Cybersecurity · Zurich · CH / EU

Security that pays.

We approach cybersecurity from an adversarial-economic perspective — investment must match the value of the information at stake. That negotiation belongs where decisions are actually made: between board, legal, and compliance.

Understand EU regulation
What we do

Three disciplines, one doctrine.

From strategic positioning through legally defensible valuation to regulatory practice. Sector- and size-agnostic, from SME to multinational.

01 / Strategy

Strategy that bridges.

We work at the level where security decisions are actually made — between board, legal, and compliance. Need-to-protect, doctrine, and investment logic are not delegated here; they are negotiated.

  • Security doctrine & strategic positioning
  • Asset valuation & risk economics
  • Investment prioritisation & security portfolio
  • Bridge function to legal, compliance & audit
  • Board & supervisory dialogue
02 / Valuation

Security, legally defensible.

Independent assessments that hold up before insurers, in due diligence, and in proceedings. We quantify what others merely assert — state of the art, duty of care, loss potential.

  • Insurer-ready reports (premium & claim cases)
  • Cyber lens in due diligence (M&A · investments)
  • State-of-the-art & duty-of-care — audit-proof
  • Proceedings support (arbitration · supervisor)
  • Loss-potential modelling
03 / Regulation

Regulation, put into practice.

We translate directives into operational reality — without buzzword theatre, with verifiable trails. Strong at the Switzerland / EU interface, from cyber to AI regulation.

  • EU cyber regulation — NIS-2 & Cyber Resilience Act
  • EU AI Act, AI governance & secure AI adoption
  • Swiss ISG & BACS reporting duties
  • ISO 27001 / 27002
  • FINMA · DORA · sector-specific
  • Audit-readiness & defensibility before regulators
The regulatory landscape

Europe is tightening the perimeter.
What does that mean for Switzerland?

From NIS-2 via the Cyber Resilience Act to the AI Act, the EU is articulating its most comprehensive cybersecurity expectation to date — and, for the first time, one for the use of AI. Swiss companies are not directly bound — but via EU subsidiaries, EU markets, and supply chains the pressure passes through almost without gap.

24h
Early warning for significant incidents — in the EU as under the Swiss ISG since April 2025.
€35M
Maximum fine under the EU AI Act for prohibited AI practices — or 7% of worldwide annual turnover.
2027
Full application of the Cyber Resilience Act from December 2027 — the same month the AI Act's high-risk duties take effect.

The EU regulates cybersecurity along two axes. The NIS-2 Directive obliges organisations: 18 sectors, risk management, supply-chain due diligence, a 24-hour reporting duty — and executive management bears personal responsibility.

The Cyber Resilience Act addresses products — all "products with digital elements" on the EU internal market, from the IoT sensor to standalone software. Security-by-design becomes mandatory, the CE mark will include cybersecurity, and responsibility does not end at the sale.

  • Organisations NIS-2: 18 sectors, medium and large enterprisesRisk management, security concepts, supply-chain due diligence — personal liability of executive bodies.
  • Products CRA: security-by-design · vulnerability management · updatesConformity assessment before market entry; support across the entire product lifetime.
  • Reporting 24 h early warning · 72 h notification · 1 month final reportUnder the CRA additionally: actively exploited vulnerabilities to ENISA from September 2026.
  • Sanctions Up to €10 m or 2% (NIS-2) · up to €15 m or 2.5% (CRA)Plus market withdrawal, CE revocation, and temporary disqualification of executives.
The EU treats cybersecurity as a compliance discipline on par with data protection or anti-money-laundering — with verifiable duties and meaningful sanctions instead of pious wishes.

With the AI Act, the EU regulates the use of AI comprehensively for the first time — risk-based, from prohibited practices via high-risk systems to transparency duties. The regulation reaches beyond the EU: it applies even when a system is operated outside the EU but its output is used within it. Swiss companies are in scope faster than many realise.

The law is only half the equation. Introducing AI creates new attack and leakage surfaces: uncontrolled AI use by employees, trade secrets in third-party models, systems open to manipulation. And wherever personal data is involved, the revDSG and GDPR apply in full — technology neutrality is no shield from supervision.

  • Approach Risk-based — duties scale with the risk classHigh-risk systems require risk management, data quality, human oversight, and documentation.
  • Timeline Prohibitions since 02 / 2025 · transparency from 08 / 2026 · high-risk from 12 / 2027The high-risk deadlines were deferred in 2026 via the "Digital Omnibus" to December 2027 and August 2028.
  • Sanctions Up to €35 m or 7% of worldwide annual turnoverFor prohibited practices; other violations up to €15 m or 3%.
  • Data protection Personal data in AI systems falls under revDSG and GDPRThe revised Swiss Data Protection Act is technology-neutral — it covers AI use in full.
Introducing AI takes both: a legal framework that holds up before the supervisor, and a security framework that prevents data leakage and misuse — before the first system goes live, not after.

Switzerland is not an EU Member State — NIS-2, the CRA, and the AI Act do not apply directly. It is nevertheless an illusion to think Swiss companies are unaffected. The effect travels through three channels, and it is real.

i

EU subsidiaries

An establishment in the EU is directly subject to local EU law — with all reporting duties and fine ceilings.

ii

Services into the EU market

Anyone offering digital services or AI systems from Switzerland into the EU often falls directly within scope — the AI Act applies as soon as the output is used in the EU.

iii

Supply chain

EU customers are required to vet their suppliers. EU duties are thus passed "downstream" — through contracts rather than statutes.

In parallel, Switzerland is tightening its own framework. The Information Security Act (ISG) has been in force since January 2024; since 1 April 2025, a 24-hour reporting duty applies to operators of critical infrastructure vis-à-vis the Federal Office for Cybersecurity (BACS). Breaches can be fined up to CHF 100,000. An expansion of scope towards the EU logic is foreseeable.

The central question is not "are we compliant?" but "are we resilient — and can we prove it?" Anyone who wants answers should have them before the incident, not after.
Timeline

What goes live when.

The regulatory wave does not start in 2027 — it has been in motion since 2024. The dates below are the pillars. Preparation begins several quarters earlier.

  1. 01 · 2024
    Swiss ISG enters into force First reporting duties for federal bodies and operators of critical infrastructure.
  2. 02 · 2025
    AI Act: prohibitions apply Prohibited practices — from social scoring to manipulative AI — are banned.
  3. 04 · 2025
    CH: 24-hour reporting duty active BACS notification mandatory for operators of critical infrastructure.
  4. 08 · 2026
    AI Act: transparency duties AI interaction and generated content must be recognisable as such.
  5. 09 · 2026
    CRA reporting duties begin Active vulnerabilities and incidents reportable — manufacturers' reality.
  6. 12 · 2027
    CRA in full · AI high-risk duties No CE without cyber — and high-risk AI requires the full evidence trail.

No sales pitch.
Fifteen minutes of clarity about what you actually need to protect.

About the firm
For sensitive matters, please use Threema or Signal — not unencrypted email