Skip to content
Board of DirectorsLiabilityCyber GovernanceSME

Cyber Risks on the Board: Liability and Duties in Switzerland

9 April 2026|7 min read

The board of directors bears ultimate responsibility for risk management, including cyber risks. In the event of an incident, board members can be held personally liable. What board members need to know and do.

Cyber risk is a board-level matter in Switzerland in the strict legal sense: risk management forms part of the board's non-transferable duty of ultimate management under Art. 716a CO, and board members who breach their duties are personally and jointly liable under Art. 754 CO. If a ransomware attack cripples the company for two weeks and the business interruption costs CHF 800,000, the next board meeting will inevitably ask: was there a documented risk management system, were adequate protective measures approved, and can both be evidenced? If not, personal liability is on the table.

Legal Basis of Board Liability

Art. 716a CO (Swiss Code of Obligations) assigns the board of directors the non-transferable and inalienable duties of ultimate management and the organisation of accounting, financial control and financial planning. Swiss Federal Court case law increasingly interprets this to mean that risk management, including cyber risks, forms part of this ultimate management responsibility. Art. 754 CO governs liability: board members are personally and jointly liable for damages caused by a breach of their duties. Liability persists even where duties are delegated, if supervision was inadequate.

What the Board Must Do

Three measures are the minimum. First, have the board briefed at least twice a year on the cyber risk posture, documented in the board minutes. The report should cover the current threat landscape, the status of protective measures, open risks and the residual risk. Second, approve an information security budget and ensure it is proportionate to the risk. A rule of thumb is 5 to 10% of the IT budget for security. Third, ensure an incident response plan exists and is tested annually.

Delegation and Supervisory Duty

The board may delegate the operational implementation of cybersecurity to management or a CISO. The supervisory duty, however, remains with the board. In practice, this means the board must verify the qualifications of the person entrusted, issue clear mandates, monitor regularly and act when deficiencies are identified. FINMA has also tightened cyber governance requirements since 2025: Supervisory Notice 05/2025 requires regulated institutions to maintain documented disruption tolerances and conduct stress tests. These standards also spill over to non-regulated companies as best practice.

Personal Protection for Board Members

A D&O insurance policy (Directors and Officers) covers personal liability but does not replace the duty of care. In the event of a claim, the insurer will examine whether the board fulfilled its duties. Documented resolutions, regular risk reports and demonstrable measures are the best protection. MilesGuard prepares cyber governance documentation for boards of directors: risk assessment, measures overview, reporting templates for board meetings and an annual cyber briefing. This allows you to demonstrably fulfil your duty of care.

Sources

Share:LinkedIn

More Posts

Related Services