Solutions
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21.25 12C21.25 13.2426 20.2426 14.25 19 14.25C17.7574 14.25 16.75 13.2426 16.75 12C16.75 10.7574 17.7574 9.75 19 9.75C20.2426 9.75 21.25 10.7574 21.25 12Z" stroke="black" stroke-width="1.5"/><path d="M7.25 12C7.25 13.2426 6.24264 14.25 5 14.25C3.75736 14.25 2.75 13.2426 2.75 12C2.75 10.7574 3.75736 9.75 5 9.75C6.24264 9.75 7.25 10.7574 7.25 12Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 16.1143C15.4512 15.4931 16.827 15.8617 17.4482 16.9377C18.0694 18.0137 17.7008 19.3895 16.6248 20.0107C15.5488 20.6319 14.173 20.2633 13.5518 19.1873C12.9306 18.1113 13.2992 16.7355 14.3752 16.1143Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 3.98927C8.45117 3.36805 9.82701 3.73671 10.4482 4.81269C11.0694 5.88867 10.7008 7.26451 9.62481 7.88573C8.54883 8.50695 7.17298 8.13829 6.55177 7.06231C5.93055 5.98633 6.29921 4.61048 7.37519 3.98927Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 20.0107C6.29921 19.3895 5.93055 18.0137 6.55177 16.9377C7.17298 15.8617 8.54883 15.4931 9.62481 16.1143C10.7008 16.7355 11.0694 18.1113 10.4482 19.1873C9.82701 20.2633 8.45117 20.6319 7.37519 20.0107Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 7.88573C13.2992 7.26451 12.9306 5.88867 13.5518 4.81269C14.173 3.73671 15.5488 3.36805 16.6248 3.98927C17.7008 4.61048 18.0694 5.98633 17.4482 7.06231C16.827 8.13829 15.4512 8.50695 14.3752 7.88573Z" stroke="black" stroke-width="1.5"/> </svg>

Modern Work

Modern workplaces and collaboration.

Effective solutions
We solve the IT challenges that most hinder Swiss SMEs. From Modern Work and Cyber Security to Cloud Migration.
Discover all solutions
Services
Craftsmanship Excellence
We support you from strategy consulting to seamless 24/7 operations. Professional, proactive, and individually tailored to your infrastructure.
Compare Service Models
About
Our story
100 years of experience. Your partner for innovation since 1925.
Blog Artikel
01.06.2026
2 min read

Together Against Cyber Insecurity

Symbolic image: red warning triangle with security icons floats above a person at a laptop in the dark.

Das Wichtigste in Kürze

  • The ISG reporting obligation affects operators of critical infrastructures and their suppliers too. Without proof of cybersecurity, companies risk losing contracts
  • Burgwinkel’s five-step recommendation: clarify whether you are affected, run a GAP analysis, implement measures, provide evidence, review regularly

Companies should not take the obligation to report cyberattacks lightly. At the Baggenstos Breakfast on 1 July, Dr. Daniel Burgwinkel from the consulting firm KRM spoke on this topic and made his position clear: “Proactively engaging with the new Information Security Act (ISG) and its European counterpart NIS2 is not a tiresome obligation, but a strategic necessity. It not only protects your company from attacks and fines, but also secures your place in tomorrow’s supply chain.”

Which companies are affected by the new Information Security Act (ISG)? In just under eight minutes, Daniel Burgwinkel sums up the current situation – for everyone who couldn’t attend the Baggenstos Breakfast.

The trade magazine Inside IT asked the Federal Office for Cybersecurity (BACS). The reporting obligation is working: according to the BACS, reports mainly concerned DoS/DDoS attacks. Often a single report lists several attacks at once. Particularly in focus: public administration and the financial sector.

A resilient economy

To protect critical infrastructures and make digital Switzerland more resilient, the federal government is tightening the reins and, from autumn onward, will also impose fines if a company fails to comply with its reporting obligation.

But who is affected? Obviously the operators of critical infrastructures. The relevant industries are listed in the ISG. Anyone not listed there should not breathe a sigh of relief: companies in the supply chain are also subject to the obligation – they are indirectly affected.

Loss of contracts looms

Companies in the energy, healthcare or financial sectors, for example, are legally obliged to ensure the cybersecurity of their entire supply chain and to require evidence from suppliers. Those who cannot provide it lose the contract.

Voluntary reporting is therefore reserved for only a smaller share of companies. But they would do well to report attacks too. In doing so, they also help strengthen resilience, by enabling the BACS specialists to identify trends early and nip attacks in the bud through awareness-raising.

Daniel Burgwinkel recommends the following measures:

  • 🔍 Clarify whether you are affected (directly or indirectly through the ISG, NIS2 or the supply chain act)
  • 📊 Carry out a GAP analysis (take stock of existing security measures)
  • 🛠️ Implement measures (information and security management system, employee training)
  • 📋 Provide evidence (documentation, where applicable certification under ISO 27001 or an industry-specific assessment)
  • 🔄 Regularly review effectiveness and adapt to new threats

At Baggenstos we support companies of all sizes, as a Microsoft partner, in building and documenting the necessary cybersecurity. Our team of experts helps them secure their place in the supply chain and become resilient against cyber threats.

No items found.

Share article

Zwei Mitarbeiter im Gespräch am Tisch, einer lächelt im Vordergrund
Schedule an appointment now

Ready for your digital transformation?

In a no-obligation discussion, we'll jointly clarify where your IT can have the greatest impact and how we can support you.