SWITZERLAND Law and Practice Contributed by: David Vasella, Jürg Schneider, Hugh Reeves and Yannick Caballero Cuevas, Walder Wyss Ltd
The initial report may be made informally, for example by e-mail or telephone. The aim is to reflect the then- known facts on the basis of the initial assessment. It may, of course, be the case that further clarifications show that the initial report would not have been man - datory. Institutions can therefore withdraw their initial reports at any time, giving them an incentive to err on the side of caution. If an institution is also subject to the reporting require - ment under the ISA, as revised, the initial report can be submitted through the relevant authority, the NCSC. To the extent known, the NCSC will forward the report to FINMA – if the reporting institution chooses this option – automatically and without filtering, so pre - sumably immediately. The actual report must then FINMA Guidance 05/2020 requires a final root cause report for reports of cyber-attacks with a severity level of “medium” or more, which at a minimum contains the internal or external investigation or forensic report (further requirements can be found in FINMA Guid - ance 05/2020). As FINMA has now clarified, the root cause report should include the following aspects for the “high” and “serious” severity levels: • the reason for the success of the cyber-attack; • the impact of the attack on compliance with regu - latory requirements, the institution’s operations and its clients; and • the mitigating measures introduced to address the effects of the attack. continue to be submitted via the EHP. Expectations for the Actual Report For cyber-attacks categorised as “serious”, evidence and analyses of the crisis organisation’s ability to func - tion must be included in the submission. Calculation of Deadlines FINMA has confirmed its existing practice: where an attack is detected by an outsourcing provider to the institution, the 24-hour window starts when the pro - vider becomes aware of the attack, shortening the time left for the institution, in order to treat institu- tions that have not outsourced any functions equally to others.
When calculating the deadlines for the initial report and follow-up reports, only official banking days count. An exception applies to attacks with the “serious” sever - ity level. In this case, the deadline for the initial report also applies outside of banking days. FINMA must be interpreted here as meaning that this does not apply to the deadline for the follow-up report. It should be noted that FINMA did not formally align its guidance with the EU Digital Operational Resil - ience Act (DORA) or its level II and level III legislation, although they are similar in several regards. 3.4 Operational Resilience Enforcement Concerning operational resilience enforcement, see 1.1 Cybersecurity Regulation Strategy and 1.2 Cybersecurity Laws . 3.5 International Data Transfers The FADP aims to protect the personality rights and fundamental rights of natural persons whose personal data is processed. As a consequence, the FADP con - tains provisions on how this protection is to be guar - anteed when data is transferred abroad, for instance to a state that does not offer the same level of data protection as Switzerland. Controllers or processors may transfer personal data abroad if the Swiss Federal Council has determined that the legislation of the relevant state or internation - al body guarantees an adequate level of protection. Therefore, the Swiss Federal Council determines, in a binding manner, to which countries the export of data is permitted. On the other hand, in the absence of such a deci - sion by the Swiss Federal Council, personal data may be disclosed abroad only if appropriate protection is guaranteed. Thus, at least one of the following condi -
tions must be fulfilled: • an international treaty;
• data protection provisions of a contract between the controller or the processor and its contracting partner, which were communicated beforehand to the FDPIC;
381 CHAMBERS.COM
Powered by FlippingBook