Read more … Part-Time Employment: Keep an Eye on Your Social Insurance Coverage
Cyberattack Checklist
A cyberattack can have devastating consequences for any business. A well-prepared incident response plan helps your organisation react quickly and effectively when an attack occurs. This checklist outlines the most important steps to take.
Immediate Actions
- If you suspect a cyberattack, immediately disconnect all affected systems from the internet and any internal networks. Disable Wi-Fi as well.
- Inform your employees about the incident and provide clear instructions on how to proceed.
- Notify the person responsible for IT security—whether internal or external—as well as your emergency response team, if one exists.
- Ideally, keep a printed copy of your emergency contact list so you can act immediately even if your IT systems are unavailable.
Passwords and Access Credentials
- Immediately change all passwords for services that were accessed from the affected devices.
- Use a unique, strong password for every service.
- Wherever possible, enable multi-factor authentication (MFA) to provide an additional layer of security.
Reporting and Notification Obligations
- If you have cyber insurance, notify your insurer without delay.
- Report the incident to the police. This supports criminal investigations and may also assist with insurance claims.
- In Switzerland, cyberattacks are subject to mandatory reporting requirements. Notify the National Cyber Security Centre (NCSC) within 24 hours of becoming aware of the incident.
- If the incident is likely to pose a high risk to the personality rights or fundamental rights of affected individuals, you must also report the personal data breach to the Federal Data Protection and Information Commissioner (FDPIC).
- Inform all affected individuals where required.
Assess and Limit the Damage
- Have IT specialists examine your systems to determine the extent of the damage.
- Identify and eliminate the security vulnerabilities that enabled the attack.
- Restore your data using backups, ensuring first that the backup files themselves have not been compromised.
Communication
- Keep employees regularly informed about the progress of the incident response.
- Where appropriate, notify customers, suppliers, and other stakeholders about the incident and any potential consequences.
Prevention for the Future
- Keep all systems and software up to date by installing security patches and updates regularly.
- Ensure that your record of processing activities, as required by Swiss data protection legislation, is always accurate and up to date.
- Implement a robust backup strategy with regular backups and routine recovery testing.
- Use firewalls, virtual private networks (VPNs), and network segmentation to reduce the risk of attacks spreading across your systems.
- Provide regular cybersecurity awareness training to employees to strengthen security awareness and reduce human error.
Remember: Cybersecurity Is an Ongoing Process
Treat every aspect of IT security as a continuous cycle rather than a one-time project. This applies not only to your internal processes but also to regular external reviews.
It is highly advisable to commission periodic IT security assessments, during which an independent external specialist critically evaluates your infrastructure, applications, and organisational security measures.