ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk: Protecting critical services without disruption

Linked InXFacebook

On 13 March 2025, teissTalk host Jonathan Craven was joined by Sofia Martinez Gomez, VP, Risk & Tech Practice - Cybersecurity, Privacy & Compliance, AlixPartners; Monika Atanasova, Global Head of Third Party Risk Management, Raiffeisen Gruppe; and Deryck Mitchelson, Global CISO, Check Point Software Technologies.


Views on news


The Switzerland National Cyber Security Centre (NCSC) has introduced a mandatory reporting requirement for cyberattacks targeting critical infrastructure, effective from April 1. Critical infrastructure operators must report any cyberattacks to the NCSC within 24 hours of detection. The reporting requirement is set out in the Information Security Act (ISA) and the Cybersecurity Ordinance (CSO). Also, these reports will allow the NCSC to support victims of cyberattacks and notify other critical infrastructure operators. Efforts made to improve reporting on cyber-attacks are now, however, a Europe-wide trend. It remains to be seen what the definition of “within 24 hours” will be and how much information can and must be shared. There is also the potential issue of getting a lot of false positives. 

 

Mandated reporting – a source of false confidence?


Compliance must go hand in hand with understanding the business’s current risk posture, as well as vulnerability assessments and red team exercises. The standardisation of regulation globally into a unified framework could free up a lot of resources, particularly those of global companies operating under many jurisdictions. Although businesses have incident response scenarios in place, real life situations may force them to be responsive to challenges that aren’t covered by the playbook. Therefore, it’s important to strike a balance between the level of compliance and flexibility to protect the company effectively. The WEF has also delved into the question of whether compliance and cyber security regulations are effective ways of improving businesses’ cyber resilience. While businesses are ready to invest in cyber security tools, less emphasis is being put on ensuring communication and collaboration between departments. Unregulated sectors without an industry cyber security standard can rely on international frameworks such as NIST or CIS’s security controls with a strong focus on supply chain security. Getting processes and governance right, however, is an important preliminary step before the deployment of security tools. Making continuous improvements and finding synergies with stakeholders are important step too, while, of course, KPIs and KRIs delivered by dashboards are key to monitoring security posture.  


Thanks to the interdependencies that exist between CNI, there are added complexities and they have more complicated OT requirements as well. They are also more exposed to cyber-attacks, particularly those carried out by state actors. Despite additional complexities, some of the attacks against CNI could have been prevented by simple tools such as multifactor authentication or privileged access management. 


The panel’s advice

  • Threat actors don’t care about how compliant you are but what vulnerabilities you have.
  • Don’t get over-reliant on cyber security tools and dashboards.
  • The Board doesn’t want to see dashboards either. They want to understand risk levels, which security professionals must make real for them. 


Find free cyber security training on NCSC’s website.   

Linked InXFacebook
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543