Switzerland’s National Cyber Security Centre (NCSC) reported that 2025 was marked by strengthened operational capabilities and expanded cybersecurity reach, anchored by the introduction of a mandatory reporting obligation for cyberattacks on critical infrastructure. According to the annual report, the centre processed nearly 65,000 cyber incident reports, including more than 220 under the new reporting requirement, while its Cyber Security Hub (CSH) grew to around 1,600 members and served as the central platform for incident reporting. 

The NCSC also saw a sharp increase in suspicious website reports and vulnerability submissions from ethical hackers, highlighting the scale of threats and the growing security community engagements. With additional parliamentary funding and deeper cooperation with sector-specific cybersecurity centres, the NCSC said it is now better placed to support preventive measures, raise awareness, and drive implementation of Switzerland’s national cyber strategy.

“A major milestone was the introduction of the mandatory reporting of cyberattacks on critical infrastructures,” Florian Schütz, director of the NCSC, wrote in the NCSC’s Annual Report 2025. “Nine months after it came into force, it is visible that the implementation is working: cyberattacks are reported on time, the designated tools are used, and the cooperation with critical infrastructure operators has been established. Moreover, the proactive communication via industry associations and supplementary explanatory videos was particularly crucial for a smooth introduction. On this basis, Switzerland now possesses stable reporting and support processes in this security-relevant area.”

He added that the approximately 65,000 voluntary reports that the NCSC received in 2025 show that cyber risks are now on people’s radar and that they are actively protecting themselves, staying informed, and reporting incidents. These reports helped the NCSC maintain an up-to-date threat picture and assess risks more accurately, enabling more targeted public awareness, information, and prevention efforts. At the same time, the CSH was expanded with enhanced reporting functions and new exchange formats to strengthen cross-sector collaboration and improve access to specialist expertise.

Schütz said that these achievements were made in a year marked by financial uncertainty. “This makes the parliamentary decision to increase the NCSC’s budget by CHF 10 million in 2026 and by a further CHF 5 million from 2027 onwards even more significant. We see the Parliament’s decision as a strong sign of confidence in our work. It enables us to compensate for the existing underfunding, make necessary investments, and implement new legal tasks – particularly in connection with the reporting obligation – in a sustainable manner.” 

The NCSC structures its work around four strategic pillars. First, it focuses on making cyber threats understandable. The centre breaks down the complexity of cyber threats into tangible messages tailored to its various audiences to facilitate dialogue between government, business, and society. In doing so, it enables its partners to take active responsibility for reducing systemic risks. 

Second, it provides the means to prevent cyber attacks. The NCSC works to reduce the attack surface of Swiss individuals and organisations in cyberspace. It proactively warns organisations of breaches and provides the necessary intelligence and tools to help prevent incidents. 

Third, it aims to limit the damage from cyber incidents. The NCSC supports victims in containing the impact of incidents and in minimising the risk of further propagation. 

Fourth, it seeks to increase the security of digital products and services. The NCSC promotes business models that incentivise manufacturers to offer secure and affordable products and services, and it fosters transparency so users can make informed decisions about their cybersecurity.

The NCSC expanded the national digital platform CSH, adding enhanced reporting for critical infrastructures, new features, and exchange formats that strengthen cross-sector cooperation and provide easier access to specialist information.

In 2025, the technical expansion of the CSH was continued and consistently geared towards the reporting obligation under the Information Security Act (ISA). Since April 2025, a multilingual reporting procedure for cyber incidents has been available in the CSH, including initial and final reporting. This has been integrated into the existing processes of the NCSC. 

In August, the ‘Share with NCSC’ function was also activated. This enables additional information relevant to the assessment of the cyber threat situation or to measures for protecting critical infrastructures to be transmitted to the NCSC via a secure channel. By the end of November, around 40 reports had been received via this channel.

The agency’s core mandate is to strengthen cybersecurity across critical infrastructure, the economy, education, the public, and government authorities by coordinating implementation of the National Cyber Strategy. In 2025, efforts centered on operationalizing the National Cyber Strategy, with governance structures consolidated and expanded to improve coordination among stakeholders. Regular exchange formats were introduced to foster dialogue and cooperation across the ecosystem.

A key outcome of this work is the creation of an NCS implementation forum, set to launch in 2026. The forum will provide a structured platform to review progress under the NCS, generate momentum for new measures, and support its long-term strategic development. An initial workshop held in December 2025 brought together around 60 implementation partners to help shape the forum’s future format. Discussions during the session reinforced the strong demand for such a platform and its importance to effective NCS delivery. The insights gathered are now informing preparations for the regular implementation forums planned from 2026 onward.

At the same time, the continued development of the NCS portfolio management has expanded the implementation portfolio to more than 90 projects supported by over 70 partners, spanning five strategic objectives. An overview of active projects is available on the NCSC website. A clearly defined and transparent process for submitting and assessing new projects has also been developed and published, enabling stakeholders to understand the criteria for inclusion in the portfolio.

In 2025, the NCSC’s final bill amounted to CHF 18.4 million. Of this, CHF 13.0 million was attributable to personnel expenses and CHF 5.4 million to material and operating expenses. Of the material and operating expenses, CHF 3.8 million was spent on IT. CHF 1.2 million of the latter was used for operations and CHF 2.6 million for further developments. The budget for further developments was increased by CHF 2.5 million using earmarked reserves. This provided the NCSC with sufficient funds to expand its existing IT systems in view of the reporting obligation for cyberattacks on critical infrastructures introduced on April 1st, 2025.

Additionally, CHF 1.8 million was spent on further developments at the CSH. A further CHF 0.1 million was spent on the analysis platform for cyber incidents (CyARC). CHF 0.5 million was used to implement bug bounty programs to identify and remedy vulnerabilities in the federal administration’s IT systems. 

The remaining funds in the IT area were used for services for critical infrastructures and for cybersecurity audits in the areas of peripheral devices, photovoltaics, and open source. Of the remaining CHF 1.6 million in material and operating expenses, CHF 0.4 million went to external services, split evenly between developing GEVER business processes and creating an open-source target vision. Expenses for travel and participation in conferences amounted to CHF 0.3 million. The remaining funds were used for rental costs, office supplies, office equipment, and printed materials.

The GEVER standard service is designed to electronically manage business-critical information produced by federal administrative units in the course of fulfilling their statutory duties.

The report also noted that since April 1, last year, there has been a legal obligation to report cyberattacks on critical infrastructures in Switzerland. “Operators of organizations subject to reporting requirements – for example, energy or drinking water suppliers, transport companies, or cantonal and municipal administrations – must now report cyber-attacks to the NCSC within 24 hours of their discovery. 

This new obligation was introduced by a revision of the Information Security Act (ISG) and is enshrined in Articles 73 ff. ISG. The reporting obligation is specified in the new Cybersecurity Ordinance (CSV), which also came into force on April 1st, 2025. The organizations subject to reporting requirements are specified in Article 74b ISG, while exceptions are regulated in Article 16 CSV.

To make the reporting process as simple as possible, the NCSC provides organizations subject to the reporting obligation with the CSH as a central reporting platform, as well as accompanying explanatory videos and information sheets. By the end of 2025, 222 reports had been received. The reports received enable the NCSC to improve its analysis of the cyber threat situation in Switzerland. This allows attack patterns on critical infrastructures to be identified and analyzed at an early stage, enabling potentially affected organizations to be warned in an appropriate timeframe in order for them to take preventive and defensive measures. 

As the reporting form is provided on the CSH, there is an incentive for critical infrastructure operators to register on the platform. The introduction of the reporting obligation helps to promote general exchange of information and achieve an effect that goes beyond fulfilling legal obligations.

In 2025, the NCSC led central cybersecurity management at three major events, including the World Economic Forum (WEF) in January, the Eurovision Song Contest in May, and the UEFA Women’s Euro in July. Key to these operations was early warning and threat analysis, with the NCSC assessing indicators and reports, developing threat scenarios, and issuing timely alerts to critical infrastructure operators to enable preventive measures. At the same time, operational support was provided, ranging from technical recommendations and incident response coordination to direct assistance in dealing with ongoing attacks.

​​The report highlighted that operations were conducted within the cyber situation network, in close collaboration with event organizers, police, and federal authorities. Joint situation conferences, coordinated communication channels, and standardized reporting processes helped shorten response times and ensure secure information flows.

The NCSC reported that the MISP platform (Malware Information Sharing Platform), a central tool for automated exchange of technical cyber incident information, supports proactive protection of Swiss critical infrastructures by enabling timely information sharing between national and international partners. Over the year, technical details on 4,615 cybersecurity incidents were exchanged, sourced from both Switzerland and abroad. The NCSC also integrated 30 additional Swiss critical infrastructure operators into MISP and maintains three separate platforms for other groups, including cantonal and national police forces.

The report highlighted that hardware and software vulnerabilities remain primary entry points for cyberattacks, prompting the NCSC to focus on targeted testing of critical components supporting the administration and economy. In 2025, efforts concentrated on the federal administration’s bug bounty program and a pilot project to enhance the security of open-source software. 

Recognizing the essential role of open-source software in critical infrastructure, the NCSC, together with the National Cybersecurity Testing Institute, tested applications such as TYPO3 and QGIS, identifying and addressing relevant vulnerabilities in collaboration with developer communities. Building on these findings, the NCSC introduced a binding open-source strategy, establishing ‘open source by default’ as a working principle to strengthen interoperability, foster innovation, and provide a secure foundation for federal projects, architectures, and procurements.


Anna Ribeiro


Industrial Cyber News Editor. Anna Ribeiro is a freelance journalist with over 14 years of experience in the areas of security, data storage, virtualization and IoT.