Skip to content
All Blogs

FINMA or NCSC? Navigating Switzerland's dual cyber-incident reporting duties

Published
FINMA or NCSC? Navigating Switzerland's dual cyber-incident reporting duties
FINMA or NCSC? Navigating Switzerland's dual cyber-incident reporting duties
2:05

 

 


TL;DR

 

A Swiss bank hit by a serious cyberattack may owe a report to FINMA and to the NCSC — on different triggers and different timelines. In the middle of an incident, that's exactly when obligations get missed. This blog untangles the two duties so regulated firms can report once, correctly, to everyone who needs to know. 

Two regulators, two clocks

Swiss financial institutions live under overlapping cyber-reporting expectations. FINMA requires supervised institutions to report cyberattacks under its supervisory framework, and separately, the NCSC/BACS reporting duty applies to operators of critical infrastructure — which includes much of the financial sector. The triggers, thresholds, and timelines aren't identical, and satisfying one doesn't automatically satisfy the other.

Where firms slip

The failure mode is predictable. During a live incident, teams focus on the regulator they know best and overlook the second obligation, or they report inconsistent details to each because the information is being assembled ad hoc. Under time pressure, fragmented reporting isn't just inefficient — it creates regulatory exposure and undermines the credibility of every notification you send.

One incident record, many notifications

The fix is to treat incident reporting as a single governed process feeding multiple outputs. This is a core strength of the 6clicks Cyber GRC approach: capture the incident once in a structured record, then generate consistent, obligation-specific notifications for FINMA and the NCSC from the same source of truth, with a timestamped trail proving what was reported and when. Built on Sovereign GRC Infrastructure, the whole workflow can run inside Swiss-resident or restricted environments, so sensitive incident data never has to leave the country to be governed. When two regulators are watching the same clock, one clean record beats two frantic ones.

 

Make sure a single incident never becomes two missed deadlines — book a strategy call with 6clicks.

Frequently asked questions

If you're a FINMA-supervised institution that also qualifies as a critical-infrastructure operator, both duties can apply to the same incident. Confirm scope for your institution. 

Not necessarily. The NCSC duty centres on a 24-hour window after discovery; FINMA has its own reporting expectations. Treat the shortest applicable clock as your target. 

Maintain one authoritative incident record and generate each regulator's notification from it, rather than assembling separate reports by hand. 

 

 

Ready to transform GRC with 6clicks?

Let’s show you how it works for your team.

awards-mobile-v3