Which incidents need to be reported?

Examples of when a cyberattack must be reported include when it threatens the functioning of critical infrastructure, has resulted in the manipulation or leakage of information, or involves blackmail, threats or coercion. Critical infrastructure operators who fail to report a cyberattack may be fined.

Types of attacks include:

  • malware successfully installed on a system 
  • encryption trojans
  • availability attacks 
  • gaining unauthorised access to computer systems through the exploitation of security holes.

The Federal Council has decided to implement the relevant legislation for fines on 1 October in order to give those concerned sufficient time to prepare for the new reporting obligation. This means that the reporting obligation will apply for six months before failure to report becomes sanctionable. 

Last modification 07.03.2025

Top of page

https://www.ncsc.admin.ch/content/ncsc/en/home/meldepflicht/meldepflichtige-cyberangriffe.html