Switzerland's first attempt to bring cyber risk into major accident supervision did not start with technical controls. It started with a conversation about business-critical processes, and its most useful finding is architectural: the last line of defense at a hazardous facility must work without IT and OT systems at all 2. For security leaders in industry, the lesson reaches beyond chemical plants. Safety independence, continuity and clear accountability for shared IT services are three separate design questions, and most organizations have answered only the first.
What the pilot tested
On 28 September 2026 the National Cyber Security Centre (NCSC, German BACS) published the findings of a pilot run with the Federal Office for the Environment (FOEN) and cantonal enforcement authorities 1. It covered facilities under the Major Accidents Ordinance (MAO), which applies where hazardous substances, organisms or dangerous goods could seriously harm the public or the environment 2. The report states that no widely accepted, practical approach yet exists for treating cyber risk systematically in major accident prevention 2.
The method was structured discussions based on the NCSC's Cyber Resilience Assessment (CyRA) questionnaire, with one volunteer company each in the cantons of Thurgau and Basel-Landschaft 2. The discussions were explicitly not audits and had no regulatory consequences 2. The scale matters: two companies. The report itself says no general conclusions on typical challenges are possible 2.
CyRA was first tested in the canton of Aargau, where 25 organizations completed a self-assessment of up to one day's work. It deliberately starts from business-critical processes and their dependencies on IT and OT systems, rather than from a control catalog such as NIST CSF or ISO/IEC 27001 3. The NCSC describes it as a prototype 3.
Three independence questions the pilot exposes
The pilot found no chain of events in which a cyber incident could directly trigger a major accident at either company. Cyber incidents could still act indirectly, by disrupting business-critical processes, altering information or influencing plant control 2. The report also observes that targeted attacks on plant processes demand such expertise that other attack types are more likely 2. From these findings we derive a simple model of three questions, each with a different owner. The model is ours; the evidence is the pilot's.
| Question | What the pilot says | Typical owner |
|---|---|---|
| Can the plant reach a safe state without IT and OT? | Independent or hard-wired safety systems should bring the facility under control during anomalies; technical protection that operates independently of IT and OT keeps safety-critical situations from arising during digital disruption 2 | Plant safety, engineering |
| Can critical processes continue or be restored? | Controlled shutdowns cost production, so continuing processes in a controlled manner or restoring them in reasonable time is the key continuity objective 2 | Business continuity, operations |
| Who is accountable when the dependency sits elsewhere? | Reliance on parent-company or external IT services makes local responsibility hard to exercise when transparency on systems, changes or emergency procedures is limited 2 | Group IT, procurement, site management |
The first question is usually settled, because physical safety functions are well established in major accident prevention 2. The second and third are where the pilot found recurring gaps: mapping business-critical processes to their IT and OT dependencies, delineating responsibility for centrally provided services, and detecting and responding to incidents early 2.
The broader Aargau pilot points the same way. Its 25 organizations typically had basic IT protections such as backups and access controls. The weak points were mapping IT and OT dependencies along business processes, prioritized and rehearsed recovery planning, and managing external IT providers, a pattern the NCSC saw across all sectors 3. Two independent pilots, in different sectors, converge on process dependencies and provider accountability, not on missing technical controls.
Our reading: the unit of analysis for cyber resilience in industry is the process, not the system. A security architecture that cannot say which process fails when a shared service fails cannot say whether the safety layer is sufficient, either. The pilot's own finding that cyber risks matter less at individual system level than through their effect on process objectives supports this 2.
What it means for Switzerland
For operators under the MAO, the pilot signals the direction of travel, not new obligations. The report says the results carry no regulatory implications 2, and it states that the approach is unlikely to scale widely because the discussions require expertise and time. It suggests targeted, risk-based use at particularly relevant or highly digitalized sites, and expects individual cantons to gain experience first 2. The NCSC intends to develop the approach so that other enforcement agencies and regulators can apply it independently 1. Operators should therefore expect questions of this kind to arrive through cantonal enforcement contacts before they arrive through legislation.
The timing matters. On 25 September 2026 the Federal Council instructed the Federal Department of Defence, Civil Protection and Sport to draft a consultation proposal for a standalone Cybersecurity Act by June 2027. Existing sector regulation stays in force, and the new act supplements it with cybersecurity obligations as a related responsibility 4. A process-based supervisory method is one plausible way such supplementary duties could be exercised across sectors. We think that is likely, but it is our inference; no source states it.
For groups with Swiss sites run on parent-company IT, the third question deserves attention first. The report flags this structure explicitly, and the CyRA feedback noted that the questionnaire only partly reflected centrally provided IT 2. The practical consequence is a governance one: someone at site level must be able to answer for processes whose systems are operated elsewhere.
Questions for leadership
- For each business-critical process at our sites, can we name the IT and OT systems and the shared services it depends on?
- Which safety functions would still work if every connected system failed, and who has verified that independently of the cyber program?
- If a parent company or external provider changes or loses a service, how would the site learn of it, and who decides?
- Would a regulator's questions about continuity and emergency procedures find us rehearsed, or only documented?
- Are we using a self-assessment to reflect, or to report? The NCSC itself says CyRA must remain an awareness tool and not a compliance tool 2.
Sources
- National Cyber Security Centre (NCSC/BACS), “Pilot project to strengthen cybersecurity at facilities with a potential for major accidents”, 28 September 2026. bacs.admin.ch
- FOEN, NCSC and cantonal enforcement agencies, “Cybersecurity at facilities with a potential for major accidents: findings from the pilot project”, 28 September 2026. bacs.admin.ch
- National Cyber Security Centre (NCSC/BACS), “Cyber Resilience Assessment (CyRA): How resilient are Swiss communes and companies to cyberattacks?”, 26 June 2026. bacs.admin.ch
- Federal Council / NCSC, “Federal Council plans to introduce new Cybersecurity Act”, 25 September 2026. bacs.admin.ch