Information Security, Standards, Roles and Duties in Switzerland
Introduction
Information security in Switzerland today plays out on three layers at once: internationally recognised standards (ISO/IEC 27001:2022, NIST CSF 2.0, CIS Controls v8), Swiss sector-specific law (the Information Security Act ISG, FINMA Circular 2023/1 on Operational Risks and Resilience), and downstream EU pressure through the General Data Protection Regulation (GDPR), NIS2 and DORA for groups with EU subsidiaries. Whether you run an SME, a bank, a hospital network or a federal supplier, you need to understand these layers and align them within one consistent management system.
This article maps the standards landscape and clarifies which roles (ISB, CISO, DPO) are responsible for what. What you will take away:
- the key standards: ISO 27001/27002/27005/27701, NIST CSF 2.0, CIS18, BSI baseline protection;
- Swiss overlays: ISG (in force since 1 January 2024), FINMA circulars, BACS/NCSC reporting duty as of 1 January 2025;
- EU obligations that reach into Switzerland: NIS2, DORA, EU AI Act;
- clear role definitions for the Information Security Officer (ISB), the Chief Information Security Officer (CISO) and the Data Protection Officer/Advisor (DSB/DPO);
- a pragmatic recommendation for which standard an SME should start with.
Relevant legal anchors: Art. 8 DSG (data security), Art. 1 ff. ISG, FINMA Circular 2023/1 mn. 27 ff., Art. 21 NIS2 and Art. 5 ff. DORA. This article is not a substitute for legal advice, but it gives you the map you need for an informed standard selection.
The standards landscape at a glance
ISO/IEC 27001:2022 is and remains the international anchor. The standard sets the requirements for an Information Security Management System (ISMS) and references in Annex A 93 controls from ISO/IEC 27002:2022, grouped under four themes: organisational (A.5), people (A.6), physical (A.7) and technological (A.8). ISO 27001 certification is routinely required in tenders by the Swiss Confederation, cantons and large enterprises.
ISO/IEC 27002:2022 provides implementation guidance for each control, ISO/IEC 27005:2022 the methodology for risk management and ISO/IEC 27701:2019 the extension into a Privacy Information Management System (PIMS), the bridge between information security and data protection (DSG/GDPR).
Alongside, the NIST Cybersecurity Framework 2.0 (February 2024) is gaining ground with six functions: Govern, Identify, Protect, Detect, Respond, Recover. The new Govern function makes the CSF maturity-friendly for SMEs. CIS Controls v8 translates the same logic into 18 prioritised technical safeguards with three Implementation Groups (IG1 for SMEs, IG2/IG3 for more mature organisations). Germany's BSI IT-Grundschutz remains relevant for Swiss groups with DACH subsidiaries, but it is documentation-heavy.
Pure cloud providers add ISO/IEC 27017 (cloud controls) and ISO/IEC 27018 (personal data in public clouds); healthcare adds ISO/IEC 27799. Pragmatic path: an SME starts with CIS IG1 or NIST CSF and grows into ISO 27001.
Swiss overlays: ISG, FINMA, BACS/NCSC
The Information Security Act (ISG, SR 128) came into force on 1 January 2024. It primarily binds the federal administration, but it has strong spillover: any supplier delivering critical IT services to the federal government must, under Art. 9 ISG, contractually meet equivalent protection requirements. Concretely: a protection-needs analysis under Art. 6 ISG (confidentiality, integrity, availability, traceability), a risk analysis, protective measures and security-vetting procedures for personnel with access (Art. 22 ff. ISG).
In the financial sector, FINMA Circular 2023/1 «Operational Risks and Resilience, Banks» has tightened ICT and cyber requirements since 1 January 2024. Mn. 27 ff. requires documented ICT risk management, mn. 49 ff. a cyber-resilience programme with Threat-Led Penetration Testing (TLPT) for large institutions. This is complemented by FINMA Supervisory Notice 05/2020 on the duty to report cyber attacks within 24 hours.
Since 1 January 2025, the duty to report cyber attacks on critical infrastructures under Art. 74a ff. ISG applies, with reports going to the Federal Office for Cyber Security (BACS, formerly NCSC) within 24 hours of becoming aware. Scope includes energy providers, hospitals, telecom operators, banks, food retail above a certain size and municipalities with more than 1,000 inhabitants that provide critical services.
EU duties with Swiss reach: NIS2, DORA, AI Act
Swiss companies are not directly bound by the EU NIS2 Directive (EU 2022/2555), but they often are indirectly: anyone supplying essential or important entities in the EU must mirror Art. 21 NIS2 in supplier audits. The ten minimum measures under Art. 21(2) NIS2 range from risk analyses to incident handling, business continuity and supply-chain security, through to multi-factor authentication and cryptography policies.
For financial services with an EU nexus, the DORA Regulation (EU 2022/2554) has been binding since 17 January 2025. It requires ICT risk management (Art. 5–15), incident reporting (Art. 17–23), Digital Operational Resilience Testing including TLPT (Art. 24–27) and strict ICT third-party risk management with contract requirements (Art. 28–30) plus a register of all ICT providers.
The EU AI Act (EU 2024/1689) introduces, since 2 February 2025, prohibitions on unacceptable AI practices (Art. 5) and, in a staggered manner through 2027, obligations for high-risk systems listed in Annex III. A Swiss provider placing an AI system on the EU market falls under Art. 2 AI Act and needs a risk management system under Art. 9, data governance (Art. 10), technical documentation (Art. 11) and post-market monitoring (Art. 72).
ISB, CISO, DPO, who does what
The three roles are often confused in the market, but they are functionally distinct. The Information Security Officer (ISB) is operational: they run the ISMS, maintain the risk register, coordinate awareness work and act as the central point of contact for security-relevant incidents. In federal environments the ISB function is anchored in Art. 83 ff. of the ISV.
The Chief Information Security Officer (CISO) is strategic, usually at C-level or reporting directly to the executive board. They own strategy, budget, reporting to the board and audit committee, and cyber resilience in the sense of FINMA Circular 2023/1 mn. 49 ff. In smaller organisations ISB and CISO merge into one role; in larger ones the CISO oversees multiple ISBs.
The Data Protection Advisor (DSB) under Art. 10 DSG is legal-facing and deals with personal data processing, data subject rights (Art. 25 ff. DSG), data protection impact assessments (Art. 22 DSG) and prior consultation with the Federal Data Protection and Information Commissioner (FDPIC/EDÖB, Art. 23 DSG). For GDPR DPO mandates, Art. 37 ff. GDPR applies. The roles overlap at the interface of TOMs (technical and organisational measures under Art. 8 DSG / Art. 32 GDPR), which is why a clean RACI matrix between ISB/CISO and DSB is mandatory.
SIDD offers all three roles as a service: external CISO/ISB for information security and DSB Switzerland or GDPR DPO for the data-protection side.
Duties in practice: from standard to control
Standards without operationalisation are paper. The core duties most frequently audited in Switzerland can be condensed into six disciplines:
- Asset and data classification under Annex A.5.9 and A.5.12 ISO/IEC 27001:2022, no inventory, no risk analysis.
- Access and authorisation management under A.5.15–A.5.18: need-to-know, segregation of duties, regular recertification, MFA for privileged accounts.
- Supplier and cloud risks under A.5.19–A.5.22 and Art. 9 DSV: onboarding assessment, DPA, sub-processor tracking, exit strategy.
- Vulnerability and patch management under A.8.8, complemented by regular vulnerability scans and targeted penetration tests.
- Incident and crisis management under A.5.24–A.5.27 with a documented playbook and defined reporting paths (BACS 24h, FINMA 24h, EDÖB 72h for personal data breaches under Art. 24 DSG).
- Awareness and training under A.6.3: annual training for all employees, role-based depth for developers, admins and the executive team.
Experience shows that 70% of audit findings do not stem from missing technology but from missing documentation and missing evidence, «implemented but not evidenced».
Common mistakes in Swiss organisations
From more than 200 SIDD audits in recent years, five patterns repeat:
- Statement of Applicability without risk linkage: controls are flagged as «applicable» wholesale, without the selection being derived from the risk register. Auditors look for traceability (risk → control → measure → effectiveness evidence).
- ISB and DPO blurred into one: one person wears both hats and neither is documented cleanly. In a personal data breach, this creates role conflicts between reporting to BACS (security) and the EDÖB (data protection).
- Vendor list without risk rating: the records of processing activities list 80 sub-processors but no critical/non-critical classification and no periodic reviews. For DORA-subject institutions, this leads to supervisory findings.
- Awareness as click-through e-learning: employees click through, yet phishing simulations show a 25% click rate. Effective awareness needs simulation, debriefing and role-specific depth.
- Cryptography policy without key management: encryption is mandated, but key rotation, HSM use and recovery processes are missing. Annex A.8.24 ISO/IEC 27001 requires both.
These mistakes are not expensive to fix if caught early, but each one costs a Major Non-Conformity in the audit report if it first surfaces at the certification audit.
How SIDD supports you
SIDD designs, runs and audits Information Security Management Systems along the standards relevant to your industry: ISO 27001/27701, NIST CSF, FINMA Circular 2023/1, NIS2, DORA. We take on the CISO/ISB function as a service, run protection-needs analyses under ISG and FINMA, and bring your ISMS to certification readiness (ISO 27001 ISMS build).
On the operational side we complement governance work with technical assessments: penetration tests and vulnerability scans as well as IT security workshops for SMEs. On the data-protection side, our DPOs under Art. 10 DSG work hand in glove with the security function so that Art. 8 DSG / Art. 32 GDPR do not become two separate worlds.
Not sure which standard to start with, or does your ISMS have a gap between ambition and reality? Request a non-binding quote or reach out directly via our contact form. In a 30-minute initial call we will frame your situation and propose the right standards mix.
