Cybersecurity 2026

SWITZERLAND Law and Practice Contributed by: David Vasella, Jürg Schneider, Hugh Reeves and Yannick Caballero Cuevas, Walder Wyss Ltd

The NCS was last updated in April 2023. The strategy sets out the objectives and measures with which the federal government and the cantons, together with the business community and universities, intend to counter cyber threats. A steering committee has been established to plan and co-ordinate the implementa - tion of the strategy. The revised NCS builds on the previous strategies, adding content and precision. It defines 17 measures, each contributing to five strate - gic objectives, namely: • self-empowerment (Switzerland is to expand its position as one of the world’s leading knowledge, education and innovation locations in cybersecu - rity); • securing digital services and infrastructures (Swit - zerland is to implement measures to strengthen cyber-resilience); • ensuring effective detection, prevention, manage - ment and defence against cyber-incidents (Switzer - land is to ensure the capacities and organisational structures needed to quickly identify cyber threats and incidents, and minimise damage, are in place); • combating and prosecuting cybercrime effectively (Switzerland is to expand its ability to identify and prosecute threat actors); and • maintaining a leading role in international co-oper - ation (Switzerland is to foster an open, free and secure cyberspace and compliance with interna - tional law in the digital space). However, the NCS does not foresee the implementa - tion of a dedicated cybersecurity legislation, instead focusing on modernising various pre-existing laws. The updated NCS is testament to the continued growth in relevance of cybersecurity in Switzerland, as well as perhaps the increased global threat posed by cyber-risks. On 14 May 2025, the Swiss Federal Council took note of the first implementation report on the Nation - al Cyber Strategy, which provides an overview of progress made to strengthen national cybersecurity efforts in Switzerland. Prepared by the NCS Steer - ing Committee in collaboration with the NCSC, the report highlighted tangible advancements, including the establishment of key co-ordination structures, the rollout of ongoing initiatives, the launch of new

projects, and a strengthened international profile for Switzerland in the field of cybersecurity. 1.3 Cybersecurity Regulators The FDPIC is a body established at the federal level under the FADP. The FDPIC supervises compliance with the FADP and other federal data protection leg - islation by federal bodies and advises private bodies. On its own initiative, or at the request of a third party, the FDPIC may carry out investigations into data pro - cessing by private bodies. In addition, each canton has its own data protection authority, which is gener - ally competent to supervise cantonal and communal bodies (but not private parties, which are subject to the FDPIC’s authority). Other regulators – for example, FINMA – may play a role in the enforcement of data protection (see the following). It is also worth mentioning here that the key official actor in the cybersecurity area is the NCSC, the Eng - lish designation of the Bundesamt für Cybersicher - heit (BACS), the federal office integrated within the Federal Department of Defence, Civil Protection and Sport (DDPS). Indeed, in an effort to centralise the administrative activities in this area, other actors such as the Reporting and Analysis Centre for Information Assurance (MELANI), GovCert and the Cybercrime Coordination Unit (CYCO) became an integral part of the NCSC. It therefore serves as the federal govern - ment’s competence centre for cybersecurity and acts as the primary point of contact for business, public authorities, educational institutions, and the public on all cyber-related matters. Tasks include raising public awareness, receiving reports on cyber-incidents and supporting operators of critical infrastructures in man - aging these incidents. Protection of the federal admin - istration against cyber-attacks is now a key task of a new specialist unit within the new State Secretariat for Security Policy (Sepos), also within the DDPS. The FADP does not provide an official role for NGOs and self-regulatory organisations (SROs). Such organ - isations would not, for example, have a right to bring a civil claim against a company perceived to be in breach of privacy laws. However, there are a num - ber of organisations that promote privacy, including several consumer protection organisations, although

378 CHAMBERS.COM

Powered by