The confirmed figures
Since 1 April 2025, covered operators of critical infrastructure must report qualifying cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of discovery.
The NCSC semi-annual report published on 30 March 2026 records 325 mandatory reports from the introduction of the duty through the end of 2025, including 145 in the second half of 2025. The NCSC also received 64,733 voluntary reports during 2025. These figures cover different reporting channels and are not a count of confirmed attacks or insured losses.
The duty does not apply to every Swiss business. Whether an organisation and a specific incident fall within scope is determined by the Information Security Act and the Cybersecurity Ordinance.
What the 24-hour deadline requires
The initial report does not have to contain every detail. Missing information can generally be added within 14 days, so operators should not wait for a complete forensic investigation before submitting the first report.
A practical process should include:
- a responsible person and deputy for reporting
- a recorded time of discovery
- secured initial facts about the affected service and impact
- a parallel assessment of other duties, such as notification to the FDPIC or FINMA
- a deadline for supplementing the report
A fine is not automatic after 24 hours
Since 1 October 2025, fines of up to CHF 100,000 are provided for. According to the NCSC, a suspected failure to report first leads to a reminder of the duty. If the organisation does not respond, the NCSC can issue an order with a warning of criminal consequences. A criminal complaint can follow only if the report is still not submitted.
Cyber insurance does not replace compliance. Depending on the contract, legal advice, forensics or crisis support may be insured. Whether procedural costs or fines are covered and legally insurable must be checked expressly in the specific policy.