Back to the news overview

Cyberattack Checklist

A cyberattack can have devastating consequences for any business. A well-prepared incident response plan helps your organisation react quickly and effectively when an attack occurs. This checklist outlines the most important steps to take.

Immediate Actions

  • If you suspect a cyberattack, immediately disconnect all affected systems from the internet and any internal networks. Disable Wi-Fi as well.
  • Inform your employees about the incident and provide clear instructions on how to proceed.
  • Notify the person responsible for IT security—whether internal or external—as well as your emergency response team, if one exists.
  • Ideally, keep a printed copy of your emergency contact list so you can act immediately even if your IT systems are unavailable.

Passwords and Access Credentials

  • Immediately change all passwords for services that were accessed from the affected devices.
  • Use a unique, strong password for every service.
  • Wherever possible, enable multi-factor authentication (MFA) to provide an additional layer of security.

Reporting and Notification Obligations

  • If you have cyber insurance, notify your insurer without delay.
  • Report the incident to the police. This supports criminal investigations and may also assist with insurance claims.
  • In Switzerland, cyberattacks are subject to mandatory reporting requirements. Notify the National Cyber Security Centre (NCSC) within 24 hours of becoming aware of the incident.
  • If the incident is likely to pose a high risk to the personality rights or fundamental rights of affected individuals, you must also report the personal data breach to the Federal Data Protection and Information Commissioner (FDPIC).
  • Inform all affected individuals where required.

Assess and Limit the Damage

  • Have IT specialists examine your systems to determine the extent of the damage.
  • Identify and eliminate the security vulnerabilities that enabled the attack.
  • Restore your data using backups, ensuring first that the backup files themselves have not been compromised.

Communication

  • Keep employees regularly informed about the progress of the incident response.
  • Where appropriate, notify customers, suppliers, and other stakeholders about the incident and any potential consequences.

Prevention for the Future

  • Keep all systems and software up to date by installing security patches and updates regularly.
  • Ensure that your record of processing activities, as required by Swiss data protection legislation, is always accurate and up to date.
  • Implement a robust backup strategy with regular backups and routine recovery testing.
  • Use firewalls, virtual private networks (VPNs), and network segmentation to reduce the risk of attacks spreading across your systems.
  • Provide regular cybersecurity awareness training to employees to strengthen security awareness and reduce human error.

Remember: Cybersecurity Is an Ongoing Process

Treat every aspect of IT security as a continuous cycle rather than a one-time project. This applies not only to your internal processes but also to regular external reviews.

It is highly advisable to commission periodic IT security assessments, during which an independent external specialist critically evaluates your infrastructure, applications, and organisational security measures.

Source: Treuhand | Suisse

More articles

If you work part-time, it is important to review your social insurance coverage. Lower contributions can lead to gaps in your pension, and employees with very small workloads are ...

by Janine Iten
(comments: 0)

The partially revised Swiss VAT Act (VATA), the revised VAT Ordinance (VATO), and several other important amendments came into force on 1 January 2025.

by Janine Iten
(comments: 0)

Employee participation schemes can significantly increase motivation—but that's not their only benefit. Involving employees in the success and responsibility of the business can ...

by Janine Iten
(comments: 0)
Copyright 2026
Settings saved
Datenschutzeinstellungen

Wir verwenden Cookies auf unseren Websites, um diese laufend für Sie zu verbessern. Mit dem Klick auf «Zustimmen» erklären Sie sich mit der Verwendung von Cookies gemäss unserer Cookie Policy einverstanden.

Technically required cookies are always loaded.

Dies sind Blindinhalte in jeglicher Hinsicht. Bitte ersetzen Sie diese Inhalte durch Ihre eigenen Inhalte. Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo.

user_privacy_settings

Domainname: Domain hier eintragen
Ablauf: 30 Tage
Speicherort: Localstorage
Beschreibung: Speichert die Privacy Level Einstellungen aus dem Cookie Consent Tool "Privacy Manager".

user_privacy_settings_expires

Domainname: Domain hier eintragen
Ablauf: 30 Tage
Speicherort: Localstorage
Beschreibung: Speichert die Speicherdauer der Privacy Level Einstellungen aus dem Cookie Consent Tool "Privacy Manager".

ce_popup_isClosed

Domainname: Domain hier eintragen
Ablauf: 30 Tage
Speicherort: Localstorage
Beschreibung: Speichert, dass das Popup (Inhaltselement - Popup) durch einen Klick des Benutzers geschlossen wurde.

onepage_animate

Domainname: Domain hier eintragen
Ablauf: 30 Tage
Speicherort: Localstorage
Beschreibung: Speichert, dass der Scrollscript für die Onepage Navigation gestartet wurde.

onepage_position

Domainname: Domain hier eintragen
Ablauf: 30 Tage
Speicherort: Localstorage
Beschreibung: Speichert die Offset-Position für die Onepage Navigation.

onepage_active

Domainname: Domain hier eintragen
Ablauf: 30 Tage
Speicherort: Localstorage
Beschreibung: Speichert, dass die aktuelle Seite eine "Onepage" Seite ist.

view_isGrid

Domainname: Domain hier eintragen
Ablauf: 30 Tage
Speicherort: Localstorage
Beschreibung: Speichert die gewählte Listen/Grid Ansicht in der Demo CarDealer / CustomCatalog List.

portfolio_MODULE_ID

Domainname: Domain hier eintragen
Ablauf: 30 Tage
Speicherort: Localstorage
Beschreibung: Speichert den gewählten Filter des Portfoliofilters.

Eclipse.outdated-browser: "confirmed"

Domainname: Domain hier eintragen
Ablauf: 30 Tage
Speicherort: Localstorage
Beschreibung: Speichert den Zustand der Hinweisleiste "Outdated Browser".
You are using an outdated browser. The website may not be displayed correctly.