Cybersecurity 2026

SWITZERLAND Law and Practice Contributed by: David Vasella, Jürg Schneider, Hugh Reeves and Yannick Caballero Cuevas, Walder Wyss Ltd

3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation FINMA, as the financial markets supervisory author - ity, frequently adopts and adapts various circulars and notices. In particular, Circular 2023/01 Opera - tional Risks and Resilience – Banks, is central to all banks’ cybersecurity practices laying out principles and guidelines on proper risk management in relation to client-identifying data (CID). It requires banks and investment firms to report certain cyber-attacks within 24 hours of becoming aware of them and to submit a full report within 72 hours. FINMA Circular 2018/3 on Outsourcing by Banks and Insurers is another essential text as it contains rules on the security of data in an outsourcing context. In the banking and financial markets sector, the regu - lator, FINMA, supervises the relevant actors (namely banks, insurance companies, financial institutions, collective investment schemes and fund manage - ment companies) and plays a role in the cybersecurity realm. Indeed, given the importance of the financial industry in Switzerland, data security and cybersecu - rity are core concerns. FINMA publishes an annual risk monitor as an overview of risks seen as particularly significant, and both the 2023 and the 2025 versions highlight that cyber-risks remain one of the biggest operational risks and note a trend towards malware attacks targeting external service providers. In case of a breach of the sectoral rules, FINMA has a varied toolbox of enforcement measures. These include the revocation of licences to practice, fines or even custodial sentences. FINMA also occasionally, and for preventative purposes, relies on a “naming and shaming” strategy, meaning that the perpetrator of any offence against the regulatory rules is publicly named. 3.2 ICT Service Provider Contractual Requirements As mentioned in 2.1 Scope of Critical Infrastructure Cybersecurity Regulation , the ISA imposes a breach reporting obligation in the event of cyber-attacks

affecting critical infrastructures. Moreover, FONES published a minimum ICT standard document as well as an ICT self-assessment tool directed at operators of critical infrastructures. This document rests, in part, on the requirements of the relatively ubiquitous NIST framework to which it refers. 3.3 Key Operational Resilience Obligations Concerning key operational resilience obligations, see also 1.1 Cybersecurity Regulation Strategy and 1.2 Cybersecurity Laws . On 7 June 2024, FINMA pub - lished supervisory guidance 03/2024 on cyber-risks, which includes: • findings from FINMA’s cyber-risk supervision, including deep dives at banks; • information on scenario-based cyber-exercises in accordance with Circular 2023/1 Operational Risks and Resilience; and • clarifications of FINMA Guidance 05/2020 on the reporting requirement for cyber-attacks. The clarifications relate to the reporting obligation under Article 29 (2) of the Financial Market Supervision Act, which requires supervised institutions to report certain material incidents to FINMA. It builds on ear - lier FINMA guidance, Guidance 03/24 and Guidance 05/2020. FINMA clarifies its expectations as follows. Deadline for Reporting FINMA confirms that the relevant institution has 24 hours from the moment a cyber-attack is discovered to report it to FINMA (see the following for informa - tion about the commencement of this window). Within these initial 24 hours, the institution must carry out an initial assessment of the criticality, with the aim of assessing whether the cyber-attack requires a report to FINMA. The “actual” report must then be made within a total of 72 hours via FINMA’s survey and application platform (EHP). Expectations for the Initial Report FINMA states that timeliness is of the essence for the initial report. There are no specific expectations in terms of form or content, and initial reports can also be withdrawn later.

380 CHAMBERS.COM

Powered by