PhishingRadar
Back to blog

Published on 20 July 2026

Security Awareness Training in Switzerland: Legal Requirement or Optional?

What the law actually requires

The revised Federal Act on Data Protection (revFADP) doesn't explicitly mandate phishing training. Art. 8 FADP does require every data controller to implement "appropriate technical and organizational measures" to protect personal data from unauthorized access. Since phishing is by far the most common entry point for a data breach, employee awareness counts, in the view of many data-protection and legal advisors, among these measures – even though the law never uses the word "training."

Where it becomes a de facto requirement: certifications and audits

Any company pursuing or holding ISO 27001 certification can't avoid security awareness measures: Annex A of the standard (control A.6.3, formerly A.7.2.2) explicitly requires an employee awareness program, along with proof that it was actually carried out. In B2B customer audits too – for example when a larger client reviews your supply chain – the question of documented phishing tests is now part of the standard checklist.

Cyber insurers already ask for it

A growing share of cyber insurers require proof of completed awareness measures either at contract signing or, at the latest, in the event of a claim. Without that proof, the insurer's obligation to pay out can be limited in a real incident, or the premium raised – a point that's increasingly asked about explicitly during contract negotiations.

What counts as proof – and what doesn't

A one-off presentation from three years ago, or an unread mass-emailed PDF, barely counts as solid proof in practice. What actually holds up is recurring, documented exercises with measurable progress – ideally timestamped, with a comprehensible evaluation per team or department, without singling out individual employees.

The difference between ticking a box and real impact

Even if your industry or insurer doesn't (yet) require explicit proof, the underlying risk remains: according to recurring NCSC reports, phishing is one of the most common ways Swiss companies get compromised. Proof that only exists on paper protects no one – what matters is that the training actually changes behavior.

The simplest way to start

PhishingRadar delivers exactly this dual benefit: realistic, recurring simulations for genuine learning progress, and a time-limited, publicly verifiable proof per employee for audits, insurers, and client requests. A free trial run shows in a few minutes what that looks like in practice.

Test your team today

Try the free demo access yourself or register your company directly.