# FINMA Supervisory Notice 03/2024: Expectations on Cyber Risk Management

> FINMA supervisory notice 03/2024: expectations on cyber risk management, notification duties, lessons from incidents and expectations on executive management.

- Source: https://www.sidd.swiss/en/insights/finma-supervisory-communication-03-2024-in-depth-look-at-cyber-risks/
- Language: en
- Published: 2026-01-28
- Last updated: 2026-05-24
- Author: Philipp Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## What FINMA supervisory notice 03/2024 is

The **FINMA supervisory notice 03/2024 (FINMA AM 03/2024)** is an official communication from FINMA (Swiss Financial Market Supervisory Authority) in which the supervisory authority consolidates findings from ongoing supervision and from notifications of serious cyber incidents. It specifies what FINMA expects of supervised institutions in dealing with cyber risks.

Supervisory notices are not circulars; they do not create new law. They do, however, make transparent how FINMA interprets existing requirements in audit practice. The relevant legal bases remain the **Financial Market Supervision Act (FINMASA)**, including the notification duty for serious incidents under **Art. 29 para. 2 FINMASA**, and **FINMA Circular 2023/01 'Operational Risks and Resilience - Banks'**, in force since 1 January 2024.

The audience comprises banks, insurers, fund management companies, securities firms, market infrastructures and other supervised entities. The notice also has an indirect effect on material ICT third-party providers whose services fall within the scope of outsourcing requirements.

## Core expectations on cyber risk management

The notice sharpens five expectations that recur in audits and supervisory dialogues:

- **Up-to-date and complete inventories** of critical functions, supporting business processes, IT assets, data flows and third parties.
- **Risk-based controls** whose effectiveness is traceably documented and reviewed regularly.
- **Defined Impact Tolerances** for critical functions with derived quantitative thresholds (RTO, RPO, maximum tolerable outage).
- **Robust detection and response capabilities**, including the use of threat intelligence, run-books and a rehearsed crisis organisation.
- **Regular tests** of operational resilience, including realistic scenarios and, where appropriate, threat-led penetration testing.

Responsibility lies explicitly with the board of directors and executive management. Cyber risk management is treated as a leadership task, not as something that can be delegated to IT.

## Notification duties under Art. 29 FINMASA

The supervisory notice recalls the **notification duty for serious cyber incidents** under **Art. 29 para. 2 FINMASA** in conjunction with **FINMA supervisory notice 05/2020**. Notifiable incidents are those liable to impair the fulfilment of material supervisory obligations.

In practice, FINMA expects an **initial notification within 24 hours** of becoming aware of a serious incident and a detailed follow-up notification within 72 hours. The thresholds at which an incident is to be classified as serious arise from the institution's internal classification and should be defined in advance in the crisis-management framework.

In addition, since 1 January 2024 the **notification duty to BACS** (Federal Office for Cyber Security) under Art. 74a et seq. ISG applies to operators of critical infrastructure. Supervised institutions must ensure that the different addressees and deadlines are mapped in the notification concept, without duplicate notifications or gaps.

## Lessons from reported incidents

The supervisory notice points to recurring weaknesses identifiable from notifications of serious incidents:

- **Inadequate hardening of exposed components**, in particular VPN concentrators, remote-access services and externally exposed web applications.
- **Delayed patch cycles** on critical vulnerabilities under active exploit.
- **Privilege escalation** via poorly segmented Active Directory structures.
- **Supply-chain vulnerabilities**, frequently through sub-processors or third-party software components.
- **Insufficiently rehearsed crisis organisations** that, under stress, delay escalated decisions.

These patterns are not new, but appear in some form in nearly every other reported case. FINMA expects institutions to derive their own lessons learned from such patterns and to demonstrate in audits how the identified weaknesses are precluded in their own environment.

## Requirements on detection and response

FINMA emphasises the maturity of **detection and response**. A purely preventive security architecture is no longer considered sufficient. Expected are a continuously operated Security Operations Centre (internal or outsourced), a documented use-case catalogue, regular threat-intelligence input, and run-books for the principal incident classes (ransomware, business email compromise, data exfiltration, DDoS).

In a response scenario, decisions on isolating compromised systems, activating recovery and external communications must be taken within short time windows. The supervisory notice expects that a rehearsed crisis organisation with clear escalation paths, predefined roles and prepared communication templates is in place for this purpose.

Realistic testing is central here. Threat-led penetration testing under **TIBER-EU** and its DORA counterpart TLPT (Threat-Led Penetration Testing) (**Articles 26-27 DORA**) provide an appropriate methodology for systemically relevant institutions.

## Link to FINMA Circular 2023/01 and DORA

The supervisory notice has a close relationship with **FINMA Circular 2023/01 'Operational Risks and Resilience - Banks'**. While the Circular sets the substantive framework, the notice sharpens expectations on operational implementation in the first years of its application.

For institutions with EU exposure, **Regulation (EU) 2022/2554 (DORA)**, applicable since 17 January 2025, applies in parallel. DORA additionally codifies a hard third-party regime including sub-processor chains, an incident-reporting regime with harmonised thresholds, and a TLPT requirement for critical market participants.

Practice is converging: even institutions without EU exposure increasingly align their run-books, resilience tests and third-party governance with DORA concepts, because these are regarded as the contemporary benchmark. A comparison of the requirements is provided in the German-language FINMA/DORA pillar at [/einblicke/finma-dora-leitfaden/](https://www.sidd.swiss/einblicke/finma-dora-leitfaden/).

## Consequences of insufficient implementation

Shortcomings in cyber risk management are addressed by FINMA primarily under supervisory law. The spectrum ranges from **recommendations and conditions** in supervisory letters, through **supervisory measures** such as activity and professional bans, to public **enforcement proceedings**. The concrete response depends on the individual case and on the institution's supervisory category.

Direct administrative fines comparable to those under GDPR do not exist in Swiss financial-market supervision; FINMA's responses are largely discretionary and depend on the case and supervisory category. In practice, however, reputational impact, increased supervisory intensity and, in extreme cases, restrictions on business activity are tangible consequences. Added to this are data-protection sanctions under **Art. 60 et seq. DSG** where data-security duties are breached - fines of up to **CHF 250,000** against responsible natural persons and subsidiary corporate fines of up to **CHF 50,000** under Art. 64(2) DSG.

Civil-law damages claims, contractual penalties under customer or service contracts, and criminal proceedings for the breach of other duties may also apply.

## How SIDD supports you

SIDD supports Swiss financial institutions in translating the expectations of FINMA supervisory notice 03/2024 into measurable structures. We assess the maturity of your detection and response, sharpen your notification concepts, and establish audit-ready evidence for operational resilience.

Our services include building an [ISMS to ISO/IEC 27001:2022](https://www.sidd.swiss/en/services/iso-27001-isms) as the underlying framework, providing a [fractional CISO](https://www.sidd.swiss/en/services/vciso), and delivering [penetration tests](https://www.sidd.swiss/en/services/penetration-test) and [vulnerability scans](https://www.sidd.swiss/en/services/vulnerability-scan). A methodological framing of both approaches is provided in our article on [pentest vs. vulnerability scan](https://www.sidd.swiss/en/insights/pentest-vs-vulnerability-scan/).

Certifications are issued through **CIS Cert** (Quality Austria Group, ISO/IEC 17021-accredited). Get in touch if you are looking for an audit-ready stocktake on the expectations of this supervisory notice.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
