Cybersecurity 2026

SWITZERLAND Trends and Developments Contributed by: David Vasella, Jürg Schneider, Hugh Reeves and Yannick Caballero Cuevas, Walder Wyss Ltd

risk exercises (see 3.3 Key Operational Resilience Obligations in the Swiss Law and Practice chapter in this Guide). Initiatives at a cantonal level The cantons have also recently increased their efforts to prevent cyber threats. For example, Switzerland’s largest canton by population, the Canton of Zurich, operates a Cantonal Cyber Security Centre (CCSC) as a knowledge hub for the canton, acting as a point of contact for cyber-issues for the cantonal adminis - tration, public authorities, critical infrastructure pro - viders, cities, municipalities, cantonal organisations, business and industry, as well as the population. The CCSC is also responsible for implementing the can - tonal cybersecurity strategy. In addition, cantonal data protection legislation – applicable to public entities acting under cantonal laws, which may include private actors carrying out public tasks – requires notification of personal data security breaches to the cantonal data protection authorities. The Artificial Intelligence Regulation (AI Regulation) and AI Act (AIA) Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence and amending Regula - tions (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (the Artificial Intelligence Regula - tion, AI Regulation, AI Act or AIA) came into force on 1 August 2024. Its provisions will take effect in stages until August 2027 (Article 113 of the AI Act). The AI Act is the comprehensive regulatory frame - work by which the EU (for the EEA, the AIA is of rel - evance) regulates the use of AI systems (AIS). Despite its name, the AI Act is not a comprehensive regulation of AI or market behaviour law, but rather a product safety law. It is based on the established principles of product regulation in the European single market, and it adopts a risk‑based approach distinguishing between unacceptable‑risk AI systems, high‑risk AI systems, and limited‑risk AI systems. In addition, it seeks to regulate general‑purpose AI models, which must be distinguished from AI systems.

Other regulatory activity Other authorities have an increased focus on cyber - security as well, within the scope of their supervisory activities. A key example is the Swiss Financial Mar - kets Supervisory Authority (FINMA), which oversees compliance with, inter alia, data security regulations in the financial sector. It publishes an annual risk moni - tor as an overview of risks that FINMA sees as par - ticularly significant. The 2025 version highlights that cyber-risks remain one of the biggest operational risks and observes a trend towards malware attacks target - ing external service providers and a need for financial institutions to improve their responsibilities and control activities with regard to service providers. Outsourcing contributes to cyber-risks and remains a supervisory focus for FINMA, particularly because the concentra - tion of outsourced services among a small number of providers means that an attack on any one of them can disrupt or impair multiple banks and financial institu - tions simultaneously. As of 1 January 2026, supervised institutions in categories 1 to 3 (namely extremely large, important and highly complex institutions with very high risk profiles (category 1), very large and complex insti - tutions with high risk profiles (category 2), and large, complex institutions presenting significant risks (cat - egory 3)) will be required to co-ordinate their opera - tional‑resilience framework with other key components of their activities, in particular ICT and cyber‑risk man - agement, in order to ensure coherent and integrated operational‑resilience arrangements. One of FINMA’s main supervisory tools is issuing guid - ance and circulars, which set out its expectations for regulated institutions. These include FINMA Circu - lar 2023/1 Operational Risks and Resilience, which entered into force on 1 January 2024. It applies to banks and investment firms, requiring them to report certain cyber-attacks within 24 hours of becom - ing aware of them and to submit a full report within 72 hours. Again, this obligation is in addition to any other incident notification obligations. There is ongo - ing discussion in the market in relation to ensuring that the 24-hour requirement is met even where an institution has outsourced IT operations to a provider, such as a cloud services provider. On 7 June 2024, FINMA published FINMA Guidance 03/2024 – findings from FINMA’s cyber risk supervision, clarification of FINMA Guidance 05/2020 and scenario-based cyber-

388 CHAMBERS.COM

Powered by