On 13 March 2025, teissTalk host Jonathan Craven was joined by Sofia Martinez Gomez, VP, Risk & Tech Practice - Cybersecurity, Privacy & Compliance, AlixPartners; Monika Atanasova, Global Head of Third Party Risk Management, Raiffeisen Gruppe; and Deryck Mitchelson, Global CISO, Check Point Software Technologies.
The Switzerland National Cyber Security Centre (NCSC) has introduced a mandatory reporting requirement for cyberattacks targeting critical infrastructure, effective from April 1. Critical infrastructure operators must report any cyberattacks to the NCSC within 24 hours of detection. The reporting requirement is set out in the Information Security Act (ISA) and the Cybersecurity Ordinance (CSO). Also, these reports will allow the NCSC to support victims of cyberattacks and notify other critical infrastructure operators. Efforts made to improve reporting on cyber-attacks are now, however, a Europe-wide trend. It remains to be seen what the definition of “within 24 hours” will be and how much information can and must be shared. There is also the potential issue of getting a lot of false positives.
Compliance must go hand in hand with understanding the business’s current risk posture, as well as vulnerability assessments and red team exercises. The standardisation of regulation globally into a unified framework could free up a lot of resources, particularly those of global companies operating under many jurisdictions. Although businesses have incident response scenarios in place, real life situations may force them to be responsive to challenges that aren’t covered by the playbook. Therefore, it’s important to strike a balance between the level of compliance and flexibility to protect the company effectively. The WEF has also delved into the question of whether compliance and cyber security regulations are effective ways of improving businesses’ cyber resilience. While businesses are ready to invest in cyber security tools, less emphasis is being put on ensuring communication and collaboration between departments. Unregulated sectors without an industry cyber security standard can rely on international frameworks such as NIST or CIS’s security controls with a strong focus on supply chain security. Getting processes and governance right, however, is an important preliminary step before the deployment of security tools. Making continuous improvements and finding synergies with stakeholders are important step too, while, of course, KPIs and KRIs delivered by dashboards are key to monitoring security posture.
Thanks to the interdependencies that exist between CNI, there are added complexities and they have more complicated OT requirements as well. They are also more exposed to cyber-attacks, particularly those carried out by state actors. Despite additional complexities, some of the attacks against CNI could have been prevented by simple tools such as multifactor authentication or privileged access management.
Find free cyber security training on NCSC’s website.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543