National strategy for the protection of Switzerland against cyber risks 2018-2022 1 Introduction Switzerland is in the process of digitalisation. Comprehensive digital interconnectivity is already a characteristic of our society, economy and state, and rapid technological progress will continue to drive this development. This process opens up great opportunities, and Switzerland is willing to use these to secure and expand welfare in our country for the long term. However, it must be borne in mind that digitalisation brings not only opportunities but also risks. The associated, increasing dependence on information and communication technologies (ICT) makes our country more vulnerable to breakdowns, disruptions and misuse of these technologies. How relevant this vulnerability is can be seen with regard to the development of threats in cyberspace. Rampant cybercrime, the accumulation of espionage activities with the help of cyber attacks, cases of cyber sabotage against critical infrastructures such as hospitals and energy providers, the spread of stolen or manipulated information for the purpose of disinformation and propaganda, and the increase in hybrid forms of conflict in which cyber attacks are used to destabilise states and societies make clear how diverse these threats are and how rapidly they are developing. The combination of the increased dependence on functioning ICT and the intensified threat situation means that the resulting risks, which we refer to as cyber risks, must necessarily be taken into account in the development of the digital society. From the perspective of security policy, measures must be taken to safeguard the independence and security of the country from emerging or intensifying threats and dangers in cyberspace. From the perspective of economic and social policy, Switzerland must protect itself from cyber risks in order to be able to make consistent use of the opportunities offered by digitalisation and to maintain its locational advantage as a safe and secure country. However, complete protection against cyber risks cannot be achieved with proportionate measures. Switzerland must therefore increase its resilience to cyber incidents. The national strategy for the protection of Switzerland against cyber risks (NCS) presented here sets out how these goals are to be achieved by 2022. It builds on the first NCS implemented from 2012 to 2017; further develops it in line with Switzerland's vulnerabilities, the significantly changed and intensified threat situation since 2012, and the foreseeable future development thereof; and it supplements it with further measures. It thus provides the strategic framework for improving prevention, early identification, response, and resilience in all areas relevant to cyber risks. Protection against cyber risks is a joint responsibility of the private sector, society and the state. This means firstly that all actors are responsible for their own protection. The NCS supports and coordinates these individual protection efforts. Beyond this, it formulates additional measures where cyber risks have a significant impact on the development and welfare of our society. This joint responsibility also gives rise to shared implementation of the NCS. The federal government, the cantons, the private sector and society should implement the NCS measures in close cooperation with each other and contribute their respective competencies. The challenges in dealing with cyber risks are great, and they will continue to be virulent. This makes it all the more important that all players approach these challenges together and in a coordinated manner. Effective cooperation of all competent bodies to the extent possible and systematic international networking are crucial to creating a secure environment for the digitalisation of society and the economy. The NCS 2018-22, which was jointly developed by the federal government, the cantons and the private sector, is intended to serve as an instruction manual and guidance in this regard. The implementation plan, which is part of the strategy, defines the competencies and implementation responsibilities for the measures determined in the strategy. 2

Select target paragraph3