The demand that hasn’t called yet Log in
getfishnet
Test my eligibility

Change your language and country?

You are currently viewing the Switzerland version, in English. Another version may be better suited to your situation.

Stay on this version Change version
Market reading · it cybersecurite

Cyberattack: deciding within 24 hours

How to assess a cyberattack, decide within 24 hours and preserve customer trust while facts remain incomplete.

getfishnetDocumented analysis20269 min read

At 8:17, a team spots unusual connections. By 9 o’clock, it still does not know whether data has left the system, yet the regulatory clock may already be running. Since 1 April 2025, certain critical-infrastructure operators have had to report qualifying cyberattacks to the Federal Office for Cyber Security within 24 hours of detection. Waiting for a perfect diagnosis is one mistake; reporting before the right scope and decision owner are known is another. This article follows the first hours of an incident: what the organisation must assess, who decides, how unknowns should be handled and why communication is also a matter of commercial trust. It then considers how a cyber specialist could turn that pressure into a purchasable crisis exercise and continuing work. A scenario is not presented as an executed campaign, and official incident statistics are not treated as market size. General information based on official sources available on 6 August 2026. It is no substitute for legal advice or incident analysis.

What does Switzerland’s cyberattack reporting duty change?

The Swiss reporting duty adds a regulatory decision to the technical handling of certain incidents. Since 1 April 2025, affected operators have had to connect detection time, scope, observed effects, responsibility and submission to the Federal Office for Cyber Security within 24 hours.

Parliament adopted the amendment to the Information Security Act on 29 September 2023. The Federal Council then set 1 April 2025 for the revised Act and Cybersecurity Ordinance to enter into force. The duty does not cover every company. It applies to public bodies and organisations defined as critical-infrastructure operators, subject to the stated exceptions.

How to read the diagram. The deadline requires a sufficiently grounded decision, not absolute certainty. The first submission may be completed within fourteen days.

Text alternative. The team timestamps the signal, assesses scope and effects, and reports before 24 hours when the threshold is met or uncertainty cannot be resolved in time. Missing information is completed in the final file.

Diagram sources. Federal Office for Cyber Security, Information on the reporting obligation and Frequently asked questions.

The FOCS names energy and drinking-water supply, transport, and cantonal and municipal administrations among the relevant areas. Its 2025 annual report refers to Articles 73 onwards of the Information Security Act, Article 74b for the organisations covered and the Cybersecurity Ordinance for exceptions. Where coverage is uncertain, the organisation may ask the FOCS for a formal decision. A sector label alone is therefore insufficient.

What does Switzerland’s cyberattack reporting duty change?What does Switzerland’s cyberattack reporting duty change?
  1. 1H+0 · Detect and timestamp
  2. 2H+4 · Assess scope and effects
  3. 3Before H+24 · Approve and submit
  4. 4Record reasons and monitor
  5. 5Within 14 days · Complete the file
  6. 6Reporting threshold met?

When does the 24-hour period actually start?

The 24 hours begin when the cyberattack is detected, not when the technical investigation ends. An affected organisation should preserve the time of the first reliable signal, assign assessment immediately and prepare a report even while some information remains unknown.

“Detection” requires the team to distinguish the raw signal, its recognition as a security event and the discovery of facts that may trigger the duty. A workable procedure names who makes that judgement and preserves what was known at each stage. Without a timestamped log, the reasoning is reconstructed after the event and management cannot show the basis of its decision.

Which incidents cross the reporting threshold?

An incident crosses the threshold when it affects an organisation covered by the rules and produces a stated effect: endangering operations, manipulating or leaking information, late detection, blackmail, threat or coercion. An attack that does not affect the critical function does not automatically trigger the duty.

This two-stage assessment—organisation first, event second—prevents every alert becoming a mandatory report. The FOCS gives the example of a denial-of-service attack against a non-critical application. If essential services remain unaffected and there is no apparent propagation risk, interruption of that application alone is not automatically sufficient.

The first-hours file should answer practical questions. Which critical function depends on the affected system? What effect is already observed? Could information have been manipulated or disclosed? Is extortion involved? How long was the event present before discovery? Answers may change, but their source and timestamp must remain visible.

Who decides, and who may assist?

The affected organisation retains the decision even where a service provider analyses the attack or submits the report. Technical teams establish facts, business owners explain operational effects, management assigns the decision, and the partner prepares evidence without becoming the responsible party by default.

The FOCS states that an IT provider or managed-service provider may in some cases report on a client’s behalf, but the delegation must be documented. It does not remove the organisation’s responsibility. A shared mailbox or generic team name is no substitute for a named primary and deputy who can be reached.

Decision questionExpected ownerMinimum evidenceIf the answer is missing
When was the event detected?security or operationstimestamped logrecord the most defensible time and the uncertainty
Is a critical function at risk?business and continuityaffected service, dependencies and effectsescalate to the function owner
Is a legal trigger present?designated leadfacts mapped to official criteriaobtain prompt competent advice
Who approves submission?management or named delegatedecision and deputyactivate the next escalation level
What remains unknown?crisis coordinatorlist of unknowns and ownersschedule the 14-day completion

How should uncertainty be handled before H+24?

Uncertainty should be treated from the first alert as information to assign, not a reason to wait. Classify each point as confirmed, probable or unknown. Give every unknown an owner, next verification step and explicit effect on the reporting decision.

The FOCS says an initial communication must be made within 24 hours even when all information is not yet available. A final report can follow within fourteen days. This supports speed only if hypotheses are not presented as facts.

Three scenarios help. If the critical function is clearly affected, escalation and submission should not wait for the investigation report. If the effect remains uncertain but evidence points in one direction, report what is known and document checks in progress. If there is no demonstrated link between the affected application and the critical function, retain the reasoning, monitor for propagation and reassess when facts change.

The same discipline improves communication with customers, partners and authorities. The organisation can state what is confirmed, what it is already protecting and when the next update will come. That avoids both silence without a deadline and premature reassurance that later needs correction.

What do the reports received by the FOCS in 2025 show?

The official figures show that the system was used: the FOCS had received 164 mandatory reports after six months and 222 by the end of 2025. These counts describe reporting activity. They measure neither every cyberattack nor the number of cyber engagements available to service providers.

The six-month review listed distributed denial-of-service attacks, hacking, ransomware, credential theft, data leaks and malware among the most frequent attacks. The annual report to the end of December placed hacking ahead of denial-of-service and recorded the largest groups of reports in public administration, information and communication, finance and insurance.

These distributions can inform credible exercises. They cannot predict how many prospects will buy one. A defensible commercial audience still requires accessible organisations, a known level of readiness, a budget owner and a partner able to deliver without creating a bottleneck.

Mandatory reports received by the FOCS in 2025Official cumulative totals: 164 after six months and 222 by year-end. This shows use of the system, not market size.
  1. 164164
  2. 222222

How does prepared reporting protect commercial trust?

Prepared reporting protects trust by giving stakeholders a reliable timeline, named responsibilities and a scheduled next update. It does not prove the incident is resolved. It shows that the organisation can make and communicate decisions under pressure without overstating incomplete facts.

A customer, insurer or partner wants more than confirmation that a form was sent. It needs to understand what is affected, what emergency measures are underway, who leads the response and when unknowns will be resolved. The decision log links technical facts with commercial commitments without disclosing sensitive details unnecessarily.

Other duties may run in parallel. The Federal Data Protection and Information Commissioner states that a controller must report a data-security breach as soon as possible where it is likely to create a high risk to personality or fundamental rights. The FOCS notes that, on express request, its form can forward a report to certain other authorities, including the FDPIC or FINMA. This facility does not merge thresholds, deadlines or responsibilities; each duty needs case-specific review.

Trust is not maintained by promising perfect security. It comes from accurate communication: known time, known scope, acknowledged limits, assigned decisions and a stated follow-up.

What can an organisation buy first?

The first purchase can be a bounded crisis exercise that tests the decision chain before a real incident. It should produce a scenario, timed sequence, decision log, gap list and improvement plan. It does not sell guaranteed compliance or unlimited incident response.

This entry offer does not require immediate replacement of security tools. The specialist observes how a signal moves from operations to the business, from assessment to management and from decision to simulated submission. Its value lies in visible gaps: unreachable contacts, ambiguous criteria, incomplete logs, absent deputies or unassigned customer communications.

For getfishnet, the route requires four commercial checks: enough genuinely accessible new accounts, a credible and available partner, pricing that supports expert time, and a payment path without a heavy deployment. Those facts must come from partner evidence; no campaign or revenue is claimed in this article.

How can acquisition identify the right accounts?

Acquisition can identify the right accounts by combining regulatory signals, the organisation’s role, operational criticality and decision maturity. It excludes businesses outside scope, then tests channels without confusing editorial interest, a qualified meeting and cash received.

Research starts with organisations whose activities may fit the official categories, then adds critical dependencies, public notices, security recruitment, customer requirements and people able to sponsor an exercise. Channels may include search, content, sector partners, events, professional networks, email, telephone, voicemail and account-based outreach.

How to read the diagram. Every stage has an exit. An organisation outside scope, with no decision owner or no observable need should not be pushed into a proposal.

How can acquisition identify the right accounts?How can acquisition identify the right accounts?
  1. 1Official signals and target accounts
  2. 2Scope qualification
  3. 3Angle: decide before H+24
  4. 4Conversation with the owner
  5. 5Bounded proposal
  6. 6Nurture, refine or stop
  7. 7Contract, then verify payment
  8. 8Useful and purchasable exercise?
Observed signalAcquisition decisionPossible offerReason to stop
likely coverage, roles untestedopen a conversationH+24 decision exerciseno internal owner
recent incident, incomplete reviewqualify urgency and confidentialitylog review and targeted exerciserequest for free intervention
customer requirementdevelop evidence of readinesstrust file and simulationevidence has no buyer value
outside legal scope but exposeddo not invoke a mandatory dutyvoluntary exercise if the need is realfear is the only trigger

How can the relationship continue without inventing a subscription?

The relationship can continue when new systems, suppliers, scenarios or customer requirements create another decision to test. Continuity is not an automatic subscription. Every recurring intervention needs a trigger, an owner and a defined deliverable.

After the first exercise, a partner may support gap closure, rerun the scenario, integrate a new critical supplier or prepare for a customer requirement. A retainer or incident-response service makes sense only where responsibilities, response times and actual capacity are contractually defined.

Commercial tracking separates four proofs: qualified conversation, accepted proposal, payment received and continuation linked to a new need. Maximum penalties of CHF 100,000 and the 222 official reports cannot replace evidence of value, margin and delivery.

Which readings and sources help take the decision further?

Useful sources separate the FOCS duty, data protection and supplier trust. The FOCS documents scope, deadlines, channels and the 2025 record; the FDPIC explains the treatment of data breaches likely to create a high risk.

Principal sources are the FOCS publications Information on the reporting obligation, Frequently asked questions, Six months of mandatory reporting and 2025 Annual Report; the Information Security Act and Cybersecurity Ordinance in Fedlex; and the FDPIC guide to reporting data-security breaches under Article 24 of the Data Protection Act.

The revised Data Protection Act article explains the threshold related to individuals. The IT and cybersecurity market page brings together the available insights.

What must be concluded before this opportunity is tested?

A 24-hour duty can support a crisis-exercise offer, but it does not prove a profitable market. Action requires a credible partner, accessible accounts, a first purchase that can be invoiced and collected, and sufficient capacity to keep the promise after the sale.

The regulatory signal is documented; commercial value still needs evidence. The eligibility test compares your acquisition challenge, expertise, capacity and economics with the market before a tailored strategy is built. If the conditions are absent, the answer should remain no. Where there is a genuine fit, the next step is a bounded, measurable programme with clear owners.

Does your market present a comparable window?

The eligibility report dates and quantifies it, then tests whether it deserves action.

Test my eligibility
Strategic development · non-exhaustive demonstration

Reading the diagram. A disease contact only progresses after proof of origin, qualification of the relationship and control of the product concerned.

Text alternative. Telephone, prescriber or incoming request follow different proofs; missing consent causes documented exit.

How can the testing cycle reach a stable operating rhythm?

Relative benchmarks: D00 sets the rules of origin and termination of contact, D14 closes the preparation, W03 to W06 tests the scripts, consents, relationships of more than thirty-six months and ceilings per product, W07 to W08 arbitrator, then M03 stabilizes documented paths. Variances are recorded before any budget extension.

Gantt chart for the testing cycle — NON-EXHAUSTIVE DEMONSTRATION

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. The foundation secures the right to contact; exploration then measures the quality of requests before any channel stabilization.

Textual alternative. D00 sets consent, D14 audits scripts, W03–W06 tests provenance, W07–W08 cuts discrepancies, M03 maintains compliance.

What financial potential does the model make visible?

Model: 132 qualified conversations, 44 reviews and 26 new customers. Weighted average: 1 527 CHF; monthly total: 39 700 CHF. The projection concerns acquisitions agreed and allocated, without using the ceilings as margin or portfolio value. No national denominator is applied.

Breakdown of acquisitions — NON-EXHAUSTIVE DEMONSTRATION

The chart counts customers, not percentage points.

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. 26 acquisitions represent subscriptions preceded by a controlled origin and relationship; the size of a share does not prejudge either the documentary quality or the maintained value.

Text alternative. The circle distributes customers obtained after verifiable consent, never people simply called. Total: 26 customers, reread with the value specific to each channel.

How do customers, average monthly revenue, and recurring revenue correlate by channel?

Channel exploredCustomersAverage monthly revenue per customerMonthly Recurring Channel Revenue
Natural and paid referencing41 300 CHF5 200 CHF
Telephone outreach31 600 CHF4 800 CHF
Voicemails2900 CHF1 800 CHF
Email Campaigns41 200 CHF4 800 CHF
Social networks31 400 CHF4 200 CHF
Partners and prescribers32 000 CHF6 000 CHF
Events and webinars21 700 CHF3 400 CHF
Advertising retargeting11 100 CHF1 100 CHF
Strategic accounts and outbound outreach22 300 CHF4 600 CHF
Content and press relations21 900 CHF3 800 CHF
Total / weighted average261 527 CHF39 700 CHF

The value is read again with the product, the applicable ceiling and the cost of controlling the provenance. The product customers × average income totals 39 700 CHF without promising performance.

Monthly recurring revenue by channel — NON-EXHAUSTIVE DEMONSTRATION

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. Compliant disease contacts, their converted volumes and the corresponding monthly income recompose 39 700 CHF without a value outside the table.

Alternative text. Each height associates an authorized channel, actual assigned customers, and the value specific to their product. Their addition exactly equals monthly 39 700 CHF.

How should acquisition cost be assessed before recurring revenue is scaled?

Arbitration adds proof of consent, script control, relationship data, call supervision and refusal handling and reports the charge to assigned customers. It compares legal origin, product concerned, ceiling, full cost, expected termination and service capacity then reduces any channel that weakens the proof.

Funnel to Retained Monthly Recurring Revenue — NON-EXHAUSTIVE DEMONSTRATION

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. disease contacts whose origin is demonstrated produce raw 39 700 CHF, then 34 142 CHF after maintaining at 86 %.

Text alternative. 132 conversations become 44 journals and 26 clients for disease contacts whose provenance is demonstrated. 39 700 CHF weighted to 86 % gives 34 142 CHF.

Financial limit. The 70 francs and the sixteen bonuses limit the remuneration; they give neither margin, nor number of contracts, nor maintenance. The 34 142 CHF remains a hypothesis, without reference value or forecast.

Text references: Federal Office of Public Health, decision and rules applicable to intermediaries; monitoring activity report. The federal office describes ceilings and outreach, while consent and history remain evidence specific to the file. The addresses remain in the internal source register. Each topic retains a clear documentary boundary.

The ISA 2024 processes the status. The ICA 2022 processes the contract trace. The nLPD 2023 shows another prequalification of the contact and data.

CORRELATED READINGS — DYNAMIC MODULE

The thematic map will link rules 2024 of health insurance intermediaries to ISA for status, ICA for contract and nLPD for legality of contact data. The links remain governed without implying equivalence.

The September deadline has passed; each origin of contact must always be able to be explained The report isolates the proof and the next action without reopening the 2024 rules of health insurance intermediaries.

g
getfishnet editorial team

The topic is broken down into entities, attributes, evidence, channels, costs and decision points. Institutions are cited in the text; no external resource interrupts the reading path.

documented

All market readings.

Test your ability to sell a credible H+24 exercise

The 100% free eligibility test checks target, exercise, responsibility, capacity and economics before acquisition begins.

Test my eligibility for free
Test d'éligibilité

Vérifions votre marché.

Dossier reçu.

Nous étudions votre marché et rendons le verdict sous 48 heures.

Fermer

Deux minutes. Verdict sous 48 heures, sans engagement.

Vérifier mon éligibilité