A roadmap to contain the attack, preserve evidence, maintain operations, and meet Swiss notification requirements without improvisation.
A screen displays a ransom request, shared files are unresponsive, or a supplier reports an email sent from your account. In the first few minutes, no one knows yet if the incident affects an isolated workstation, the entire company, or data already copied by the attacker. This is precisely why it is necessary to act methodically.
The first 24 hours have four objectives: limit the spread, preserve useful elements for the investigation, maintain vital functions, and quickly decide which people or authorities need to be informed. Restoration comes next. Bringing a server online before understanding the entry point can turn a quick recovery into a second attack, with a free bonus of stress.
The roadmap below is aimed at Swiss small businesses. It does not replace the intervention of an incident response specialist: depending on the type of attack, shutting down a machine can stop ongoing encryption, but it can also erase traces present in memory. The technical decision must therefore be made quickly, by a competent person.
In short
- Isolate the affected equipment and connected backups, without deleting or reinstalling anything.
- Immediately alert the IT provider and the cyber insurer, then appoint a crisis manager.
- Keep a timestamped log of symptoms, decisions, contacted individuals, and actions taken.
- Evaluate the technical incident, personal data breach, and contractual obligations separately.
- Swiss DPA does not provide a general 72-hour deadline: a notification to the FDPIC must occur as soon as possible if the risk is likely high.
- As of April 1, 2025, certain critical infrastructures must report the relevant cyberattacks to the FIS within 24 hours of detection.
Before the timer: confirm the facts without waiting for certainty
An unavailable server is not necessarily a victim of a cyberattack: a failure, a configuration error, or accidental deletion can produce similar symptoms. Conversely, the absence of a ransom demand proves nothing. Email compromise, payment fraud, or discreet exfiltration can remain invisible for several days.
The right reflex is to take the signs seriously, without prematurely announcing a cause or extent. Note the exact time of discovery, photograph the displayed messages, record the affected accounts and devices, and ask employees not to use the suspicious systems. Do not forward the ransom demand to the entire team from the possibly compromised messaging.
The roadmap for the first 24 hours
| Period | Priority | Expected result |
|---|---|---|
| 0 to 30 min | Isolate, alert, log | Propagation contained, crisis team activated, first timestamped trace |
| 30 min to 2 h | Protect access and vital activity | Engaged providers, secured sensitive payments, defined degraded mode |
| 2 to 6 h | Assess the incident and the data | Provisional scope, preserved evidence, notification obligations assessed |
| 6 to 12 h | Decide and communicate | Factual messages, notifications initiated, validated recovery priorities |
| 12 to 24 h | Restore under control | Clean environment, gradual recovery, enhanced monitoring |
0 to 30 minutes: isolate, alert, and open the crisis log
Disconnect the clearly affected workstations from the network: Ethernet cable, Wi-Fi, VPN access, or other link. If backups are accessible from the network, isolate them immediately. Cutting global Internet access may be necessary when the attacker is still communicating with the environment, but this measure must be coordinated to avoid cutting useful channels or a security service without reason.
Do not automatically turn off all machines. Useful volatile elements may disappear. If encryption is visibly in progress, the specialist may decide on a precautionary shutdown. The practical rule is therefore: isolate first, then follow the instruction of the technical responder.
Contact the IT provider or the incident response team from a device and a channel deemed safe. Inform the cyber insurer at the emergency number specified in the contract: some coverages require the use of licensed responders or prior validation of expenses. Designate a decision-maker, a person who coordinates the technical aspects, and a person who keeps the log. In a small SME, three roles can fit into two heads; they must still be assigned.
30 minutes to 2 hours: secure access and maintain the essentials
From a clean device, revoke compromised sessions and prioritize the handling of admin accounts, email, remote access, and application keys. Do not initiate a general password change from suspicious workstations: you could immediately hand over the new secrets to the attacker.
In case of email compromise or CEO fraud, call the bank immediately to block suspicious payments and review pending orders. Notify employees, through an alternative channel, that no changes to IBAN, urgent requests, or payment procedures should be executed without verbal verification.
Rank functions in order of survival: collections, e-banking, salaries, invoicing, access to client files, orders, telephony, and imminent legal obligations. Activate a manual or isolated operation for the few essential processes. An offline table indicating the responsible person, the deadline, and the temporary solution is better than a disorganized recovery of all software.
2 to 6 hours: qualify the incident and preserve evidence
The technical team must establish a provisional scope: affected systems, likely first access, accounts used, relevant period, potential persistence, encrypted, modified or copied data, backup status, and signs of propagation. Keep logs from firewalls, servers, directories, messaging systems, and cloud applications, the ransom demand, some encrypted files, and, if recommended by the specialist, images of the affected media.
Do not reinstall before preserving useful elements and, if a complaint is considered, before coordinating this issue with the police. The NCSC accepts cyber reports but does not receive criminal complaints: these must be filed with the competent police.
In parallel, examine the breach of personal data. The FADP aims not only at disclosure but also at loss, destruction, deletion, or unauthorized modification. Ransomware that makes files unavailable may therefore constitute a breach even if exfiltration has not yet been proven. For preventive governance of data and digital tools, see also our article on generative AI and data protection in Swiss SMEs.
Who needs to be informed, and within what timeframe?
| Recipient | Trigger | Swiss deadline | Point of attention |
|---|---|---|---|
| FDPIC | Data breach likely resulting in a high risk to personality or fundamental rights | As soon as possible | An initial announcement can be supplemented; uncertainty does not always justify waiting. |
| Affected individuals | Information necessary for their protection, or order from the FDPIC | Early enough to allow for useful action | Examples: changing a password, blocking a card, monitoring phishing attempts. |
| Client responsible for processing | The SME acts as a subcontractor and identifies a breach concerning the client's data | As soon as possible, for any breach | The subcontractor does not apply the high-risk threshold before alerting the responsible party. |
| NCSC — mandatory notification | Subject organization operating critical infrastructure and cyberattack meeting legal criteria | 24 hours from detection; follow-up within 14 days if necessary | The obligation is not general for all SMEs. |
| NCSC — voluntary notification | Cyberincident worth reporting, even outside of obligation | Without general legal delay | The portal provides an initial automated assessment and forwards the case to the NCSC. |
| Insurer, bank, partners | Contract, payment fraud, dependency, or shared data | Immediately or according to the contract | Check coverage conditions and notification clauses, without waiting for the final report. |
The FDPIC indicates that when the quick analysis reveals a likely high risk or does not allow for its exclusion with sufficient certainty, the responsible party should not wait for lengthy investigations. A preliminary announcement can be made and then supplemented. The assessment particularly focuses on the sensitivity of the data, the ease of identifying individuals, the possible consequences — fraud, identity theft, damage to reputation — vulnerable individuals, the volume, and the duration of exposure.
Document the facts, effects, and measures taken. Article 15 OPDo provides for the retention of documentation related to the breach for at least two years from the announcement. Even when no announcement to the FDPIC is ultimately required, keeping a dated and defensible analysis allows for explaining the decision and improving the system.
6 to 12 hours: decide, announce, and communicate without speculating
Gather management, technical staff, data protection, the insurer, and, depending on the stakes, legal counsel. Validate four decisions: which notifications to launch, which services to maintain, what message to disseminate, and what conditions must be met before resuming.
Good communication distinguishes confirmed facts from ongoing investigations. It indicates the affected services, the measures taken, what the recipient should do, and the date of the next update. Avoid statements like "no data was stolen" as long as logs and other indicators do not allow for establishing that. The opposing argument will easily arise: the company could not exclude it and yet reassured its clients categorically.
Paying a ransom offers no guarantee of recovery or non-disclosure. It funds criminal activity and may attract a new attempt. The operational recommendation is not to pay. If the issue arises nonetheless, it should never be decided solely under the pressure of the attacker: insurers, technical specialists, police, and legal counsel must be involved. A payment does not eliminate any notification obligation.
12 to 24 hours: restore gradually, not heroically
Before any restoration, check the healthy date of backups, the absence of compromise in them, and the handling of the entry point. Affected systems generally need to be rebuilt or properly reinstalled, patched, and then reconnected in stages. Accounts, secrets, application keys, and remote access that may have been compromised should be renewed from a trusted environment, with multi-factor authentication and enhanced monitoring.
Start with the processes whose halt causes the greatest damage: security, reliable communication, cash collections, orders, billing, payroll, and operational records. Document the checks performed before each re-commissioning and monitor connections, account creations, outgoing flows, and unusual behaviors.
Finally, list the tax, social, contractual, or judicial deadlines threatened by the incident. A cyberattack does not automatically suspend deadlines. Contact the authority or the contracting party, request written confirmation, and keep proof of the encountered impossibility. IT urgency does not make the administrative schedule compassionate by spontaneous generation.
Errors that often exacerbate the crisis
- wait for complete certainty before isolating the first equipment ;
- erase, reinstall or restart before preserving evidence ;
- change passwords from a possibly compromised device ;
- use only the attacked messaging to manage the crisis ;
- restore backups without having addressed the cause and persistence ;
- confuse NCSC reporting, announcement to the FDPIC and criminal complaint ;
- publicly reassure before knowing the actual extent ;
- forget financial flows, salaries and deadlines while all attention remains on the servers.
How Delta Conseil SA can assist you
Delta Conseil SA does not conduct forensic investigations. However, we can help management organize the administrative aspect of the crisis: inventory critical deadlines and flows, secure the continuity of accounting, billing and salaries, reconstruct financial documents and data, coordinate exchanges with the insurer, the bank, the audit body or the authorities, and document the decisions made.
When the incident requires a technical response, specialized data protection analysis or a criminal approach, we coordinate the intervention of competent specialists. This distribution prevents the IT service provider from having to decide alone on legal communication or for management to attempt to manage restoration amid payroll deadlines.
Caution
Technical measures depend on the attack, the architecture, and the available security tools. Isolating a workstation is generally urgent; turning it off, restoring a backup, or revoking access en masse can have contradictory effects. Have these actions validated by a specialist. Legal obligations also depend on the role of the SME, the data, the contracts, the sector, and any potential application of the European GDPR.
Frequently Asked Questions
Does a Swiss SME have to report any cyberattack to the FDPIC?
No. Reporting to the FDPIC concerns a breach of personal data security that likely poses a high risk to personal rights or fundamental rights. The incident and the decision must still be analyzed and documented. If the SME acts as a subcontractor, it must inform the data controller of any breach as soon as possible.
Is the Swiss deadline 72 hours?
No, not under the federal FADP: the text requires a report "as soon as possible." The 72-hour deadline belongs to the European GDPR, when it applies. One should not wait three days automatically if the high risk appears sooner.
Do all SMEs have to report the attack to the NCSC within 24 hours?
No. The obligation targets authorities and organizations defined by law as operators of critical infrastructures, for cyberattacks that meet legal criteria. Other SMEs can make a voluntary report to the NCSC.
Should a ransom be paid to recover faster?
In principle, no. Payment does not guarantee either an effective key or the deletion of copied data. It may encourage further extortion. Recovery must be based on a cleaned environment, verified backups, and a decision coordinated with specialists and the insurer.
Can we go back online as soon as the backup works?
Not without control. The entry point must be addressed, persistence must be sought, the backup must be verified, compromised access must be renewed, and services must be gradually restored under supervision. Restoring too early can simply reinstall the crisis with a cleaner interface.
Official sources
- Federal Data Protection Act (FADP), art. 24
- Data Protection Ordinance (OPDo), art. 15
- FDPIC — Guide on the notification of data security breaches, version 1.2 of April 23, 2025
- FDPIC — Secure DataBreach Portal
- NCSC — Information on the obligation to report cyberattacks against critical infrastructure
- NCSC — Cyber incident reporting portal
- Cybermalveillance.gouv.fr — Ransomware reflex sheet, updated May 7, 2026
- General Data Protection Regulation (GDPR), notably art. 33
Target publication date: June 5, 2026. Last legal check: September 2, 2026.
Warning
This publication is provided for informational purposes and does not constitute individualized legal, tax, accounting, or financial advice. The situation must be assessed in light of the specific circumstances and the applicable law at the time of the decision.
For more information, please see our Legal notices and disclaimer.