Cybersecurity legislation in Switzerland: Legal obligations for company management
By SPIE ICS SA
Firstly, two points should be noted:
1. Under Article 716a(1)(1) of the Swiss Code of Obligations (OR), the board of directors is ultimately responsible for cybersecurity.
2. Switzerland does not have a specific 'cybersecurity law'. The relevant rules and prohibitions are set out in various pieces of legislation.
Cybersecurity is no longer only a matter of technical protection. Swiss companies must now comply with increasingly strict legal requirements, especially when they have more than 200 employees. The digital landscape is evolving rapidly, threats are multiplying and cybercrime now represents global costs estimated at several billion dollars. In this context, leaders can no longer consider system security as a simple technical formality. It is part of their core responsibilities and directly commits the company to the confidentiality, integrity, and availability of data.
Cybersecurity is a legal responsibility that falls to senior management, and here is why.
In environments where organisations are increasingly vulnerable to cyberattacks, awareness must be immediate. Leaders must understand that Swiss regulation is not limited to theoretical obligations. It requires concrete actions to protect personal and professional data, prevent data breaches, and reduce the risk of data theft. Typically Swiss: data protection legislation includes general cybersecurity obligations. A recent study shows that attacks exploiting security flaws in software or mobile applications are rising sharply, affecting large companies as well as public offices.
Legal requirements extend across the entire organisational chain, from internal teams to external partners. Every member of the company becomes a key actor in security.
Cybersecurity for highly exposed organisations
Large companies are particularly exposed to threats. Their organisational scale creates more entry points for cyberattacks and increases the volume of sensitive data that must be protected.
These requirements include several areas:
- Implementation of a formal cybersecurity management system
- Continuous updates to reduce security vulnerabilities
- Documentation of each critical application
- Strict compliance with applicable laws in all relevant states when the company operates internationally
- Maintenance of an internal or external competence centre able to respond quickly to a threat
- Continuous verification of the sender’s identity on every sensitive message
- Dedicated processes for detecting and handling an online incident
Data protection
The Federal Act on Data Protection requires companies to secure personal information using suitable technical measures that are regularly tested.
Minimum standards and sector specific obligations
Critical infrastructure is subject to reporting requirements (ISG/CSV), as well as enhanced cybersecurity obligations more generally. Further obligations may also arise from regulations (e.g. FINMA) or industry standards.
Contracts and responsibilities
Companies often need to prove their compliance in their contractual relations, particularly when working with technology partners or external specialists. Critical infrastructure is subject to reporting requirements (ISG/CSV), as well as enhanced cybersecurity obligations more generally. Further obligations may also arise from regulations (e.g. FINMA) or industry standards.
Essential measures to ensure resilience
To ensure the success of their cybersecurity strategy and remain compliant with Swiss law, companies must adopt a structured approach.
Governance and oversight
Leaders should establish a dedicated committee acting as a competence centre, and clearly define the roles of internal teams and service providers.
Risk management
Each organisation should create a mapping of its assets, identify systems vulnerable to cyberattacks, and establish realistic mitigation plans.
Continuous training
Training remains essential. Employees must recognise a suspicious message, detect a fraudulent link, and understand the central role of daily vigilance.
Technical protection
Technical measures must include network segmentation, access monitoring, strict management of permissions, and systematic updates of environments.
Response plan
The company must prepare realistic scenarios, anticipate examples of possible incidents, and guarantee a rapid reaction in the event of an attack.
Conclusion
Cybersecurity in Switzerland relies on a combination of legal compliance, operational resilience and active involvement from leadership. They must integrate a global, documented and standards aligned approach or risk facing major incidents with heavy financial and reputational consequences. By mastering obligations and structuring robust processes, leaders establish the foundation for lasting security and strategic success.