InfoGuard AG (Headquarter)
Lindenstrasse 10
6340 Baar
Switzerland
InfoGuard AG
Stauffacherstrasse 141
3014 Bern
Switzerland
InfoGuard Com-Sys GmbH
Frankfurter Straße 233
63263 Neu-Isenburg
Germany
InfoGuard Deutschland GmbH
Landsberger Straße 302
80687 Munich
Germany
InfoGuard Com-Sys GmbH
Am Gierath 20A
40885 Ratingen
Germany
The Information Security Act (ISG) is an important step towards strengthening cyber resilience. The ISG obliges federal authorities, third parties and operators of critical infrastructure to establish an information security management system (ISMS) and to report cyber attacks within 24 hours if they endanger the organization's ability to function and lead to serious consequences.
These regulations affect critical infrastructures such as hospitals, energy suppliers, transportation companies, many other sectors and federal authorities. The introduction of an ISMS in accordance with the international standard ISO/IEC 27001:2022 is recommended as best practice in order to meet the legal requirements and at the same time strengthen the trust of customers and partners.
Sector |
Legal basis |
Core requirements |
Recommended standards |
Rail & Transportation |
CySec-Rail, NIS2 |
ISMS obligation, protection of control systems, emergency plans |
ISO 27001:2022, IEC 62443 |
Healthcare sector |
ISG, cantonal requirements |
Risk management, reporting obligation, protection of patient data, training |
ISO 27001:2022 |
Operational Technology |
NIS2, ISG, IEC 62443 |
OT security measures, integration into ISMS, documentation |
ISO 27001:2022, IEC 62443 |
Critical infrastructures |
NIS2, ISG |
ISMS obligation, audits, supply chain security |
ISO 27001:2022, industry standards |
Banks & insurance companies |
FINMA, ISG |
Risk management, protection of customer data, internal guidelines |
ISO 27001:2022 |
Public administrations |
ISG |
ISMS obligation, reporting obligation, public authority data protection |
ISO 27001:2022 |
The CySec Rail Directive of the Federal Office of Transport (FOT) requires all railroad companies to introduce an ISMS. The directive is based on ISO 27001 and focuses on the protection of control, signaling and communication systems.
For Swiss companies operating in the EU or working with EU partners, the EU's NIS2 Directive also applies. This stipulates that operators of critical transport infrastructures must introduce an ISMS and report cyber incidents within 24 hours.
The core requirements:
The Information Security Act (ISG) stipulates that hospitals, pharmacies and nursing homes must introduce an ISMS. Cyberattacks that jeopardize functionality or lead to data leakage must be reported to the Federal Office for Cyber Security (BACS) within 24 hours.
The core requirements:
The EU's NIS2 Directive and the Swiss ISG require the introduction of an ISMS for operators of critical OT systems, e.g. in energy supply, water treatment, etc. There is a 24-hour reporting obligation for cyber attacks.
The international standard IEC 62443 serves as a reference for the security of industrial control systems and is recognized in Switzerland and the EU.
The core requirements:
The EU's NIS2 Directive and the Swiss ISG require operators of critical infrastructure to introduce an ISMS, carry out regular audits and report cyber incidents within 24 hours. The requirements apply to 18 critical sectors, including energy, water and digital infrastructure.
The core requirements:
FINMA requires clear risk management guidelines for banks and insurance companies. The ISG obliges all federal authorities to introduce an ISMS and to report cyber attacks.
The core requirements:
The requirements from ISG and NIS2 as well as the 24-hour reporting obligation are not only legal obligations, but also the key to a future-proof security strategy. An ISMS in accordance with ISO 27001:2022 is the gold standard and creates transparency, strengthens the trust of customers and partners and reduces supply chain risks in the long term. Those who combine information security (ISMS) and data protection (DSMS) in an integrated management system benefit from greater efficiency, clear processes and measurable compliance.
With InfoGuard as your partner, you gain both: legal certainty and resilience. Contact us, our specialists will support you in the successful implementation of the measures for the legal requirements and will further develop your security architecture together with you.
Image caption: Image generated with AI