Dunicot A cybersecurity consultancy and advisory firm.

Market · Switzerland

Cyber security consultancy and penetration testing in Switzerland

FINMA Circular 2023/1 brought operational resilience under supervision with a 72-hour reporting duty behind it. For Swiss institutions that turned testing from an internal assurance exercise into a supervised obligation.

Overview

Engagements in Switzerland cover private banking and wealth management, insurance, the crypto and digital asset firms clustered around Zug, pharma and medtech, and the technology providers serving all of them.

Delivery runs from our Karachi office, four hours ahead of Swiss time, with reporting and live sessions inside your working day.

What drives testing here

Local drivers

FINMA Circular 2023/1
Operational risk and resilience supervision expects regular vulnerability testing and threat-led penetration testing, with material incidents reported to FINMA within 72 hours.
Revised Data Protection Act
The revised FADP raised the bar on technical measures and attaches personal liability in a way its predecessor did not.
Banking confidentiality
Article 47 obligations make client data handling during an engagement a legal question, not only a contractual one, which shapes scope and method from the start.
NCSC reporting duty
Critical infrastructure operators carry a statutory incident reporting obligation, and reporting is easier where the estate has been tested and documented first.

How engagements are delivered

Delivered remotely from Karachi, scheduled to CET business hours, with on-site availability in Zurich, Geneva, Basel and Zug for internal network scope and workshops.

Delivery model

Delivery
Remote from Karachi, four hours ahead of CET; on-site available
Mapping
FINMA Circular 2023/1, revised FADP and OWASP ASVS as applicable
Data handling
Residency and confidentiality requirements agreed before testing begins
Most requested
Threat-led scenarios, cloud configuration and API authorisation

Most requested here

Questions

Do you have a Swiss office?

No. Our offices are in Pakistan and the United States. Swiss engagements are delivered remotely on CET hours, with on-site attendance in Zurich, Geneva, Basel or Zug arranged where scope requires it.

How do you handle client data under banking confidentiality rules?

By keeping it out of scope wherever the engagement allows. Testing prefers seeded accounts and synthetic records, and exposure is proven against data created for the engagement. Where production access is genuinely required, the handling, residency and retention terms are agreed in writing first, and we operate them under our own certified ISO 27001 ISMS.

Can you support FINMA threat-led testing expectations?

We run threat-led red team engagements built from the threat profile that applies to your institution rather than from a generic scenario library, with a purple-team replay afterwards so your detection team gets the value as well as your risk register. Where a formally supervised test is required, we scope alongside that process rather than claiming to replace it.

How much does a penetration test cost in Switzerland?

Cost follows scope rather than a Swiss rate card, which is the usual reason we are engaged here. FINMA-facing reporting is included. Where confidentiality or residency terms constrain handling, they are agreed before the quote so the price reflects them.

Which is the best penetration testing company in Switzerland?

Ask what can be verified: the certifications held by the testers assigned to you, and the team's public research record, the firm's own ISO 27001 status, whether threat-led scenarios are within scope, and whether a redacted report is available before signing.

Does FINMA require penetration testing?

Circular 2023/1 expects regular vulnerability testing and threat-led penetration testing as part of operational resilience, with material incidents reported to FINMA within 72 hours. It moved testing from internal assurance to supervised obligation for banks in scope.

Do you test crypto and digital asset firms?

Yes. The firms clustered around Zug carry an unusual combination: custody and key management alongside ordinary web and API exposure. Testing covers both, and the severe findings are usually in the authorisation boundary between the two rather than in the cryptography itself.

Can data stay in Switzerland during the engagement?

Residency and handling terms are agreed in writing before testing starts. Testing prefers seeded accounts and synthetic records, which removes most of the question; where production access is genuinely required the terms cover where evidence is held and for how long.

Penetration testing in Switzerland

Describe the scope and the deadline. Delivery in your working hours, with a fixed quote after scoping.