Content area

Abstract

As the digital landscape evolves, states are increasingly implementing national cyber incident reporting obligations to enhance cyber resilience. This study investigates the implications of these obligations on multinational organizations, focusing on the variability of compliance requirements across jurisdictions and the challenges faced by companies in adhering to these diverse regulations. Through the methodological approach of conducting interviews with cybersecurity experts across various sectors, this study points out the growing complexity in cybersecurity incident reporting obligations. Findings reveal that companies employ multiple strategies to report to regulators, monitor regulatory changes, and educate employees responsible for reporting. However, maintaining compliance is identified as a significant challenge across all sectors, leading to calls for the standardization of regulations and the improvement of automation solutions. Given the lack of research in this area, this work lays the groundwork for future research, opening new avenues for investigation into the potential standardization and automation of cyber incident reporting processes.

Details

Title
Implications of cyber incident reporting obligations on multinational organizations headquartered in Switzerland
Alternate title
Auswirkungen der Meldepflicht für Cybervorfälle auf multinationale Organisationen mit Hauptsitz in der Schweiz
Author
Ecabert, Thomas 1 ; Muhly, Fabian 2   VIAFID ORCID Logo  ; Zimmermann, Verena 3 

 School of Computer and Communication Sciences, EPFL, Lausanne, Switzerland (GRID:grid.5333.6) (ISNI:0000000121839049) 
 Military Academy at ETH Zürich, Birmensdorf, Switzerland (GRID:grid.5801.c) (ISNI:0000 0001 2156 2780); Leo & Muhly Cyber Advisory GmbH, Zürich, Switzerland (GRID:grid.5801.c) 
 ETH Zürich, Professorship for Security, Privacy & Society D-GESS, Zürich, Switzerland (GRID:grid.5801.c) (ISNI:0000 0001 2156 2780) 
Publication title
Volume
5
Issue
4
Pages
585-614
Publication year
2024
Publication date
Dec 2024
Publisher
Springer Nature B.V.
Place of publication
Wiesbaden
Country of publication
Netherlands
Publication subject
ISSN
26629720
e-ISSN
26629739
Source type
Scholarly Journal
Language of publication
English
Document type
Journal Article
Publication history
 
 
Online publication date
2024-09-24
Milestone dates
2024-08-13 (Registration); 2024-07-19 (Received); 2024-08-03 (Accepted)
Publication history
 
 
   First posting date
24 Sep 2024
ProQuest document ID
3255265340
Document URL
https://www.proquest.com/scholarly-journals/implications-cyber-incident-reporting-obligations/docview/3255265340/se-2?accountid=208611
Copyright
© The Author(s) 2024. This work is published under http://creativecommons.org/licenses/by/4.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
Last updated
2025-09-29
Database
2 databases
  • ProQuest One Academic
  • ProQuest One Academic