Swiss rolling-stock maker Stadler Rail confirmed in July 2026 that the Everest ransomware and extortion group breached a data-exchange platform Stadler shares with one of its suppliers, using compromised login credentials to steal supplier technical data. Everest demanded CHF10 million (roughly $12.3 million) to prevent publication or sale of the material. Stadler said flatly it "will not pay any ransom under any circumstances," reported the incident to the Thurgau cantonal police, and stated that no safety-relevant or personal data was taken and that its own IT systems, production, and vehicles were unaffected (Bleeping Computer; SWI swissinfo.ch).
What neither Stadler's statement nor Everest's leak-site posture resolves is a narrower but consequential legal question: did this trigger Switzerland's mandatory 24-hour cyberattack reporting duty for critical infrastructure?
A young law built for direct hits
Switzerland's Information Security Act (ISG) reporting obligation — Articles 74a to 74f, added to the ISG and brought into force on 1 April 2025 alongside the implementing Cybersecurity Ordinance — requires operators of critical infrastructure, including transport companies, to notify the National Cybersecurity Centre (NCSC, now folded into the Federal Office for Cyber Security, BACS) within 24 hours of discovering a cyberattack, with a fuller follow-up report due within 14 days (NCSC: legal basis). Operators that miss the window through intent or gross negligence face fines of up to CHF100,000, a penalty regime that took full effect on 1 October 2025 after a six-month grace period.
In its first six months, the duty generated 164 reports across finance, IT, energy, health, postal services, and transport, according to NCSC's own review — evidence the law is functioning as intended for incidents on an operator's own network (NCSC: six-month review). But the statute and its published guidance describe the trigger as a cyberattack on a covered operator's infrastructure. The Stadler incident sits somewhere else: a breach of a third-party platform, shared with a supplier, holding the supplier's data rather than Stadler's own systems or passenger-facing operations. Neither Stadler's public disclosure nor NCSC's materials address whether that configuration counts.
The case for reading the duty broadly
Regulators have a genuine point here, and it deserves stating plainly before disputing it. Modern rail manufacturing runs on shared supplier extranets, parts-tracking systems, and engineering-data exchanges that sit outside any single company's perimeter but are integral to how trains get built and maintained. If a hostile actor can pivot from a compromised supplier portal into a manufacturer's design data — or eventually toward vehicle software — a reporting regime that only counts attacks squarely on the operator's own servers has an obvious blind spot. NIS2 in the EU already leans this way, folding supply-chain risk management into covered entities' obligations rather than treating vendors as someone else's problem. A narrow reading of the ISG risks the same failure mode global supply-chain incidents (SolarWinds, MOVEit) have repeatedly exposed: the weakest link is rarely the well-defended core.
Why Switzerland should clarify, not expand, first
That said, stretching a 24-hour statutory deadline to cover every incident touching any platform a critical-infrastructure operator happens to share with a vendor would be the wrong fix, and Bern should resist it. The ISG's proportionality was deliberate: it targets operators whose own compromise threatens continuity of an essential service, backed by a real penalty, and its early results — 164 clean reports, sectoral spread, no reported enforcement disputes — show a workable law precisely because its scope is legible. Grafting an undefined "any third party in the data chain" trigger onto that structure would multiply reporting obligations for events a covered entity often cannot detect, verify, or control within 24 hours, since the incident lives on someone else's infrastructure. It would also punish exactly the kind of transparency Stadler modelled: refusing to pay, disclosing publicly, and going to the cantonal police voluntarily, well within the news cycle, without a statutory gun to its head.
The better path is the one Switzerland has generally favored in implementing the ISG: targeted guidance from BACS clarifying when a supplier or platform breach counts as an attack "on" a covered operator — likely tied to whether the operator's own data, systems, or service continuity were materially affected, not merely whether a shared login was involved. That preserves the law's proportionate design while closing the genuine supply-chain gap regulators are right to worry about. Passed via an ordinance amendment or interpretive notice, it would avoid what a blanket expansion would invite: reporting fatigue, chilled willingness to use joint supplier platforms at all, and a critical-infrastructure duty that loses its sharp edges the moment it tries to cover everything.