Since 1 April 2025, Swiss municipalities have been required to report cyberattacks. In most places the response was predictable: work out who reports, to whom, within what deadline. A process appears, a form, an owner.
The duty is met. The risk is not.
A report describes the past
It documents that something happened. It does not change the likelihood of it happening again. Treat compliance as a paper exercise and you end up with a very well documented incident.
The difference is between evidence and an alibi.
Where the real value sits
The duty does have value, just somewhere other than expected. It forces a question nobody had asked before: how would we even know we were being attacked?
The honest answer is usually this: from a person who notices something unusual and says so. Not from a system. Your reporting chain does not start with technology. It starts with someone who takes a suspicion seriously and knows where to take it.
What can actually be measured
All of that can be tested long before it matters:
- How many of your people recognise a realistic attack?
- How many report it rather than quietly ignoring it?
- How quickly?
Know those numbers and you do more than meet the reporting duty. You can show that you exercise diligence continuously, rather than describing it after the fact.