Switzerland cybersecurity policy

Stadler's Supplier Breach Tests the Edges of Switzerland's 24-Hour Cyber Reporting Duty

Stadler's refusal to pay Everest's CHF10m ransom exposes a gap in Switzerland's cyber reporting law for third-party breaches.

Stadler Breach Meets Switzerland's Cyber Reporting L… People of Internet Research · Switzerland CHF10m / $12.3M Ransom demanded Everest's demand after breaching a… 24 hours Mandatory reporting window ISG Art. 74a requires critical-inf… 164 Reports in first six months NCSC received 164 cyberattack repo… CHF 100,000 Maximum non-reporting fine Operators that intentionally or ne… peopleofinternet.com
Stadler Breach Meets Switzerland's Cyb… People of Internet Research · Switzerland CHF10m / $12.3M Ransom demanded 24 hours Mandatory reporting window 164 Reports in first six months CHF 100,000 Maximum non-reporting fi… peopleofinternet.com

Key Takeaways

Swiss rolling-stock maker Stadler Rail confirmed in July 2026 that the Everest ransomware and extortion group breached a data-exchange platform Stadler shares with one of its suppliers, using compromised login credentials to steal supplier technical data. Everest demanded CHF10 million (roughly $12.3 million) to prevent publication or sale of the material. Stadler said flatly it "will not pay any ransom under any circumstances," reported the incident to the Thurgau cantonal police, and stated that no safety-relevant or personal data was taken and that its own IT systems, production, and vehicles were unaffected (Bleeping Computer; SWI swissinfo.ch).

What neither Stadler's statement nor Everest's leak-site posture resolves is a narrower but consequential legal question: did this trigger Switzerland's mandatory 24-hour cyberattack reporting duty for critical infrastructure?

A young law built for direct hits

Switzerland's Information Security Act (ISG) reporting obligation — Articles 74a to 74f, added to the ISG and brought into force on 1 April 2025 alongside the implementing Cybersecurity Ordinance — requires operators of critical infrastructure, including transport companies, to notify the National Cybersecurity Centre (NCSC, now folded into the Federal Office for Cyber Security, BACS) within 24 hours of discovering a cyberattack, with a fuller follow-up report due within 14 days (NCSC: legal basis). Operators that miss the window through intent or gross negligence face fines of up to CHF100,000, a penalty regime that took full effect on 1 October 2025 after a six-month grace period.

In its first six months, the duty generated 164 reports across finance, IT, energy, health, postal services, and transport, according to NCSC's own review — evidence the law is functioning as intended for incidents on an operator's own network (NCSC: six-month review). But the statute and its published guidance describe the trigger as a cyberattack on a covered operator's infrastructure. The Stadler incident sits somewhere else: a breach of a third-party platform, shared with a supplier, holding the supplier's data rather than Stadler's own systems or passenger-facing operations. Neither Stadler's public disclosure nor NCSC's materials address whether that configuration counts.

The case for reading the duty broadly

Regulators have a genuine point here, and it deserves stating plainly before disputing it. Modern rail manufacturing runs on shared supplier extranets, parts-tracking systems, and engineering-data exchanges that sit outside any single company's perimeter but are integral to how trains get built and maintained. If a hostile actor can pivot from a compromised supplier portal into a manufacturer's design data — or eventually toward vehicle software — a reporting regime that only counts attacks squarely on the operator's own servers has an obvious blind spot. NIS2 in the EU already leans this way, folding supply-chain risk management into covered entities' obligations rather than treating vendors as someone else's problem. A narrow reading of the ISG risks the same failure mode global supply-chain incidents (SolarWinds, MOVEit) have repeatedly exposed: the weakest link is rarely the well-defended core.

Why Switzerland should clarify, not expand, first

That said, stretching a 24-hour statutory deadline to cover every incident touching any platform a critical-infrastructure operator happens to share with a vendor would be the wrong fix, and Bern should resist it. The ISG's proportionality was deliberate: it targets operators whose own compromise threatens continuity of an essential service, backed by a real penalty, and its early results — 164 clean reports, sectoral spread, no reported enforcement disputes — show a workable law precisely because its scope is legible. Grafting an undefined "any third party in the data chain" trigger onto that structure would multiply reporting obligations for events a covered entity often cannot detect, verify, or control within 24 hours, since the incident lives on someone else's infrastructure. It would also punish exactly the kind of transparency Stadler modelled: refusing to pay, disclosing publicly, and going to the cantonal police voluntarily, well within the news cycle, without a statutory gun to its head.

The better path is the one Switzerland has generally favored in implementing the ISG: targeted guidance from BACS clarifying when a supplier or platform breach counts as an attack "on" a covered operator — likely tied to whether the operator's own data, systems, or service continuity were materially affected, not merely whether a shared login was involved. That preserves the law's proportionate design while closing the genuine supply-chain gap regulators are right to worry about. Passed via an ordinance amendment or interpretive notice, it would avoid what a blanket expansion would invite: reporting fatigue, chilled willingness to use joint supplier platforms at all, and a critical-infrastructure duty that loses its sharp edges the moment it tries to cover everything.

Sources & Citations

  1. NCSC: legal basis of the reporting obligation
  2. NCSC: six-month review of the reporting obligation
  3. Bleeping Computer: Stadler rejects $12.3M ransom demand
  4. SWI swissinfo.ch: Stadler hit by cyberattack, CHF10m demanded