Cyber Security Switzerland, Consulting, Audits, Awareness

6 min readLast updated By Oliver Stutz

Introduction

Cyber security in Switzerland is no longer an add-on in 2026; it is a mandatory programme. With the duty to report cyber attacks on critical infrastructures in force since 1 January 2025 (Art. 74a ff. ISG), tightened FINMA requirements under Circular 2023/1, and indirect pressure from NIS2 and DORA, Swiss organisations face a dense chain of obligations. A serious cyber security consultancy bundles five building blocks into a coherent programme: assessment, ISMS build, technical assessments (pentest/scan), awareness, and incident response readiness, optionally complemented by managed detection (SOC).

This article describes, in service-page style, how a professional Swiss cyber security consultancy is typically structured. What you will take away:

  • the typical phases of an engagement (assessment → roadmap → implementation → run);
  • which regulatory anchors define the scope (DSG, ISG, FINMA, NIS2, DORA, AI Act);
  • the five core service blocks and how they interlock;
  • typical pitfalls in SME projects;
  • selection criteria for a cyber security partner in Switzerland.

The audience is the executive teams and IT leaders of SMEs, hospitals, municipalities, utilities and financial services that want to build a structured cyber programme or raise the maturity of an existing one.

Phase 1, Cyber Security Assessment

Every serious cyber engagement starts with a baseline. It has three objectives: measure the actual state objectively, derive the regulatory target state from applicable obligations, and document the gap as a prioritised roadmap.

In practice SIDD works with a hybrid of three frameworks:

  • NIST Cybersecurity Framework 2.0 as the maturity language (Tier 1–4) for reporting to executive board and supervisory board;
  • ISO/IEC 27001:2022 Annex A (93 controls) as the depth checklist for operational scoring;
  • CIS Controls v8 with its three Implementation Groups to distinguish quickly between must (IG1), should (IG2) and could (IG3).

The assessment output is a report with three chapters: (1) maturity profile per NIST function (Govern/Identify/Protect/Detect/Respond/Recover), (2) prioritised findings with risk scoring per ISO/IEC 27005, (3) a 12- to 24-month roadmap with quarterly milestones, budget estimates and required resources. For regulated sectors, FINMA Circular 2023/1, ISG or DORA serve as additional target reference frameworks.

Effort for a typical SME: 5–10 consulting days, spread across workshops with executive board, IT leadership, data protection and selected business functions.

Phase 2, ISMS and governance build

The roadmap becomes governance. Building an Information Security Management System (ISMS) per ISO/IEC 27001:2022 typically takes 6–12 months and consists of seven work packages:

  1. Scoping and context under Clause 4: scope of applicability, interested parties, applicable requirements.
  2. Leadership and policy under Clause 5: adoption of the information security policy by the executive board, appointment of the ISB.
  3. Risk management under Clause 6 and ISO/IEC 27005: asset inventory, threat and vulnerability analysis, risk assessment, risk treatment plan.
  4. Statement of Applicability: documented selection of the 93 Annex A controls with a justification per control.
  5. Control implementation across the four themes: organisational (A.5), people (A.6), physical (A.7), technological (A.8).
  6. Internal audit under Clause 9.2 and management review under Clause 9.3.
  7. Certification audit by an accredited body (e.g. SQS, SGS, TÜV) in two stages (document review and on-site audit).

For organisations not seeking certification, the same build can run «conformity-equivalent», structured per ISO 27001 but without external certificate. This fits SMEs that mainly need to pass supplier audits from their large customers.

More on the practice: ISMS build per ISO 27001.

Phase 3, Technical assessments

Governance without technical verification is lip service. Three assessment formats have established themselves:

  • Vulnerability scan: automated scan of network, servers, endpoints and web applications using tools such as Nessus, Qualys or OpenVAS. Quarterly or monthly, with trend reporting to the executive board. Mandatory for FINMA-regulated entities under Circular 2023/1 mn. 49 ff. See vulnerability scan.
  • Penetration test: manual, targeted testing by certified testers (OSCP, OSCE, CREST). Depending on the goal, run as black-box (external), grey-box (with standard user) or white-box (with full knowledge). Methodology typically OWASP Testing Guide v4.2 (web), OWASP MASTG (mobile) or PTES. See penetration test.
  • Threat-Led Penetration Testing (TLPT): per FINMA Circular 2023/1 mn. 49 ff. and DORA Art. 26 for large financial institutions. TLPT simulates real attackers (red teaming) along current threat intelligence and typically runs 3–6 months, coordinated with internal defence.

Reports include, per finding, a CVSS 3.1 score, reproduction steps, impact description and concrete remediation recommendation. After remediation, a retest with status report follows, important for ISMS documentation and for DPA obligations toward large customers.

Phase 4, Awareness and training

85% of all successful cyber attacks exploit human behaviour as the point of entry (phishing, compromised credentials, social engineering). Annex A.6.3 ISO/IEC 27001:2022 requires a documented awareness and training programme. An effective programme has three components:

  • Baseline training for all employees, at least annually, on passwords/MFA, phishing recognition, secure handling of mobile devices, data classification, incident reporting.
  • Role-based depth for developers (secure coding per OWASP ASVS), administrators (hardening per CIS Benchmarks), HR (onboarding/offboarding) and the executive board (crisis management, personal liability under Art. 21(2) NIS2 and FINMA Circular 2023/1).
  • Phishing simulation on a quarterly basis, with a just-in-time learning moment for clickers. The target is a click-through rate below 5% after 12 months of programme.

SIDD offers structured workshops for this: IT security workshops for SMEs and data protection workshops. Importantly, awareness is not a one-off e-learning module but a recurring cycle with measurable metrics (click-through rate, report rate, time-to-report).

Phase 5, Incident response and managed detection

When an incident happens despite prevention, response capability decides the scale of damage. Annex A.5.24–A.5.27 ISO/IEC 27001:2022 requires a documented incident management. Specifically:

  • Incident response plan with defined roles (Incident Manager, Forensics Lead, Communications, Legal), escalation stages and playbooks for typical scenarios (ransomware, data leak, BEC attack, DDoS).
  • Reporting paths: BACS within 24 hours per Art. 74a ff. ISG, FINMA within 24 hours for banks/insurers, EDÖB within 72 hours for personal data breaches per Art. 24 DSG.
  • Tabletop exercises at least annually with executive board, IT, data protection and communications. One exercise per year is NIS2- and DORA-compliant and ISMS-required.
  • Retainer with an incident response provider for forensics and crisis communication, contracts must be in place before the incident, otherwise the first 24 hours are lost.

For continuous detection, mature programmes operate a Security Operations Center (SOC) or a Managed Detection and Response (MDR) service that correlates EDR logs (endpoint detection), cloud logs and identity-provider telemetry. For SMEs, in-house SOC staffing is rarely economical, MDR services with 24/7 coverage are the usual solution.

Typical mistakes in SME projects

From consulting practice, these patterns recur:

  • Tool-first instead of risk-first: a new SIEM/EDR is bought before it is clear which risks it should address, the tool then sits unused.
  • Awareness as a one-off workshop: without a recurring cycle, the learning effect fades within 3–6 months.
  • ISMS documentation without life: policies are written but not trained and not lived, audits then find «documented but not implemented».
  • Supplier audits ignored: the records of processing activities list 60 sub-processors, but no one verifies their security, a major finding in any ISO audit.
  • Penetration test without retest: findings are remediated but the effectiveness of the measures is never verified.
  • Crisis plans without exercises: the plan lives on a shared drive that is encrypted in a ransomware case.

Avoidance: an external consultancy should provide a clear quantity structure at the start (who does what by when with what effort) and adjust the roadmap each quarter.

How SIDD supports you

SIDD is a Swiss consultancy at the intersection of cyber security and data protection. We support SMEs, hospitals, municipalities, utilities and financial services through all five phases: assessment, ISMS build, technical assessments, awareness and incident response readiness. We provide the CISO/ISB function as a service, build your ISO 27001 ISMS, run penetration tests and vulnerability scans, and train your employees in IT security workshops.

On the data protection side we offer DSB Switzerland and GDPR DPO mandates, so that Art. 8 DSG and Art. 32 GDPR are implemented consistently with the cyber security strategy.

Want to know where your organisation stands today and which roadmap is realistic? Request a non-binding quote for a cyber security assessment or reach out via our contact form. A 30-minute initial call is enough to clarify whether we are the right partner.

Need help putting this into practice? SIDD operates the matching service.
See service →

Cyber Security Switzerland, Consulting, Audits, Awareness

INSIGHT

InfoSec
24 May 2026
Oliver Stutz
How cyber security consulting is structured in Switzerland: assessment, ISMS, penetration tests, awareness and incident response in five phases.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.