security awareness

Is security awareness training mandatory in Switzerland?

AA
Aurum Avis Labs Author
6 min read

Is security awareness training mandatory in Switzerland?

No Swiss statute names security awareness training as a duty of its own. The revised Federal Act on Data Protection (FADP) does require appropriate technical and organisational measures for data security, though, and staff training is one of the usual ways an SME shows it has dealt with human risk. Insurers, customers and standards such as ISO/IEC 27001 often ask whether you train your staff, even if the law never uses the word “awareness”.

This article is for owners and office leads in German-speaking Switzerland with roughly 20 to 250 employees. It is practical orientation, not legal advice. For what belongs in a session, see security awareness training topics.

What the FADP actually requires

Art. 8 FADP requires controllers and processors to ensure data security through technical and organisational measures that suit the risk. The Data Protection Ordinance adds detail on security measures, logging and breach notification. Neither text lists an “annual phishing course”.

In practice, staff behaviour counts as part of the organisational measures: who may send client data, how payments are verified, how incidents are reported. Buying firewalls while ignoring behaviour is hard to defend after a preventable fraud.

Criminal fines under the FADP can reach CHF 250’000. They target natural persons and require intent (FDPIC overview). That is no reason to frighten staff, but it explains why management asks for documented steps.

Who asks besides the law

Cyber insurance applications and renewals often include questions about how often you train and what the training covers. We have not verified a universal insurer checklist, so read your own form and your insurer’s published guidance.

Large customers, especially in EU supply chains, may ask for training evidence in contracts or supplier audits. ISO/IEC 27001:2022 control A 6.3 expects an ongoing awareness programme with records. A one-hour session does not certify you, but it can be part of the evidence.

EU customers may pass NIS2-style obligations on through contracts, although NIS2 does not apply directly in Switzerland. Article 20 NIS2 expects training for management bodies and regular training offers for staff. That is contractual pressure, not Swiss statute. If your contract has a training clause, read that clause rather than a general leaflet.

Usually drives the question

  • Near-miss or fraud attempt
  • Insurance questionnaire
  • Customer audit or ISO A 6.3
  • Uncertainty after the revised FADP

Usually not the driver

  • A named annual course in Art. 8 FADP
  • BACS 24-hour reporting for every SME
  • Automatic GDPR fine for missing e-learning

What is not a general SME duty

The BACS cyberattack reporting duty from 1 April 2025 applies to operators of critical infrastructure, not to most SMEs. Do not tell every firm that it must report to BACS within 24 hours.

Limit

The FADP asks for appropriate measures and names no product. A platform alone does not replace live training or a clear reporting path.

How often should you train?

The law sets no frequency. Auditors and insurers often expect at least an annual refresher and training at onboarding. After a real incident (a phishing click, a changed IBAN, CEO fraud), an extra session makes sense even if the calendar already says “training done”.

65%

Share of small Swiss firms with regular cyber training, in Deloitte’s 2026 study of firms under 250 staff. Not our survey. Deloitte study PDF. Many peers can already show an auditor what they trained and when.

E-learning or live training?

Both can count as evidence. E-learning scales for basics and logged completion. Live sessions fit questions from your own inbox, payment checks and reporting paths. Many SMEs combine the two: a live session once a year and a short module at hiring. Whichever you choose, the content should match your own risks.

What counts as proof?

Keep it simple: a calendar invite or sign-in sheet, slide titles or a one-page summary, the facilitator’s name and the language used. Record date and duration, name attendees or departments, and note three topics taken from your own mail. Repeat the reporting path after the session. File the ISO/IEC 27001:2022 A 6.3 mapping separately from the attendance record. The session does not certify the company.

Security awareness and privacy training

Security awareness covers fraud, phishing and authentication. Privacy training covers everyday handling of personal data under the FADP and GDPR. Many firms book both. The audiences overlap, but the questions differ, so privacy content does not automatically belong in every phishing slot.

Who can wait briefly

A five-person start-up with no client payments and no personal data beyond payroll may put access control first. Once you handle client mail, invoices and HR files at scale, “we are too small to train” no longer holds.

Companies with a full-time security team and a learning platform are outside this article’s audience.

Culture beats checkbox

A duty that exists on paper and is skipped in practice helps nobody. The attendance record matters little if management never says why the training exists and never sits in the room.

If someone clicks a real link, one training session has not failed, but your response path still has to work. See clicked a phishing link at work.

Working with your IT partner

Most SMEs run training with an external facilitator while IT owns mail rules and MFA. Agree who sends reminders, who collects attendance and who answers report mails after the session. Without an owner, annual training becomes an HR calendar entry that IT never hears about.

Swiss context reminders

Fraud dominates the public BACS reports (German page), so payment requests and CEO-style messages belong in every annual session, even if last year’s incidents were “only” phishing links. The reporting duty for critical infrastructure does not apply to most SMEs. Do not unsettle staff with 24-hour rules unless you know you are in scope.

Is a PDF handout enough?

A handout alone shows little effect. Auditors and insurers usually ask for attendance, date and topics. A short live session with a sign-in list goes further.

Must every role get the same course?

Finance and HR need different examples from production. A shared core (phishing, reporting) plus role-specific minutes often suffices.

Light next step

You do not need a platform on day one. Name a person responsible, pick a date for a live session and list three topics from your own mail. Keep the note where the board can find it, not only in the IT ticket system.

When you want a structured format with follow-up, Security Awareness Training describes what a live session covers in Swiss SMEs.

security awareness fadp switzerland compliance
AA

Written by

Aurum Avis Labs

Builds and ships at Aurum Avis Labs. Writes here about what we learn working with founders and SMEs in the DACH region.

Customize your cookie preferences. Essential cookies cannot be disabled as they are required for the website to function properly.

Essential Cookies

Required for basic website functionality, security, user authentication, and error tracking.

Always active

Analytics Cookies

Help us understand how visitors interact with our website to improve user experience. Includes Google Analytics and Microsoft Clarity session recordings.

Marketing Cookies

Used to track visitors across websites to display relevant and engaging advertisements.