About

Most compliance writing is either legal jargon or generic global advice. This is neither.

Second Line exists because Swiss information security regulation — revDSG, FINMA circulars, ISDS and WAID requirements for cantonal and social-insurance bodies — is either buried in legal register few practitioners have time to parse, or flattened into generic international content that skips the parts specific to Switzerland entirely.

Regulation pieces here follow the same structure on purpose: what a requirement actually says, why it exists, and a short checklist of what it means in practice. Everything is checked against the primary text rather than against other people's summaries, and margin numbers are cited so you can go and look. Alongside those, there is writing about the work itself — what a career in audit, risk and compliance actually involves, which is covered far less honestly than the technical side of security.

The name

The second line of defence is the risk and compliance function: it sits between the first line, which owns and runs the risk, and the third line, internal audit, which checks that both are working. It is an unglamorous place to sit and a very good place to see from. That is the vantage point everything here is written from.

Who writes this

The author works in IT security, governance and risk consulting in Switzerland, with a background spanning finance, IT audit, and information security advisory for regulated organisations. For now, this is published without a name attached — the writing is meant to stand on its own.

  • Certification CISA · CISM · CRISC (ISACA)
  • Certification ISO 27001 Lead Auditor
  • Certification SWIFT Customer Security Programme
  • Background Finance → IT Audit → GRC / Security advisory

Nothing here draws on client work, and no client is ever the subject of a post. Everything is written from public sources and general practice.

Get in touch

A contact channel will be added here once the anonymous phase ends.