ICT incident classification and reporting, set up audit-ready
In a real incident, hours count. FINMA expects a cyber-attack notification within about 24 hours of detection, DORA requires an initial, an intermediate and a final report for major ICT incidents, and where personal data is affected the 72-hour clock runs in parallel. SIDD builds the classification matrix, the playbook, the report-ready templates and rehearses them with your team in tabletops. So under pressure your team knows what is reported, when and to whom.
DORA Pillar 2 · FINMA cyber notificationDE · FR · ENindependent, no in-house SOC business
A single cyber incident can trigger several reporting duties at once. Supervisory and data-protection deadlines run in parallel, with different addressees and contents. What applies in concrete terms we verify case by case.
Operational resilience and the handling of ICT incidents have become supervisory duties. FINMA expects supervised institutions to notify a cyber-attack within about 24 hours of detection, in line with established supervisory practice. DORA requires a staged reporting cascade for major ICT incidents, and data-protection law has its own deadlines where personal data is affected. These duties overlap, and that is exactly what makes a real incident error-prone.
For Swiss institutions the FINMA duty applies directly. DORA usually reaches them indirectly, for example via branches or subsidiaries in the EU or via contracts with EU-regulated financial entities that pass their duties down contractually. Whether DORA applies directly or indirectly has to be clarified per institution. Classifying an incident as major decides the reporting duty, and it follows defined criteria such as affected clients and transactions, duration and downtime, geographic spread, data losses and economic impact.
FINMA cyber-attack notification to the supervisor within about 24 hours of detection (supervisory practice, Art. 29 FINMASA)
DORA reporting cascade for major ICT incidents: initial, intermediate and final report to the competent authority
Classification against defined thresholds that make an incident reportable in the first place
Data-protection notification to the competent authority within 72 hours of a personal-data breach (nFADP, GDPR)
Information of affected clients, counterparties and where applicable the public, depending on severity and requirement
Gap-free documentation of detection, classification, decision and report as audit-ready evidence
How we make your reporting fast and audit-ready
We build the process, the classification and the governance, coach your team and rehearse it. We do not run the operational 24/7 detection or managed live response, we coordinate that with specialised partners.
At the centre is a classification matrix that categorises an incident against the relevant criteria and at the same time surfaces the applicable reporting duties. It translates the DORA thresholds, the FINMA supervisory practice and the data-protection triggers into a decision your team can make defensibly under pressure. A decision tree leads from first suspicion through classification to the reporting decision, without anyone having to reread the regulation in a real case.
Alongside this we deliver a reporting playbook with clear roles, escalation paths and timelines, plus report-ready templates for the supervisor, the data-protection authority and client communication. The templates follow the DORA logic of initial, intermediate and final report and the FINMA cyber notification, so in a real case only the facts need to be filled in. Detection itself and the technical response stay with your functions or a specialised partner, we make sure their findings turn into a correct report on time.
So the process does not only work on paper, we rehearse it with your team in tabletop exercises. Using realistic scenarios we play through detection, classification, decision and reporting, expose gaps in roles and deadlines and sharpen the templates. Management and the board end up seeing a rehearsed sequence rather than an untested assumption.
We maintain the classification matrix, the playbook, the templates and the exercise records in the Priverion Platform. The incident register, measures and evidence sit there in one maintained place, so you can demonstrate to FINMA and internal audit at any time that your reporting process exists, has been rehearsed and worked.
Why SIDD for your incident reporting
An incident report is at its core a legal deadline with technical content. We cover exactly that combination from one partner, backed by an in-house technical team.
Legal, security and AI from one partner
The reporting duties from FINMA supervisory practice, DORA and data-protection law are classified by doctorate-level lawyers, the technical content by an in-house security team under an ISO 27001 Lead Auditor. So the deadline, addressee and content of the report fit together.
Built for the deadline
We build the process so the FINMA window of about 24 hours and the DORA reporting cascade hold up under real pressure. Templates, roles and the decision tree are designed so that in a real case no one has to work out anew what goes to whom and when.
Rehearsed, not just documented
A playbook in a folder helps little in a real incident. We play your reporting process through in tabletop exercises, expose gaps and coach your team so it makes the classification and the report confidently under pressure.
Clearly delimited from the SOC
We set up the process, classification and governance and rehearse them. We do not run a 24/7 SOC or managed live response, we coordinate that with specialised partners when needed. That keeps our advice independent and your reporting cleanly separated from the technical response.
Audit-ready evidence in tooling
We maintain the incident register, the classification matrix, the reports and the exercise records in the Priverion Platform. If FINMA or internal audit asks, the evidence that your reporting process exists and worked is ready, maintained and exportable.
Multilingual & independent
We set up the reporting process in German, French and English and, in a real case, communicate in the language of the supervisor and the clients. Because we do not sell an in-house SOC, our recommendations stay independent and focused on your audit-readiness.
Two routes to a report-ready organisation
Incident-reporting playbook & tabletop
Fixed fee
The one-off build of your reporting readiness, from classification through templates to a rehearsed exercise.
Classification matrix for major ICT incidents against DORA, FINMA supervisory practice and data-protection triggers
Reporting playbook with roles, escalation paths, timelines and decision tree
Report-ready templates for the FINMA cyber notification, the DORA initial, intermediate and final report and the 72-hour data-protection notification
Templates for client communication in German, French and English
One tabletop exercise with your team and an incident register in the Priverion Platform
The ongoing operation: a partner who keeps your playbook current, helps drive the reports in a real case and rehearses your team regularly.
Ongoing maintenance of the classification matrix, playbook and templates as requirements change
Legal support of the classification and reporting decision in a real case, in DE, FR or EN
Co-coordination of the supervisory, data-protection and client notifications, aligned with your technical functions or partners
Regular tabletop exercises and coaching for management and the incident team
Maintenance of the incident register and evidence in the Priverion Platform for FINMA and internal audit
LexCMD
Our tool: LexCommand
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your incident reporting, concretely: LexCommand backs every reporting threshold and deadline with the exact source from the DORA incident rules and FINMA reporting practice, and drafts the classification matrix and notification templates, so that in a real case every notification is sourced and on time.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions
Do you run a 24/7 SOC or the live response?
No. We set up the reporting process, the classification and the governance, coach your team and rehearse it in tabletops. We do not run a 24/7 SOC, the continuous detection or the managed live response. We coordinate those operational services with specialised partners when needed, while we make sure their findings turn into a correct and timely report to the supervisor, the data-protection authority and clients. That keeps our advice independent.
How fast must we report?
It depends on the duty. In line with established supervisory practice, FINMA expects a cyber-attack notification within about 24 hours of detection. For major ICT incidents DORA requires a staged report consisting of an initial, an intermediate and a final report within defined deadlines. Where personal data is affected, the 72-hour clock under nFADP or GDPR runs in parallel. Which of these deadlines concretely apply to your institution we verify case by case, precisely because DORA usually only reaches Swiss institutions indirectly.
When does an incident count as reportable at all?
Whether an ICT incident is reportable is decided by the classification. DORA works with defined criteria such as affected clients and transactions, duration and downtime, geographic spread, data losses and economic impact. Our classification matrix translates those thresholds, together with the FINMA supervisory practice and the data-protection triggers, into a defensible decision your team can make confidently under pressure.
Does DORA apply to us as a Swiss institution?
For Swiss institutions DORA usually applies only indirectly, for example via branches or subsidiaries in the EU or via contracts with EU-regulated financial entities that pass their duties down contractually. It applies directly above all to EU-regulated entities. Whether and how DORA concretely reaches your institution and how it interacts with the directly applicable FINMA duty we verify case by case.
Do you take over the reporting for us in a real case?
Under the reporting-readiness mandate we support the classification and the reporting decision legally and help drive the notifications to the supervisor, the data-protection authority and clients. The reporting party remains your institution, because the report is made in the name of the supervised company. The technical detection and response stay with your functions or a specialised partner, and we ensure the timely and correct bridge to the report.
Do you work in French and English?
Yes. We set up the playbook, the templates and the tabletops throughout in German, French and English and, in a real case, communicate in the language of the supervisor and your clients, relevant for institutions in German-speaking Switzerland, French-speaking Switzerland and with an EU nexus.
Matching next steps
Your reporting process only works if ICT risk management and resilience testing stand behind it:
Ready to report on time and audit-ready when it counts?
We build your classification matrix, the reporting playbook and the report-ready templates and rehearse them with your team in a tabletop, aligned with FINMA and DORA.