A New Fear is Emerging Among Swiss Banks
Operational resilience – a clunky term is currently making the rounds in the IT departments of Swiss banks.
Swiss financial institutions today must protect themselves against a wide range of technical risks. The focus is on cyberattacks (e.g., DDoS on e-banking), outdated IT systems (legacy platforms), and heavy dependence on cloud providers. In addition, stricter requirements for resilience and data protection are coming into force.
Blackout No Longer Just a Theoretical Threat
Ensuring banking services during a power outage is now part of the agenda. Plenty of documentation has been produced, but real-life drills are rare, says Henning Gebert. «Since the blackout on April 28 this year in Spain and Portugal, this is no longer a theoretical risk. Banks are now aware that such an event could very well occur in our region,» says the digitalization specialist at Capco. Henning supports financial institutions in planning and implementing digital transformation projects at the international management and technology consulting firm.
Henning Gebert, digitalisation specialist at Capco. (Image: zVg)
Numerous Swiss banks are currently seeking support from Henning and his team. Stress tests are needed. The blackout in Spain and Portugal revealed several serious issues:
- Branches and terminal infrastructure often lacked sufficient UPS (uninterruptible power supply), meaning even brief interruptions caused major disruptions. Yet cash availability is essential as an emergency backup in severe crises. A contingency plan for cash logistics should be prepared in advance.
- Only larger institutions or central clearing were able to rely on redundancy systems, while branch offices were paralyzed. Mobile connections and internet failed, and point-of-sale systems were knocked out.
- The payment infrastructure at the banks remained stable, but customers had severely restricted access, unable to reach their bank branches or use ATMs. Ultimately, cash withdrawals became impossible.
It is essential that systems can be restarted autonomously in such situations, without relying on external authentication, which typically fails during a blackout, Gebert explains.
Stricter Regulations for International Banks
Those who fail to manage IT security risk outages, fines, and massive reputational damage.
Since January this year, the Digital Operational Resilience Act (DORA) has introduced stricter regulations in the EU for banks, insurers, and asset managers. It mandates systematic ICT risk management, standardized incident reporting, resilience testing, and strict rules for outsourcing IT services.
Swiss Banks Also Affected
DORA also tightens liability rules: executive boards are explicitly liable for deficient ICT governance – even in the case of outsourcing.
Swiss institutions are indirectly affected. They must adapt their governance, IT contracts, and processes – or risk being excluded as third-party providers in the future. DORA has cross-border effects, even without a direct EU mandate.
According to Henning Gebert, awareness among banks has increased significantly since the blackout in Spain and Portugal.









