← Back to Insights
Regulation

Reporting duty met, risk unchanged

Reporting duty met, risk unchanged

Since 1 April 2025, Swiss municipalities have been required to report cyberattacks. In most places the response was predictable: work out who reports, to whom, within what deadline. A process appears, a form, an owner.

The duty is met. The risk is not.

A report describes the past

It documents that something happened. It does not change the likelihood of it happening again. Treat compliance as a paper exercise and you end up with a very well documented incident.

The difference is between evidence and an alibi.

Where the real value sits

The duty does have value, just somewhere other than expected. It forces a question nobody had asked before: how would we even know we were being attacked?

The honest answer is usually this: from a person who notices something unusual and says so. Not from a system. Your reporting chain does not start with technology. It starts with someone who takes a suspicion seriously and knows where to take it.

What can actually be measured

All of that can be tested long before it matters:

  • How many of your people recognise a realistic attack?
  • How many report it rather than quietly ignoring it?
  • How quickly?

Know those numbers and you do more than meet the reporting duty. You can show that you exercise diligence continuously, rather than describing it after the fact.