Kessler
Cybersecurity and Reporting Obligations in Switzerland
Pages
4
Time to read
7 mins
Publication
Language
English
Pages
4
Time to read
7 mins
Publication
Language
English
This report outlines recent developments in cybersecurity regulations in Switzerland, particularly focusing on the reporting obligations for operators of critical infrastructure that began on April 1, 2025. It details the sectors impacted, including energy, finance, and public administration, specifying that cyber incidents must be reported to the National Cyber Security Centre within 24 hours under certain conditions. The report also discusses the implications of the EU Artificial Intelligence Act of 2024, which establishes requirements for high-risk AI systems. It addresses the potential barriers faced by small-scale providers and the call for clearer guidelines in the industry. Additionally, the report covers the challenges of cybersecurity in mergers and acquisitions (M&A), emphasizing the need for early identification of cyber risks. It further discusses the role of cyber insurance in crisis management and its importance in ensuring business continuity during security incidents. Lastly, it assesses the current cybersecurity maturity of Swiss companies, comparing their resilience with international standards.