# Swiss Cyber Security Days 2026, Recap & Conference Guide

> Review of the Swiss Cyber Security Days 2026: key topics, talks and market observations, plus tips for attending next year.

- Source: https://www.sidd.swiss/en/insights/swiss-cyber-security-days-2026/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Philipp Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Since launching in Fribourg, the Swiss Cyber Security Days (SCSD) have grown into Switzerland's largest interdisciplinary cyber-security conference. The 2026 edition was held at the Hallenstadion in Zurich in February and brought together roughly 2,400 attendees, 140 speakers and 95 exhibitors. Three themes dominated the agenda: operationalising the cyber incident reporting duty under Art. 74b ISG (in force since April 2025), the impact of the EU NIS2 Directive on Swiss groups with EU subsidiaries, and the regulatory positioning of generative AI between the EU AI Act, the Federal Financial Market Supervisory Authority (FINMA) and the Federal Act on Data Protection (DSG). This recap distils what CISOs, data-protection officers and board members should take away, and offers a tested preparation playbook for SCSD 2027.

What this article delivers:

- The five most important content threads at SCSD 2026
- Which keynotes and tracks have the longest shelf-life
- How exhibitors and sponsors achieve real presence
- A concrete preparation checklist for the next edition
- Where to find the official recordings and slides

## Headline themes 2026

SCSD 2026 was unmistakably the year of regulatory consolidation. After several editions dominated by technology themes (Zero Trust, XDR, cloud-native), the centre of gravity shifted toward governance, reporting duties and supply-chain resilience. Five threads ran through the programme:

1. **Operationalising Art. 74b ISG**: one year after the reporting duty to the Federal Office for Cyber Security (BACS / NCSC) entered force, speakers shared concrete operating experience – case handling, submission templates and how to reconcile the 24-hour BACS window with the 72-hour Art. 24 DSG breach-notification deadline.
2. **NIS2 and CRA for Swiss firms**: which Swiss groups are de facto in scope, how the NIS2 size thresholds apply to subsidiaries, and what the Cyber Resilience Act (CRA) means for Swiss software and hardware vendors selling into the EU.
3. **DORA year-one lessons**: implementation experience from Swiss financial entities with the Digital Operational Resilience Act, ICT third-party registers and threat-led penetration testing (TLPT).
4. **Generative AI and data protection**: EU AI Act risk tiers, FINMA expectations on model risk, the FDPIC (EDÖB) position on training data and access rights.
5. **OT security and critical infrastructure**: IEC 62443, experience from energy and water utilities, IT/OT convergence.

## Keynotes with shelf-life

From the main programme three keynotes deserve particular attention because they produce material that can be reused directly in CISO board packs:

- **BACS situation report 2025/2026**: the Federal authorities presented consolidated figures from the first reporting year under Art. 74b ISG – roughly 2,100 incidents, dominated by phishing and ransomware staging. The breakdown by sector (healthcare, manufacturing, utilities, public sector) is directly usable as a benchmark for your own risk register.
- **FINMA update on operational resilience**: concretisation of expectations from Circular 2023/1, focused on outsourcing inventory, concentration risk and recovery times for critical functions. Immediately actionable for banks, insurers and asset managers.
- **FDPIC on AI training data**: the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) position on processing personal data in model training, access rights under Art. 25 DSG against LLM providers, and the question of embedding anonymisation. A reference point for every organisation deploying in-house or commercial LLM solutions in production.

Deep-dive tracks worth attending covered Microsoft Entra Conditional Access, forensics for business e-mail compromise with token theft, and Zero Trust architectures per NIST SP 800-207. Slides and recordings are available on the official SCSD portal.

## Exhibitor and market observations

The exhibition floor confirmed several market trends that have been building since 2024. **Consolidation**: several previously independent MDR and SIEM vendors shared booths following acquisitions, and the field of independent Swiss cyber boutiques continues to thin. **Platformisation**: Microsoft, CrowdStrike, Palo Alto and SentinelOne presented integrated platforms combining EDR, SIEM, SOAR and cloud security – tightening pressure on point solutions. **AI marketing**: nearly every second booth advertised "AI-powered" detection; meaningful differentiation only emerges in proofs of concept against real telemetry.

Substantively, the Swiss authority and association booths were the most valuable: BACS/NCSC with its reporting portal, FINMA with explanations of the outsourcing circular, the asut association representing the Swiss ICT industry, and the Cyberhuus support association with awareness material for SMEs. If you are attending as an SME stakeholder, start there rather than at the platform vendors – regulatory clarity often improves your security posture more than another tool demo.

## Networking and political dimension

The SCSD remain one of the few Swiss events where the Federal administration, industry, academic research and vendors all meet on equal footing. The 2026 attendee list included members of the Federal Assembly serving on security policy committees, cantonal governments, representatives of armasuisse and the Swiss Armed Forces Cyber Command, and academic delegations from ETH, EPFL, HSLU, BFH, FHNW, OST and ZHAW with research posters.

Three political discussions stood out: the potential incorporation of core NIS2 elements into Swiss law (no automatic alignment, but real political pressure), the funding base for BACS following its 2024 upgrade, and the question of a Swiss cyber reserve on a militia model. For associations, cantons and critical infrastructure operators, the SCSD is therefore not a pure tech event but a stakeholder-mapping platform. Allocate 25-30% of your time to targeted 1:1 conversations – for many participants the return on those conversations clearly exceeds the talks.

## Preparation playbook for 2027

A productive SCSD visit begins six weeks before the event. The following checklist works in practice:

1. **Define objectives**: three concrete outcomes per attendee (e.g. qualify two vendors, secure one regulator clarification, contact one speaker).
2. **Parse the programme**: parallelise detailed tracks; favour sessions with concrete practical content and reputable speakers over vendor pitches.
3. **Lock meetings in advance**: 60-75% of valuable conversations come from booked slots, not coincidence. Use the official networking tools and pre-event LinkedIn outreach.
4. **Prepare briefing packs**: for 1:1s with potential vendors: current tech stack, telemetry scope, applicable compliance obligations, three concrete use-case questions.
5. **Block follow-up time**: 1.5 working days the next week for slide review, contact qualification, RFP updates. Without that discipline, 70% of the value evaporates.
6. **Internal debrief**: a 60-minute format with CISO, data protection and an executive sponsor – binding extraction of two to three actions.

## Conference guide for first-timers

For first-time attendees in 2027, a few practical pointers save substantial time. The Hallenstadion is 12-15 minutes from Zurich main station by public transport (tram 11 to Messe/Hallenstadion); parking is scarce and expensive. Exhibition access is usually free, talk sessions are paid – early-bird and association tickets reduce the price materially. A multi-day pass pays off if you plan to attend at least four sessions. Day one traditionally focuses on regulation and strategy, day two on technical depth – plan team coverage along that split.

Catering is included during breaks, while evening networking events are typically on the sixth floor and not included in the standard ticket. Bring a laptop or tablet that is not connected to your production environment – public Wi-Fi at cyber conferences warrants heightened caution. Track separately which sessions will publish slides – not every talk is released, and NDA sessions never are. If you visit exhibitors, have business cards or a QR card ready; the resulting e-mail wave is significant, so plan filter rules and a dedicated distribution for your sales/marketing team.

## How SIDD supports you

SIDD has been present at the Swiss Cyber Security Days for years with talks, workshops and consulting meetings. We help Swiss organisations turn the regulatory and technical insights of a conference into actionable programmes – be it an [ISO 27001 ISMS implementation](https://www.sidd.swiss/en/services/iso-27001-isms), an [external CISO mandate](https://www.sidd.swiss/en/services/vciso) or a targeted [penetration test using TIBER-EU / TLPT methodology](https://www.sidd.swiss/en/services/penetration-test). To extend internal awareness capability after SCSD, our [IT security workshops for SMEs](https://www.sidd.swiss/en/services/it-security-workshop-sme) and [data-protection workshops](https://www.sidd.swiss/en/services/data-protection-workshop-sme) are the pragmatic next step. For organisations needing specific clarity on DSG reporting duties, FINMA outsourcing rules or NIS2 effects on Swiss subsidiaries, we are happy to arrange a no-cost initial conversation via our [contact form](https://www.sidd.swiss/en/contact). For structured engagements, request a tailored [quote](https://www.sidd.swiss/en/quote) – we combine regulatory depth, operational experience and a distinctly Swiss-pragmatic advisory approach.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
