InfoGuard AG (Headquarter)
Lindenstrasse 10
6340 Baar
Switzerland
InfoGuard AG
Stauffacherstrasse 141
3014 Bern
Switzerland
InfoGuard Deutschland GmbH
Frankfurter Straße 233
63263 Neu-Isenburg
Germany
InfoGuard Deutschland GmbH
Landsberger Straße 302
80687 Munich
Germany
InfoGuard Deutschland GmbH
Am Gierath 20A
40885 Ratingen
Germany
InfoGuard GmbH
Kohlmarkt 8-10
1010 Vienna
Austria
Cyberattacks on critical infrastructure are steadily increasing. At the same time, regulatory requirements are becoming more stringent for companies that are essential to the supply of goods and services to the public and the economy. In Switzerland, the ISG serves as the foundation for protecting these facilities. It requires operators of critical infrastructure to report significant cyber incidents. While appropriate protective measures and regular risk assessments are not subject to a separate ISG compliance requirement, they are considered a fundamental prerequisite for fulfilling this reporting obligation and for enhancing an organization’s own cyber resilience.
While the Information Security Act (ISG) provides the regulatory framework in Switzerland, Germany is governed, among other things, by the provisions of the BSI Act as well as the requirements of the KRITIS regulation and the NIS2 implementation. In Austria, the Network and Information System Security Act (NISG 2026), adopted in December 2025, implements the same EU requirement; it will take effect approximately nine months after its promulgation (expected in the fall of 2026). Despite differing legal frameworks, all three countries in the DACH region share the same goal: operators of critical infrastructure must protect their OT and IT systems against cyberattacks and continuously enhance their resilience.
However, legal requirements alone do not create resilience. What matters most is how technical, organizational, and procedural measures are implemented in a way that ensures both security and availability.
Especially in OT environments, implementing regulatory requirements poses particular challenges for companies: Production and control systems must be protected against cyberattacks without compromising the availability of critical processes. Security and operational continuity must be equally ensured.
The Swiss Information Security Act (ISG) defines a key obligation for operators of critical infrastructure in this regard: the reporting of relevant cyber incidents. To fulfill this obligation, companies also need appropriate protective measures.
Mandatory reporting of cyber incidents (ISG Art. 74a–h)
Operators must report cyber incidents with significant consequences (such as a threat to operational functionality, data breaches, extortion, or attacks that remained undetected for an extended period; Art. 74d ISG) to the Federal Office for Cybersecurity (BACS) . The reporting deadline is 24 hours after the cyberattack is discovered.
Appropriate Protective Measures
Unlike, for example, the German BSI Act, the ISG does not impose a separate, recurring obligation to provide evidence or obtain certification in this regard. Companies must implement technical, organizational, and physical measures to ensure the availability, integrity, and confidentiality of their systems.
These include, among other things:
The current threat landscape also underscores the importance of these requirements .
Since the reporting requirement took effect on April 1, 2025, BACS has received approximately 260 reports from operators of critical infrastructure through spring 2026. The majority of these reports came from the public sector as well as the IT/telecom, financial, and energy sectors.
A similar picture emerges across the entire DACH region:
While the number of incidents reported to BACS is rising in Switzerland, the German BSI and the Austrian cybersecurity authorities also report a persistently high or increasing threat from cyberattacks on companies, public institutions, and critical infrastructure.
Before security measures can be implemented, companies must first understand which systems, processes, and facilities are particularly worthy of protection. The first step, therefore, is a structured analysis of their own vulnerability and a comprehensive inventory of existing assets.
This involves first determining whether and to what extent a company qualifies as an operator of critical infrastructure (KRITIS). In Switzerland, this assessment is based on the criteria defined in the Information Security Act (ISG, Art. 74c, in conjunction with the Cybersecurity Ordinance, CSV), which take into account, among other factors, the industry , the importance of the service to public supply, and the impact of a potential outage.
In Germany, too, the identification of critical processes and systems forms a central basis for the implementation of KRITIS and NIS2 requirements. Regardless of the regulatory framework, the following applies: Only those who understand their IT—and, in particular, their OT—environments can assess risks and prioritize appropriate protective measures.
A key component of this assessment is structured asset mapping. This involves identifying all relevant systems and interfaces—from traditional IT components to industrial control and production environments.
These include, for example:
Network infrastructure: VLANs, firewalls, routers, and communication paths between IT and OT networks
Control and production systems: PLCs (programmable logic controllers), SCADA systems, and RTUs
External interfaces: Remote maintenance access points, cloud connections, and connections to suppliers or service providers
A complete and up-to-date overview of these assets forms the foundation for all further steps, from risk assessment and the prioritization of measures to increasing cyber resilience.
Where do you stand in the digitalization of your business processes? With our OT Security Services, you can identify potential vulnerabilities in control and process technology early on and implement effective protective measures.

Once the relevant assets have been identified, the next step is to assess the associated risks. A structured risk catalog helps companies systematically identify and evaluate threats and derive appropriate protective measures. In this process, risks are considered particularly with regard to confidentiality, integrity, and availability.
The key is not to address every potential vulnerability at once, but to prioritize measures based on their criticality. Factors evaluated include the likelihood of a scenario occurring as well as its potential impact on operations—for example, unsecured remote access or the failure of a central control system in an OT environment.
Targeted measures can be planned on this basis. Particularly for critical OT systems, priority should be given to measures that sustainably increase availability and operational reliability, such as appropriate network segmentation in accordance with ISA/IEC 62443, redundant control systems, and robust backup and recovery strategies.
The ISG calls for appropriate technical protective measures tailored to the individual protection needs of the systems. These include, among other things, access controls, encryption, logging, and emergency response plans. It is crucial that these measures are not only implemented but also documented in a traceable manner and reviewed regularly.
A balanced approach is particularly crucial in OT environments: production and control systems must remain reliably available, while at the same time being protected against modern cyber threats. These requirements can be implemented in a structured manner using established security standards such as ISO/IEC 27001 or ISA/IEC 62443.
By dividing the system into separate security zones, critical systems can be better protected and communication paths controlled. Typical areas include, for example, production zones with control systems, maintenance zones for updates and remote access, and external zones for suppliers or cloud services. Technically, this separation is implemented using firewalls, VLANs, or—for particularly stringent requirements—unidirectional connections (data diodes).
Remote access also poses a common risk in OT environments. Therefore, remote services should be conducted via controlled access points such as jump hosts, with time-limited permissions, logging, and multi-factor authentication (MFA).
In addition, continuous monitoring provides transparency into security-related activities. This includes, for example, the integration of OT-specific events into security monitoring solutions, separate logging structures for forensics, and the monitoring of critical industrial protocols such as Modbus or DNP3.
Technical protective measures alone are not sufficient to secure critical infrastructure in the long term. Clear responsibilities, defined processes, and regular reviews are crucial to ensuring that security measures remain effective over time.
This includes, in particular, structured change management: Changes to OT systems must be documented in a traceable manner, reviewed, and approved. Appropriate processes and ticketing systems create transparency and ensure that, even in complex production environments, it remains clear at all times which adjustments have been made.
Regular audits and practical exercises, such as tabletop exercises, help identify security vulnerabilities early on and improve the ability to respond in an emergency. In addition, targeted training and awareness-raising measures strengthen employees’ security awareness—especially in areas where administrative or technical access rights are granted.
Regardless of whether your company is subject to the requirements of the Swiss Information Security Act (ISG) or the German KRITIS and NIS2 regulations: Securing critical infrastructure is not a one-time project, but an ongoing process. Regularly assessing risks in IT and OT environments, implementing targeted technical safeguards, and continuously refining security processes creates greater resilience and supply security in the long term.
In OT environments in particular, the interplay of technology, organization, and people is crucial. A structured approach helps companies protect critical systems, identify security vulnerabilities early on, and reduce the impact of potential cyberattacks.
When developing a customized security strategy, we help companies assess their current situation, prioritize risks, and identify appropriate measures for their IT and OT environments—from the initial impact analysis and asset mapping to the development of a targeted resilience roadmap. We look forward to hearing from you!
Caption: AI-generated image