Presentation in preparation...
Data protection is no longer a matter of tools, but of proof: a regulated institution must not only protect its data, it must demonstrate that it can restore it — fully, within strict deadlines, following an incident or an attack. FINMA Circ. 2023/1 on operational resilience shifts the requirement from best practice to obligation: tested recovery, immutability, isolation.
The question for Swiss CIOs and CISOs is concrete: can the operation of this protection be entrusted to a managed service without delegating the responsibility, which can never be outsourced?
This session draws the line between what is entrusted and what remains one's accountability before the regulator — and shows how delegation complements an internal framework instead of replacing it.
Register