FINMA’s Circular 2023/1 on operational risks and resilience has been in force since 1 January 2024, and recent supervisory guidance shows most institutions are still short of what it actually requires. The gap is not about awareness of the rule. It is about how resilience gets tested in practice.
What the circular actually demands
FINMA does not ask institutions to describe their resilience on paper. It expects proof under realistic conditions.
The core obligation
Supervised institutions must identify their critical functions, define impact tolerances for each, and regularly test whether their protective, detective and responsive measures actually hold up under a severe but plausible scenario, not a scenario designed to be survivable.
Where most institutions still fall short
FINMA Guidance 05/2025 found that only 12 to 15% of institutions had actually brought business continuity management, ICT and cyber risk, third-party risk, crisis management and recovery planning together into a single coherent framework. The rest were running these components in parallel, each managed separately, with no shared inventory or single reporting line into the board.
Why running components in parallel is a real problem, not a paperwork issue
A resilience framework that cannot be assessed independently of the specific people running each piece is exactly what FINMA is now testing for.
- The arithmetic mean number of identified critical functions across institutions in FINMA’s dataset was 3.5, with the highest count reaching 36, a spread that itself suggests wide inconsistency in how “critical function” gets defined
- Around 60% of institutions defined their own resilience metrics rather than referencing a common standard, making it difficult for a board, or a regulator, to compare performance meaningfully across periods
- An end-to-end test that stops at an institution’s own perimeter misses exactly the part FINMA is asking about, since roughly a third of Swiss financial sector incidents involve a third party, not an internal system alone
TIBER-CH: the test that goes furthest
For systemically important institutions specifically, FINMA expects something considerably more rigorous than a conventional penetration test.
How TIBER-CH differs from a standard pentest
| Standard penetration test | TIBER-CH red team exercise | |
| Scope | A specific application or system | Full attack chain against the real institution |
| Basis | Generic vulnerability scanning | Real threat intelligence on adversaries likely to target the specific institution |
| Duration | Days to weeks | Active red-team phase of at least twelve weeks |
| What it proves | Technical vulnerabilities | Whether detection and response actually work under a live, simulated attack |
TIBER-CH is Switzerland’s variant of the European Central Bank’s TIBER-EU framework, administered jointly by FINMA and the Swiss National Bank, which piloted the approach domestically. A single TIBER-CH engagement can cover three of FINMA’s core expectations at once: protection, detection and response, all evidenced under conditions close to a genuine attack rather than a scripted, survivable one.
Switzerland is not in the EU, but DORA still reaches in
Switzerland’s position outside the EU does not mean DORA and TIBER-EU are irrelevant to every Swiss institution.
A Swiss institution with EU subsidiaries, or a material EU customer base, can fall directly within DORA’s scope and then has to satisfy its own threat-led penetration testing requirement, built on the same TIBER-EU methodology. A threat-led exercise run under TIBER-CH domestically often serves two purposes simultaneously in that situation: it satisfies FINMA’s expectation of tested resilience now, and it lays groundwork that a later, formal DORA TLPT can build on rather than starting from nothing.
What a defensible 2026 resilience programme actually looks like
Given where FINMA’s supervisory attention is focused, a handful of specific steps separate institutions likely to pass close scrutiny from those still exposed.
- Consolidate business continuity, ICT risk, third-party risk, crisis management and recovery planning into one framework with a single reporting line to the board, rather than several parallel workstreams
- Design test scenarios that are severe but plausible, and that are not limited to cyber alone, incorporating natural events, geopolitical disruption and third-party failure where those dependencies are material
- Extend testing scope to cover material third-party relationships directly, since a test that stops at the institution’s own perimeter does not reflect where a meaningful share of real incidents actually originate
- For systemically important institutions, build toward TIBER-CH engagement specifically, rather than relying on standard penetration testing to demonstrate detection and response capability
Building resilience that holds up to supervisory scrutiny
Cyber resilience services Switzerland institutions increasingly need go well beyond a compliance checklist built around the reporting rules already in force. FINMA’s own language is direct: institution-specific supervisory activity in this area will continue and intensify, including deeper scenario analysis. An institution still running its resilience components in parallel, without bringing them into one coherent framework and without having tested its detection and response capability under realistic, threat-led conditions, is exactly the profile FINMA’s current supervisory cycle is built to identify.
READ ALSO: How Modern Schools Can Build More Reliable Communication Systems




