TL;DR
A Swiss bank hit by a serious cyberattack may owe a report to FINMA and to the NCSC — on different triggers and different timelines. In the middle of an incident, that's exactly when obligations get missed. This blog untangles the two duties so regulated firms can report once, correctly, to everyone who needs to know.
Two regulators, two clocks
Swiss financial institutions live under overlapping cyber-reporting expectations. FINMA requires supervised institutions to report cyberattacks under its supervisory framework, and separately, the NCSC/BACS reporting duty applies to operators of critical infrastructure — which includes much of the financial sector. The triggers, thresholds, and timelines aren't identical, and satisfying one doesn't automatically satisfy the other.
Where firms slip
The failure mode is predictable. During a live incident, teams focus on the regulator they know best and overlook the second obligation, or they report inconsistent details to each because the information is being assembled ad hoc. Under time pressure, fragmented reporting isn't just inefficient — it creates regulatory exposure and undermines the credibility of every notification you send.
One incident record, many notifications
The fix is to treat incident reporting as a single governed process feeding multiple outputs. This is a core strength of the 6clicks Cyber GRC approach: capture the incident once in a structured record, then generate consistent, obligation-specific notifications for FINMA and the NCSC from the same source of truth, with a timestamped trail proving what was reported and when. Built on Sovereign GRC Infrastructure, the whole workflow can run inside Swiss-resident or restricted environments, so sensitive incident data never has to leave the country to be governed. When two regulators are watching the same clock, one clean record beats two frantic ones.
Make sure a single incident never becomes two missed deadlines — book a strategy call with 6clicks.
Frequently asked questions