

Technology considerations
Under this heading, the NCSC publishes short statements on selected topics that are related to IT security and are of general interest.

Technical reports
The reports explore various topical issues relating to incidents and developments in information and communication technologies (ICT) and will address the corresponding set of problems and put them in a major context.

Semi-Annual Reports
The NCSC publishes a report entitled ‘Cybersecurity: The Situation in Switzerland and Internationally’ half-yearly.