Cyber Risk Compendium

Regulator / supervisory authority

Regulators and supervisory authorities impose legal or regulatory Control requirements on the organisation and can audit or sanction non-compliance. For linkyard's clients this includes bodies such as FINMA (financial institutions), the EDÖB/FDPIC and cantonal data protection commissioners (see ), and sector-specific authorities for critical infrastructure and cantonal government bodies.

Unlike most other stakeholders, regulators do not own the Assets or bear the operational impact of a Risk materialising, but they define minimum requirements (e.g. the Swiss IKT-Minimalstandard, EU NIS2/DORA) and can compel remediation, making them a stakeholder that shapes which controls are mandatory rather than optional.