What to do when it happens
The right reflexes for the first hours, who to contact in Switzerland, your legal obligations, and the mistakes that make things worse.
7 articles in this domain
Cyberattack: what to do in the first 24 hours
You've discovered a cyberattack. Isolate without shutting down, who to notify, what to document, when to report: the hour-by-hour steps.
ReadWho to contact after a cyberattack, and in what order
IT provider, NCSC, police, insurer, FDPIC: who to call after a cyberattack in Switzerland, in what order, and what each one can actually do.
ReadPaying the ransom or not: a decision to prepare before the attack
Whether to pay a ransomware demand: what Swiss authorities recommend, what payment really guarantees, and how to make the decision.
ReadYour legal obligations after a cyberattack
Reporting to the FDPIC, informing people, contracts, evidence: what Swiss law really requires after a cyberattack. And why it isn't 72 hours.
ReadCommunicating during a cyberattack: customers, partners, staff
Site down, e-mails unanswered: your customers will notice. What to say, to whom, through which channel, and a short template to prepare before the crisis.
ReadIncident response plan: the document to write before the attack
How to write, in one to two pages, the plan your SME will follow during a cyberattack: full outline, roles, contacts, yearly test.
ReadCyber Insurance: What It Really Covers, and What It Does Not
What a cyber insurance policy covers for a Swiss SME, what stays excluded, and the policyholder obligations that can void the coverage.
Read