Hospitals & critical infrastructure · cyber reporting and governance

NIS2, Critical Infrastructure & Cyber Reporting for Hospitals, legally led

Hospitals are critical infrastructure, with cyber-reporting duties and a responsibility that reaches into the board. We cleanly distinguish the Swiss ISG/BACS duty from the EU NIS2 directive and close your gaps with a gap analysis, reporting-process playbooks and an ISMS, legally led and independent.

legally led (Dr. iur., CIPP/E) ISG/BACS clearly separated from EU NIS2 independent, no in-house SOC business
Cyber-reporting and governance for hospitals as critical infrastructure

For hospital leadership, boards, executive management, CFOs, CISOs and cantonal operators

Legally led Dr. iur. · CIPP/E
Reporting duty ISG/BACS · Switzerland
EU NIS2 only with an EU footprint
ISO 27001 / ISMS Governance via vCISO
Board-ready briefings & evidence
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

LinkedIn

Hospitals are critical infrastructure, with their own cyber-reporting duty

A cyberattack on a hospital hits not just data but operations and patient safety. That is precisely why the legislator treats healthcare provision as critical infrastructure.

In Switzerland, operators of critical infrastructure are subject to a cyber-reporting duty towards the Federal Office for Cybersecurity (BACS), based on the Information Security Act (ISG). Hospitals and parts of healthcare provision can fall within its scope. Serious cyber incidents must be reported to the BACS within a short deadline.

Whether your organisation is concretely subject to the duty, which thresholds apply and within what deadline you must report, needs to be assessed case by case. The detailed deadlines and exact scope are still partly being specified. We clarify this classification cleanly before we set up any process.

We treat the topic as a governance and compliance question: not as a technology purchase, but as the demonstrable organisation of responsibility, processes and escalation paths around an incident.

Important to distinguish: EU NIS2 or Swiss ISG/BACS?

NIS2 and the Swiss reporting duty are often lumped together. That is risky, because applicability, deadlines and obligations differ. We separate the two regimes cleanly.

NIS2 is an EU directive. Switzerland has not adopted it. NIS2 can therefore only directly bind entities that have an establishment or operations within the EU, for example a Swiss hospital group with sites or subsidiaries in an EU member state. For a hospital operating purely in Switzerland, NIS2 itself imposes no direct obligation.

Hospitals operating purely in Switzerland are instead subject to the Swiss cyber-reporting duty under the ISG, enforced by the BACS. This is a self-standing regime with its own thresholds and deadlines and must not be confused or merged with NIS2.

For organisations with a foot in the EU, both regimes can apply side by side. We build you a clear applicability map: which entity falls under which regime, with which deadline and which reporting channel, so that nobody is looking for the wrong authority during an incident.

The two regimes side by side

Orientation, not legal advice. We verify scope, thresholds and deadlines case by case. Details are still partly being specified.

RegimeWhat it requiresWho it bindsStatus
Switzerland: ISG / BACS reporting dutyReporting serious cyber incidents to the BACS within a short deadline; operators of critical infrastructureSwiss operators of critical infrastructure (assess hospital case by case)in force (verify detailed deadlines)
EU: NIS2 directiveRisk management, reporting duties and management responsibility for essential and important entitiesonly entities with an EU establishment or operations (not for purely Swiss organisations)EU law, not adopted by Switzerland
Revised FADP (data protection)Separate notification of data-security breaches to the FDPIC, its own logic alongside the cyber-reporting dutyall controllers in Switzerland processing personal datain force since 1 Sep 2023

Board responsibility, and how we secure it

In a hospital, cybersecurity is a leadership matter. Responsibility cannot be delegated to IT, but it can be organised and evidenced cleanly.

Board oversight duty

Cyber risks belong to the non-delegable duties of care of top leadership. We make oversight manageable: clear roles, reporting lines and a documented risk picture that the board can genuinely understand and own.

Governance via vCISO

With our vCISO, your organisation gains accountable security leadership that steers strategy, risk acceptance and reporting to executive management, without you having to build a costly full-time role.

ISMS as a robust foundation

An ISMS aligned with ISO 27001 anchors risk management, controls and incident handling in an auditable system. That is exactly the structure that reporting-duty regimes and supervisory bodies want to see.

Swiss professional secrecy

Where a SIDD lawyer advises in a legal capacity, your information may be covered by professional secrecy under Art. 321 of the Swiss Criminal Code, in addition to contractual confidentiality. We clarify the exact scope per mandate, especially for sensitive incident information.

Multilingual & independent

We advise in German, French and English, relevant for French-speaking Switzerland and for organisations with EU parent companies where NIS2 and ISG/BACS must be steered side by side. Because we do not sell an in-house SOC, our recommendations stay independent.

Audit-ready evidence

We maintain the risk picture, controls and reporting processes in a structured way, on request in our Swiss Priverion Platform. In case of a regulator request, the evidence is available as maintained tooling instead of scattered across emails.

What we concretely deliver

Our mandate is readiness and assessment, preparing responsibility, processes and evidence. Explicitly not a managed-SOC or 24/7 monitoring service.

We prepare the organisational interfaces and escalation paths so that your organisation can act quickly and correctly during an incident. The actual operation of monitoring and the technical incident handling we coordinate with your specialised providers. We do not replace them.

  • Applicability and gap analysis: does your organisation fall under ISG/BACS, NIS2 or both, with a prioritised gap list
  • Reporting-process playbooks: who reports what, to which authority, within what deadline and via which channel
  • Prepared interfaces and escalation paths to external IR providers, insurers and authorities
  • Board and executive-management briefings: the risk picture prepared and documented in board-ready form
  • Supplier and third-party risk controls: security and reporting clauses in contracts with critical suppliers
  • Governance build-up: an ISMS framework aligned with ISO 27001 and ongoing security leadership via our vCISO

Entry packages

Reporting-process & playbook package

on request

From the gap to a working process: documented reporting workflows and prepared escalation paths.

  • Reporting-process playbooks per regime and incident type
  • Prepared interfaces to external IR and insurer
  • Roles, responsibilities and communication templates
  • Tabletop-ready workflow documentation for your exercise

vCISO & ISMS governance

on request

Ongoing security leadership: ISMS build-up aligned with ISO 27001 and continuous responsibility via our vCISO.

  • ISMS framework and risk management aligned with ISO 27001
  • vCISO with reporting to executive management and the board
  • Supplier and third-party risk controls
  • Data-protection integration via external data-protection advisory

Related services

These topics interlock in a hospital:

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your applicability map and the reporting-process playbooks, concretely: LexCommand keeps the Swiss ISG/BACS duty and the EU NIS2 directive in separate jurisdictions and sets the obligations side by side with sources, so that every deadline and reporting channel traces back to a retrievable primary source.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

Does NIS2 apply to our Swiss hospital?

NIS2 is an EU directive that Switzerland has not adopted. It directly binds only entities with an establishment or operations in the EU. A hospital operating purely in Switzerland is instead subject to the Swiss cyber-reporting duty under the ISG, enforced by the BACS. Organisations with EU sites or subsidiaries can fall under both regimes. We assess this concretely for your structure.

Within what deadline must we report a cyber incident?

The Swiss cyber-reporting duty requires reporting serious incidents to the BACS within a short deadline. The exact thresholds and detailed deadlines must be assessed case by case, as they are still partly being specified. That is precisely why we prepare your reporting process so that you can act on time and via the right channel.

Do you take over 24/7 monitoring or incident handling?

No. We do not operate an in-house SOC and do not offer ongoing monitoring or technical incident handling. Our mandate is readiness and governance: we prepare responsibility, processes, interfaces and escalation paths and coordinate with your specialised IR providers, insurers and authorities. This keeps our advice independent.

What does the board have to do with this?

Cyber risks belong to the duties of care of top leadership and cannot be delegated to IT. We prepare the risk picture in board-ready form, clarify roles and reporting lines, and give the board a documented basis on which to exercise and own its oversight.

What is the best way to start?

With the fixed-fee critical-infrastructure/NIS2 24h readiness check. It clarifies whether and under which regime you are subject to the reporting duty, checks your reporting capability and delivers a prioritised gap list with a board-ready report. After that you decide on playbooks, ISMS and an ongoing vCISO mandate.

Could you report a cyber incident on time today?

Start with the critical-infrastructure/NIS2 24h readiness check: classification ISG/BACS vs. NIS2, a check of your reporting capability and a prioritised gap list, with a board-ready report.