Summary
- Swisscom's 2020 record must be treated as a sequence, not as one outage with one cause. The Federal Office of Communications, or OFCOM, identified six outages from 17 January through 19 February and another on 26 May; its analysis isolated seven first-half incidents with nationwide consequences from ten reports. [1]
- On 17 January, a landline failure affected most cantons from about 10:00 to 11:22. Reporting based on Swisscom's account attributed it to a defective component. Emergency numbers were affected, and mobile calling was offered as an alternative, but that instruction does not prove that every caller had a usable fallback. [18]
- The 11–12 February event provides the clearest public control evidence. Swisscom said several critical components were updated at the same time after the risk was classified too low; it later said the safer plan would have split the work across two nights. [3]
- That maintenance event began at about 22:30, affected internet-based services, fixed and mobile telephony and television, and made emergency numbers unavailable in several cantons. Swisscom stopped and reversed the work, with services recovering after midnight. [15]
- SRF reported at least 40 unanswered calls to the Zurich emergency centre and relayed Swisscom's explanation that installed redundancies could not be activated after the maintenance error disabled them. The figure is evidence from one centre, not a national missed-call total. [16]
- The later incidents must remain distinct. A 19 February hardware fault affected a subset of customers for roughly five hours, while the 26 May fixed-and-mobile calling outage was reported across all Swiss regions; contemporaneous reporting said emergency numbers were not affected on 26 May and that the cause was still under investigation. [17][19]
- OFCOM described emergency calling as an end-to-end service involving the caller's fixed or mobile access, any transit network, emergency routing and the alarm centre's connection. A fallback at only one point cannot establish continuity for the whole chain. [1][20]
- Swisscom commissioned two external audits and recorded tighter change controls, more redundancy, closer work with emergency organisations, additional monitoring and a programme to remove single points of failure. Those are documented responses; the underlying audits are not public in the available record, and the measures are not independent proof that every failure mode was durably removed. [1][2][3]
- Swisscom still met the annual universal-service voice-availability criterion. That countervailing fact shows why an aggregate availability measure can coexist with a serious emergency-continuity failure at a particular time and place. [1][7]
- Later official measures sharpened the design test: emergency-number reachability entered the Federal Council's 2022–2025 objectives for Swisscom, and OFCOM's 2023 reference model proposed an independent platform fallback, a second provider for alarm-centre connections and stronger static or dynamic routing. These are later governance and design records, not retroactive findings about the exact 2020 network. [8][13]
Redundancy becomes real only when traffic can use it
A network can contain duplicate components and still have a single operational fate. Two devices may depend on the same maintenance decision. Two access technologies may converge on the same voice platform. Two logical routes may terminate on one alarm-centre connection. A backup may be installed but unavailable while work is under way. For ordinary service, that gap can become a frustrating outage. For an emergency number, it becomes a test of whether the public can reach police, fire or medical assistance when minutes matter.
Swisscom's account of the 11 February maintenance event makes that distinction unusually concrete. The operator said several critical components were updated simultaneously because the work had been assessed as too low-risk. It also said the change should instead have been divided across two nights, with only half of the relevant components affected on each night. [3] The admission does not disclose the full architecture, the people who made each decision or every command executed. It does establish that the planned boundary of the work was part of the failure problem.
That fact changes the accountability question. It is not enough to ask whether redundant equipment existed before the maintenance window. The more useful questions are whether the components occupied genuinely separate fault domains, whether the work preserved at least one known-good route, whether emergency calls were monitored independently of ordinary traffic and whether rollback restored the service that mattered. Redundancy is an operating property demonstrated under stress, not an inventory count.
OFCOM's analysis reinforces this view from the service side. Emergency calling is not a function performed by one box. The call must originate over a fixed or mobile connection, move through the relevant provider and any transit arrangements, be routed to the technically and geographically competent alarm centre, and reach that centre over its own connection. [1] A duplicate element at one stage cannot compensate for a common dependency elsewhere. Continuity therefore belongs to the complete call chain, even where control of that chain is divided among institutions.
This is why the Swisscom sequence is a network-infrastructure accountability case rather than a generic corporate outage story. Remove emergency-call routing, the fixed and mobile voice dependencies, the maintenance-induced loss of usable redundancy, the evidence that some alarm centres were unreachable and the uncertainty around call completion, and the public-safety thesis disappears. What remains is merely a list of service interruptions. The central issue is whether an essential communications route continued to operate when its nominal safeguards were needed.
The chronology is a sequence, not a single defect
The first discipline is numerical and chronological. OFCOM reported six Swisscom network outages between 17 January and 19 February 2020 and an additional outage on 26 May. Swisscom had reported ten disruptions during the first half of the year. OFCOM's account says one did not meet the applicable reporting threshold and two were locally limited cable breaks outside Swisscom's responsibility, leaving seven incidents with nationwide consequences in its analysis. Across that set, fixed or mobile telephony, internet, television and mobile-radio services were affected. [1]
Those numbers should not be converted into a claim that one defect persisted across the period. OFCOM's conclusion was more cautious: the failures appeared to have different causes and no causal relationship. [1] Swisscom publicly discussed a mixture of hardware failure, human misjudgment and missing or ineffective redundancy, but neither that description nor the clustering of dates establishes one hidden technical root. The proper unit of analysis is a bounded sequence that raised recurring resilience questions through different events.
17 January: a landline failure with an incomplete fallback story
On 17 January, the landline network failed across most Swiss cantons. SWI swissinfo.ch, citing Swisscom, reported an interval of approximately 10:00 to 11:22 and attributed the disruption to a defective component. Emergency numbers were affected. Users were directed toward mobile alternatives while the fixed service was unavailable. [18]
The mobile instruction is evidence of some access diversity, but it is not evidence of universal continuity. It shows that a different access technology remained available to at least some users; it does not establish that every person attempting an emergency call possessed a working mobile device, had coverage, understood the instruction or could reach an alarm centre over an end-to-end independent route. The sources do not provide those population-level details, so the point is narrower: a caller-side alternative may reduce harm without proving that the emergency service itself remained continuously reachable.
The January event also should not be retrofitted with the February explanation. The public account attributes January to a defective component. It does not say that the same simultaneous software update, the same disabled redundancy or the same exact routing condition caused both incidents. [18] Keeping that boundary intact matters because a useful resilience programme must test more than one failure class: component failure, maintenance error, congestion, dependency loss and recovery behaviour may require different controls.
11–12 February: maintenance crossed the redundancy boundary
The 11–12 February interruption is the strongest public evidence about control. SRF reported that the event began at around 22:30 and affected internet-based services, fixed and mobile telephony and television. Emergency numbers were unavailable in several cantons. Swisscom stopped the maintenance and reversed it, and services recovered after midnight. [15]
Swisscom later supplied the key planning detail. Several critical network components had been updated at the same time because the risk classification was too low. The operator said the work should have been separated across two nights so that only half of the critical components were touched on either night. [3] This is not a basis for naming an individual as careless. It is evidence that risk classification, work segmentation and the preservation of an unaffected fault domain were organisational controls with direct public-safety consequences.
SRF's separate account adds a service-level effect. At least 40 calls to the Zurich emergency centre went unanswered during the interruption. The report also relayed Swisscom's explanation that redundancies existed but could not be activated after the maintenance error disabled them. [16] The minimum of 40 belongs to the cited Zurich centre. It must not be multiplied, generalised to Switzerland or represented as a complete count of failed emergency calls.
The distinction between installation and activation is the central lesson. Redundancy that is administratively or technically unavailable during the activity most likely to disturb the primary system is not usable protection for that activity. A maintenance plan can therefore create a common-mode failure even if the steady-state architecture contains duplicated equipment. The public evidence does not disclose the exact topology, but it does disclose enough to ask whether the change plan respected the topology's intended separation.
Rollback also needs a precise reading. Stopping and reversing the work was a necessary recovery action, and the reported recovery after midnight gives a bounded service chronology. [15] Yet reversal alone does not answer which emergency routes had resumed, how call completion was verified, whether every affected alarm centre had recovered or how long retries and partial failures persisted. A configuration can return to its earlier state before the end-to-end service is fully healthy. The sources do not provide a national service-by-service restoration matrix.
19 February: a narrower hardware event
On 19 February, SRF reported another disruption, this time associated with a hardware defect. It affected a subset of customers from about 03:40 until 08:40. The report placed it against the backdrop of the January and 11–12 February incidents, but its public scope was narrower. [17]
The record does not support saying that every Swisscom customer was affected, that every service failed or that emergency numbers were unavailable nationwide during this event. It belongs in the regulator's early-2020 sequence because it contributed to the scrutiny of network stability. It does not inherit the emergency-call impact evidence from 17 January or 11–12 February. Treating it separately prevents a true series from becoming a false composite.
26 May: nationwide calling disruption without a confirmed emergency-number failure
On 26 May, fixed and mobile calling was disrupted across all Swiss regions from around 11:50 to 14:55. Contemporaneous SWI reporting said Swisscom stated that emergency numbers were not affected. It also said the precise cause was still being investigated. [19]
Both parts of that account matter. The breadth of the calling disruption makes May relevant to the regulator's resilience analysis. The reported availability of emergency numbers keeps it from becoming another confirmed emergency-call outage. The unresolved cause prevents later analysis from filling the gap with a February-style maintenance explanation, a supplier theory or an invented common component. The bounded statement is that May was a nationwide fixed-and-mobile calling failure in the sequence, with emergency numbers reported unaffected and cause not yet established in the contemporaneous source.
A separate March record also needs a boundary. Swisscom and Sunrise later described interconnection congestion during the exceptional call volumes of the early COVID-19 period. [4] That record demonstrates that cross-network call capacity can become a continuity dependency. It does not show that pandemic traffic caused the January or February faults, and it should not be used to collapse a demand-driven interconnection issue into the earlier hardware and maintenance events.
An emergency call is an end-to-end network service
The emergency number is simple at the user interface and complicated underneath. The caller enters a short number. The network must identify the service requested, determine the appropriate destination, retain or derive location information as required, route the call through the relevant voice systems and deliver it to an alarm centre capable of answering. Pre-event OFCOM material had already described the routing and location challenges introduced by mobile and VoIP services. [20]
OFCOM's 2020 incident report framed the chain in practical terms. An emergency call passes through the caller's fixed or mobile connection, may traverse another network, and must reach the alarm centre through that centre's connection. [1] This structure creates several distinct availability questions. Can the caller originate a voice session? Can the provider recognise and route the emergency number? Can any transit or interconnection carry it? Is the destination mapping available? Can the designated alarm centre receive the call? Can the operator and centre tell that the call completed?
The 2020 record contains evidence from both ends. OFCOM said access to emergency services was sometimes impossible for subscribers of other operators. It also said some alarm centres were themselves temporarily unreachable. [1] The first fact points toward cross-provider routing or transit dependence; the second points toward the destination side of the chain. Neither supplies a complete topology, but together they rule out an analysis limited to Swisscom retail subscribers.
Switzerland's transition to All-IP provides relevant context but not an incident cause. Swisscom recorded completion of its All-IP migration in 2020, and ComCom's annual report also described the transition. [5][7] Fixed telephony operating over IP can share operational systems and dependencies that differ from older line-powered arrangements. The cited records do not establish that VoIP, by itself, caused any specific 2020 outage. The sound inference is that emergency continuity had to be assessed in an IP-based voice environment rather than assumed from the historical identity of a landline.
Swisscom had earlier marketed battery support and mobile fallback for IP-based emergency telephone equipment. [6] That illustrates one useful layer of resilience: keep customer equipment powered and offer another access technology. It is not evidence about the alarm-centre topology in 2020, and it does not show that failover succeeded during the incidents. A battery cannot repair an unavailable routing platform. A mobile handset cannot guarantee independence if fixed and mobile calls converge on a failed function or destination connection.
Current OFCOM guidance and technical material further describe provider duties for routing and location identification and the role of central emergency-call functions. [9][10] Those current materials should not be projected backward as a precise description of every 2020 configuration or obligation. They are useful because they make the service layers visible: origin, location, routing, platform and alarm-centre delivery must be considered together.
The continuity problem is therefore systemic but not ownerless. Different organisations can control different segments. A fixed or mobile provider controls its access and voice systems. Transit or interconnection partners control links between networks. An emergency platform operator may control central routing functions. Cantonal or emergency organisations may control how their alarm centres connect. The regulator controls parts of the rule and reporting environment. Divided control makes evidence more important, not less, because no single status light proves the whole service works.
The February change was a chain of control decisions
A software update is often described as a technical act, but its risk is shaped before anyone begins the work. Someone defines the intended change. Someone identifies affected components. Someone classifies the risk and blast radius. Someone decides whether redundant elements may be touched together. Someone sets stop conditions and rollback criteria. Someone chooses the telemetry that will determine whether customers and emergency services remain protected.
Swisscom's account identifies a failure in that chain without identifying every actor. The risk was assessed too low, several critical components were updated simultaneously, and the operator later said the work should have been divided across two nights. [3] The relevant unit of accountability is therefore the change-control system: its rules, evidence, approvals, separation constraints and ability to preserve a known-good service route.
Risk classification is not merely an administrative label. It determines who must approve a change, what testing is required, how much of the network may be exposed, which staff must be present, whether external stakeholders need notice and what rollback threshold applies. When the affected service includes emergency calls, consequence must matter alongside estimated probability. A low-probability event can still demand strong controls if its credible impact includes unreachable alarm centres.
Work segmentation is equally important. Dividing the update across two nights would not, by itself, guarantee safety. It would, however, preserve more opportunity to observe one group while another remains unchanged. It can limit the common blast radius, provide a comparison state and reduce the chance that a single mistaken assumption disables all redundant elements at once. Swisscom's own account makes segmentation a concrete counterfactual rather than a generic best practice. [3]
The public record does not say who authored the risk assessment, who approved it or whether a supplier influenced the plan. It does not disclose the exact components, configuration, dependency graph or maintenance commands. Those absences prevent personal blame and vendor attribution. They do not prevent an evidence-based question: what control allowed multiple critical elements to enter the same change domain, and what proof now prevents a recurrence?
Monitoring is the next link. Ordinary alarms may show processor state, interface state or platform availability. Emergency continuity requires a service-level view: attempted emergency calls, routing success, delivery to the intended centre, answer or completion signals, failures by originating network, and anomalies at the destination. The sources do not reveal which measures were available in real time on 11 February. That is precisely why monitoring evidence belongs in any credible assurance record.
Rollback criteria also need to be service-specific. A team may reverse a change when infrastructure alarms cross a threshold. But if emergency calls already fail, the criterion has arrived too late. A stronger control defines both preventive abort conditions and restoration conditions. The first limits harm; the second prevents a declaration of recovery based only on the state of the changed components.
SRF reported that Swisscom stopped and reversed the maintenance and that services recovered after midnight. [15] That supports the public chronology. It does not establish that every call route recovered at the same moment. A rigorous restoration record would separate fixed voice, mobile voice, calls originating on other networks, delivery to each affected alarm centre and location information. It would also record whether the alternatives remained available throughout recovery.
The February event thus resists two easy stories. It is not adequately explained as one person's mistake, because the simultaneous scope depended on organisational controls. It is not adequately excused by the existence of redundancy, because the redundancy was reportedly unavailable when needed. Accountability sits in the gap between design intent and operating behaviour.
Fallback must be independent of the failure it is meant to cover
A fallback route is useful only if it does not share the decisive failure domain. Independence can be physical, logical, administrative or organisational. Two fibre strands in one duct may share physical risk. Two devices changed under one maintenance plan may share administrative risk. Fixed and mobile access may appear diverse while sharing a routing platform. Two alarm-centre links may use different products but the same provider or facility.
The public record does not disclose enough to map those relationships for every 2020 event. It does disclose results that justify testing them. On 17 January, mobile service was offered as an alternative to the failed landline service. [18] On 11–12 February, fixed and mobile telephony were both among the affected services, and installed redundancy was reportedly unavailable after the maintenance error. [15][16] On 26 May, fixed and mobile calling were again disrupted across all Swiss regions, although emergency numbers were reported unaffected. [19]
These are not proof of one shared platform. They are evidence that access labels alone cannot establish independence. A continuity assessment must trace where fixed and mobile voice diverge, where they converge, and whether the emergency route remains separate at each critical point. The same test applies to callers on other operators, because OFCOM found that emergency access was sometimes impossible for them as well. [1]
Alarm-centre connectivity is especially important. A caller can have a healthy handset, a functioning access network and a correctly routed call, yet still fail to reach assistance if the destination connection is unavailable. OFCOM said some alarm centres became temporarily unreachable. [1] That moves resilience beyond the retail operator's edge. It requires clarity about primary and backup providers, physical and logical separation, routing control and tested failover at the receiving centre.
The 2023 OFCOM reference model later proposed an independent fallback for the Swisscom emergency platform, second-provider access for alarm centres and stronger static or dynamic routing arrangements. [8] Those proposals cannot be used as a diagram of the 2020 network. They are valuable as a later official articulation of the independence problem exposed by end-to-end emergency calling.
The practical test is simple to state and demanding to prove: if the primary component, provider, route, platform or maintenance authority fails, can the same caller still reach the correct alarm centre over a route that did not inherit that failure? A yes requires traffic evidence. A redundant label, contract clause or architecture slide is not enough.
Impact evidence must be local where the evidence is local
Emergency-call outages invite dramatic claims, but the available sources support a disciplined account. SRF reported that at least 40 calls to the Zurich emergency centre went unanswered during the 11–12 February interruption. [16] That is specific evidence of failed contact at a named centre. It is not a complete Swiss total, and it does not say what happened to every caller afterward.
OFCOM's broader record says emergency-service access was sometimes impossible for subscribers of other operators and that some alarm centres were temporarily unreachable. [1] It does not publish a complete count of attempted, answered, failed, abandoned or rerouted calls. Nor does it establish that an unsuccessful call caused a death or other specific outcome. The absence of a complete impact count must remain visible rather than being filled with assumption.
That boundary does not make the evidence trivial. Forty or more unanswered calls at one centre demonstrate that the failure crossed from platform availability into the public service. The national unknown shows an evidence deficit: without comparable data from all affected centres and originating networks, neither the full harm nor the effectiveness of fallback can be measured.
A strong incident record would preserve counts by time, originating provider, fixed or mobile access, intended alarm centre, route selected, setup result, answer result and fallback action. It would distinguish callers who retried successfully from callers who abandoned, used another network or remained unable to connect. Location-identification performance would need its own result because a connected call and a correctly located call are related but different service outcomes. Current official material treats routing and location as core emergency-call functions. [9][10]
Restoration should be measured with the same precision. Infrastructure health is evidence, but it is not the final service test. The decisive proof is that calls from the affected access types and other operators once again reached the correct alarm centres, with the required information, under realistic load. The sources do not publish that complete matrix for 2020.
Different causes can still reveal a common governance weakness
OFCOM's finding that the incidents appeared to have different causes is a constraint on the article, not an obstacle to analysis. [1] A defective component, a maintenance misjudgment and another hardware failure should not be rewritten as one technical defect. A network can nevertheless reveal a recurring governance weakness when different triggers produce serious continuity effects and the organisation cannot publicly demonstrate independent fallback and service-level recovery.
The common question is control over failure propagation. Did a component fault remain bounded? Did a change preserve an untouched fault domain? Did retries or cross-system dependencies amplify the event? Could other operators still route emergency calls? Could alarm centres receive them? Did monitoring detect failure at the transaction level? Did restoration criteria prove recovery for each service?
This framing avoids both overreach and complacency. It does not allege that Swisscom ignored a known single cause. It also does not allow different root causes to end the inquiry. Resilience exists to handle more than one trigger. The relevant evidence is whether the system and its operating model contain component failure, change error, congestion and destination loss without removing emergency reachability.
The response record is substantial but not fully inspectable
Swisscom's recorded response included a group-level task force, tighter handling of changes, closer control of critical maintenance, additional redundancy and monitoring with emergency organisations, and the Stabilo programme to identify and remove single points of failure. OFCOM described short-, medium- and long-term technical, organisational and cultural measures. [1][3]
Swisscom also commissioned two external audits. One examined system-critical platforms and operating controls; the other addressed the resilience of the emergency-call system. OFCOM received the results, held four meetings with Swisscom and contacted one of the auditors. Parliamentary oversight later addressed the principal outages, the audits, emergency redundancy and scrutiny of maintenance practices. [1][2]
That is meaningful oversight evidence. It shows that the response went beyond a press statement and that the regulator had access to material not contained in public news reports. OFCOM regarded Swisscom's analysis and response as comprehensive enough for its regulatory follow-up. [1] The parliamentary record supplies a further institutional layer. [2]
The limitation is equally important: the two underlying audit reports are not public in the available record. Readers cannot inspect their complete findings, test methods, exceptions, residual risks or evidence of closure. The record therefore supports saying that audits occurred and that OFCOM examined their results. It does not support saying that independent public scrutiny verified every corrective measure.
Swisscom's own statements about tighter change management and planned resilience work should be treated as operator claims and commitments. [3] A commitment can be specific and valuable without being proof of durability. To establish durable remediation, an assurance record would link each measure to the failure mode it addresses, the date it entered service, the test used to validate it, the result under realistic conditions and the owner of any residual risk.
Later owner-level reporting described emergency-service outages as unacceptable and said network stability remained a priority. [14] That record concerns a later reporting period and measures begun after 2020. It adds governance weight but does not retroactively establish liability or verify each technical fix. Accountability is strongest when strategic concern, operator action, regulator access and public technical evidence all point to the same tested result.
The regulatory boundary did not match the whole service chain
OFCOM's legal analysis contains a counterintuitive point. Emergency-number access was not a special obligation imposed only on Swisscom because it held the universal-service concession. The duty applied to providers of public fixed and mobile voice services. [1] The service depended on multiple providers and connections even though Swisscom's central role made its failures especially consequential.
At the same time, OFCOM said the telecommunications framework then in force did not regulate the entire chain. It did not fully govern how alarm centres were connected or establish uninterrupted-reachability controls across every part of delivery. OFCOM also identified the absence of a specific minimum quality level for emergency calls. [1] A public-safety transaction therefore crossed a regulatory perimeter that did not map neatly onto its technical perimeter.
This gap matters because accountability can dissipate at handoffs. A provider may meet duties for originating calls while an alarm-centre connection lacks equivalent resilience requirements. An alarm centre may procure a backup without controlling upstream routing. A central platform may route correctly while a transit or destination link fails. Without an end-to-end standard and shared evidence, each segment can appear compliant while the caller still cannot reach assistance.
The annual universal-service result illustrates a second mismatch. OFCOM said Swisscom still met the annual voice-availability target, and ComCom's 2020 report recorded compliance with universal-service quality criteria. [1][7] That is not a contradiction. An annual aggregate can remain above threshold even when a short, geographically broad incident disables an exceptionally critical service.
Aggregate availability is useful for measuring general service performance. It is weak as the sole measure of emergency continuity because it averages across time, users and service types. A ninety-minute emergency-number outage can be small in an annual percentage and large in public-safety significance. The correct response is not to discard the annual metric; it is to pair it with service-specific measures for emergency-call completion, alarm-centre reachability and failover performance.
OFCOM's network-fault reporting framework provides an official channel for reporting covered services, scale, cause and repair information. [11] The currently hosted technical edition should not be represented as the exact wording applicable to every report in 2020. Its relevance is evidentiary: a regulator needs timely, structured incident data in order to see patterns that an annual percentage can conceal.
A later government critical-infrastructure report explicitly treated telecommunications as critical infrastructure and referred to the 2020 Swisscom sequence as affecting life-critical emergency services. [12] This framing supports a consequence-based approach. The more society depends on a route for access to assistance, the stronger the evidence required that redundancy works during faults and maintenance.
Regulatory accountability, however, should not be confused with operational control. OFCOM can define obligations, receive reports, inspect audits and propose resilience models. It does not execute a carrier's maintenance rollback or answer calls at an alarm centre. A complete account identifies who could act at each stage and what evidence each actor owed to the others.
Later reforms illuminate the test without rewriting 2020
Follow-on policy can reveal which weaknesses institutions considered important, but it must remain in its own time. In November 2021, the Federal Council placed network reliability and emergency-number reachability explicitly within its strategic objectives for Swisscom for 2022–2025. [13] That decision is governance evidence. It is not a judicial finding, and it does not by itself show that the 2020 incidents legally caused every later objective.
The federal ownership report for 2021 described the emergency-service outages as unacceptable and recorded continuing priority for network stability. [14] Again, this is later owner-level assessment. It strengthens the public expectation around continuity while leaving the technical facts and legal boundaries of each 2020 event to their own sources.
OFCOM's 2023 reference model is the clearest later design response. It proposed an independent fallback for the emergency-call platform, a second provider for alarm-centre connections and stronger static or dynamic routing options. [8] Each element addresses a different possible common-mode failure: central platform loss, destination-provider loss and inability to redirect traffic around impairment.
The model should not be presented as proof that these controls were absent everywhere in 2020, that they were all deployed afterward or that they were retroactively required. Its value is architectural. It treats fallback independence as an end-to-end design requirement and recognises that alarm-centre access is as important as caller access.
Taken together, the later records move accountability from a general promise of reliability toward named controls: independent platforms, second-provider connections, routable alternatives and explicit emergency-reachability objectives. The remaining question is empirical. Which controls were implemented, how were they tested, and what evidence shows that they survive the same maintenance and failure conditions that defeated continuity before?
A control map makes responsibility testable
The public evidence supports a map of practical control without supplying every name. Swisscom controlled the maintenance scope described in its own account, the operation of its network components, rollback, internal monitoring, its task force, commissioned audits and announced remediation. [1][3] That makes the operator responsible for producing evidence about change boundaries, fault separation and recovery within the systems it controlled.
Other public voice providers controlled their own access networks and parts of cross-network delivery. OFCOM's finding that subscribers of other operators sometimes could not reach emergency services shows why their evidence matters even where the initial failure lay elsewhere. [1] The joint Swisscom-Sunrise congestion statement later demonstrated the operational importance of interconnection capacity, though it described a different episode. [4]
Alarm-centre authorities and their connectivity providers controlled or influenced destination access, procurement and failover, but the available sources do not disclose every contract or topology. It would be wrong to allocate a particular failure to a canton or supplier without that evidence. It is still reasonable to require proof that primary and backup centre connections are independently routed and regularly tested.
OFCOM controlled regulatory reporting and scrutiny. Parliament supplied oversight. The Federal Council, as owner-level policymaker, set later strategic expectations. [1][2][13] These institutions did not operate the failed equipment, but they controlled whether continuity requirements, reporting and assurance covered the whole public service.
This separation prevents a familiar accountability error: assigning all responsibility to the actor closest to the visible fault. The technician, component or supplier nearest the trigger may not control the risk classification, architecture, maintenance policy, alarm-centre contract or restoration declaration. Practical control is distributed, and the evidence should follow that distribution.
The evidence test for emergency-call redundancy
The Swisscom sequence supports an assurance test rather than a verdict. A national operator and the public bodies that depend on it should be able to demonstrate at least ten things.
A bounded incident ledger. Each outage should retain its own start, detection, affected services, emergency-call effect, alarm-centre effect, mitigation, restoration and verified end time. Different causes should not be merged merely because the incidents occurred close together.
A current fault-domain map. The map should identify where fixed access, mobile access, voice platforms, emergency routing, interconnection, location functions and alarm-centre connections are independent and where they converge. Sensitive details can be protected while regulators still receive enough evidence to test common-mode risk.
Consequence-based change classification. Work affecting an emergency-call dependency should be classified by credible public-safety impact as well as probability. The evidence should show who approved the classification, which components could be changed together and which route had to remain untouched.
Staged maintenance with a known-good side. A change should preserve an independently operating fault domain whenever feasible. Swisscom's own account that the February work should have been divided across two nights makes this control directly relevant. [3]
Live end-to-end failover tests. Tests should originate from fixed and mobile access, include other providers, traverse intended transit arrangements and terminate at representative alarm centres. Component health and laboratory success are not substitutes for completed service transactions.
Independent alarm-centre access. Primary and backup centre connections should not inherit the same decisive provider, facility, routing or maintenance failure. The later OFCOM reference model's second-provider proposal supplies a concrete benchmark for this question. [8]
Emergency-call observability. Operators and centres should see attempted calls, setup failures, routing outcomes, delivery and answer results quickly enough to stop harmful work. Counts should be reconcilable across originating networks and destinations while respecting lawful data controls.
Separate rollback and restoration criteria. Reversing a configuration should not automatically close an incident. Recovery requires evidence that fixed voice, mobile voice, cross-provider calls, location functions and alarm-centre delivery have returned to defined levels.
Measure-to-failure remediation. Every corrective action should name the failure mode it addresses, the owner, implementation date, validation method, exception and residual risk. Repeated testing should show that the control remains active after later network changes.
Proportionate public assurance. Full topology and security-sensitive details need not be published. The public record can still disclose the incident boundary, service effects, control failures, test categories, remediation status and unresolved limitations. The unpublished audits in this case show why a regulator's access and public reproducibility are related but different forms of assurance.
This test keeps the analysis close to operating reality. It does not ask whether an organisation has a resilience policy; it asks whether an emergency call completed when a component failed or maintenance changed the network. It does not ask whether a backup exists; it asks whether the backup remained independent and carried traffic. It does not ask whether a configuration was restored; it asks whether the public service recovered.
The test also preserves proportionality. A carrier cannot publish every configuration or security-sensitive dependency. Regulators and qualified auditors may need confidential access. But confidentiality does not require an evidence vacuum. Aggregated call-completion results, failover scope, fault-domain attestations, remediation milestones and residual-risk statements can provide meaningful assurance without exposing exploitable detail.
Finally, the test recognises change over time. An emergency network is not fixed after one audit. Platforms are upgraded, interconnections change, alarm centres move, providers consolidate, software evolves and staff turn over. A control that passed once can lose independence later. Durable assurance therefore depends on recurring exercises and current evidence, not the memory of a completed programme.
What the public record still cannot answer
The complete topology, exact components, configurations and call-routing paths for each incident are not public. The identities and decisions of change authors, assessors, approvers, incident commanders, executives and equipment suppliers are also absent. Those gaps prevent attribution to particular people or vendors.
There is no complete national count of emergency calls attempted, completed, failed, abandoned or rerouted across the sequence. The available record does not provide every alarm centre's primary and backup carrier, physical diversity, routing design or failover result. The Zurich figure remains local evidence. [16]
The two external audits supplied to OFCOM are not publicly available here. Their full findings, exceptions and remediation tests therefore cannot be independently examined. The exact cause of the 26 May outage was still under investigation in the contemporaneous report. [19]
The available public sources do not independently verify that every announced short-, medium- and long-term measure remained deployed and effective. They also do not establish negligence, sabotage, intent, individual legal liability, a death caused by an unsuccessful call or a complete financial loss. Any claim on those points would exceed the evidence.
These unknowns are not a reason to abandon accountability. They define its proper form. The evidence supports questions about practical control, proof and institutional boundaries. It does not support a courtroom verdict, a hidden-topology reconstruction or a personalised blame narrative.
Redundancy passed from engineering claim to public-safety evidence
Swisscom's early-2020 sequence did not reveal one defect that explains an entire year. It revealed several events whose consequences tested the same essential promise: when the normal voice route fails, emergency communication should continue.
The 17 January event showed that a mobile alternative could coexist with a failed fixed emergency route without proving universal fallback. The 11–12 February event showed how a low risk classification and simultaneous work on critical components could make installed redundancy unavailable. The 19 February event added a narrower hardware incident. The 26 May outage widened scrutiny of fixed and mobile calling while remaining distinct because emergency numbers were reported unaffected and the cause was then unresolved. [3][15][17][18][19]
OFCOM's end-to-end framing supplies the correct standard. Continuity must extend from caller access through provider and transit systems to routing and alarm-centre delivery. [1] Annual availability, a restored configuration or a duplicate component cannot substitute for evidence that this transaction worked.
The accountable conclusion is therefore conditional rather than accusatory. Redundancy should be accepted as public-safety protection only when separated fault domains, live failover, independent alarm-centre connections, call-completion monitoring, bounded maintenance and service-specific restoration are demonstrated. The Swisscom record made that proof—not the mere existence of backup equipment—the test.
Sources
- https://www.parlament.ch/centers/documents/fr/bericht-bakom-netzunterbrueche-swisscom-juni-2020-f.pdf
- https://www.parlament.ch/centers/eparl/curia/2021/20210004/Jahresbericht%20GPK%20und%20GPDel%202020%20F.pdf
- https://www.swisscom.ch/en/about/news/2020/03/09-network-quality-from-swisscom.html
- https://www.swisscom.ch/de/about/news/2020/03/18-gemeinsame-stellungnahme-swisscom-sunrise.html
- https://www.swisscom.ch/de/about/news/2020/08/10-piazzetta-ip-ist-alltag.html
- https://www.swisscom.ch/de/about/news/2017/04/20170427-mm-vollstaendige-umstellung-auf-ip.html
- https://www.comcom.admin.ch/dam/en/sd-web/3uaKB0xHqrHR/ComCom%20Activity%20Report%202020_EN.pdf
- https://www.bakom.admin.ch/dam/de/sd-web/KRVVW2DoIHRr/referenzmodell_notrufe.pdf
- https://www.bakom.admin.ch/de/notrufdienste
- https://www.bakom.admin.ch/de/sr-78410111313-leitweglenkung-und-standortidentifikation-der-notrufe
- https://www.bakom.admin.ch/dam/bakom/de/dokumente/tc/technologie/sr_784_101_113_18meldungvonnetzstoerungen.1.pdf.download.pdf/sr_784_101_113_18meldungvonnetzstoerungen.pdf
- https://www.bakom.admin.ch/dam/de/sd-web/1bHs9X7I6Rd1/strommangellage-bericht.pdf
- https://www.news.admin.ch/de/nsb?id=86030
- https://www.efv.admin.ch/dam/de/sd-web/n1h3DZjTLggS/Konsolidierte-Kurzberichterstattung-2021-d.pdf
- https://www.srf.ch/news/schweiz/probleme-bei-der-swisscom-wartungsarbeiten-legten-notfallnummern-lahm
- https://www.srf.ch/news/schweiz/unterbruch-bei-swisscom-notrufzentralen-aergern-sich-ueber-ausfall-des-telefonnetzes
- https://www.srf.ch/news/schweiz/ausfall-des-internets-swisscom-kaempft-erneut-mit-problemen
- https://www.swissinfo.ch/eng/business/network-down_swisscom-national-landline-crash-caused-by-faulty-part/45504680
- https://www.swissinfo.ch/ita/swisscom-risolto-il-guasto-che-ha-bloccato-la-rete/45785196
- https://www.bakom.admin.ch/de/bericht-notrufdienste
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
