National strategy for the protection of Switzerland against cyber risks 2018-2022 2 Background The first step towards effective protection of Switzerland against cyber risks is to assess the current and future threat situation. The goal is not to precisely calculate the risks for Switzerland, but rather to assess the strategic importance of the various threats and to develop an outlook on probable trends in their development. In addition to the threat situation, the current status of Switzerland's protection against cyber risks is the second major factor in determining the background. The future need for action becomes apparent when the threat situation and its future development are compared with the existing arrangements for protecting Switzerland against cyber risks. 2.1 The cyber threat situation To clarify the origin of cyber risks, the main threats to Switzerland are described. It should be noted that the threats are developing very dynamically. The most important drivers are digitalisation, which is making our society and economy increasingly vulnerable to disruptions and failures of ICT systems, as well as the intensified threat situation due to the observed professionalisation of attackers and the expansion of power politics into cyberspace. Given that these trends are expected to continue, the threat situation will likely intensify further. In order to assess the situation, it is important to distinguish between threats from intentional, unauthorised acts (cyber attacks) and threats from unintentional events (human error and technical failures). These threats are accordingly described in separate sections below. 2.1.1 Cyber attacks Threats from cyber attacks have risen sharply in recent years. Successful attacks in Switzerland and abroad with sometimes serious consequences have shown that not only are the frequency and complexity of cyber attacks increasing, but that they are also increasingly being used in a targeted manner against states and companies. In view of the large number of possible cyber attacks, it is important to distinguish between different phenomena in order to assess the situation. Distinguishing criteria are the purpose of the attacks, the actors behind the attacks, and the circle of those affected. On this basis, five types of cyber attacks can be distinguished, while it should be noted that they often occur in combination and that there is overlap among them. Cybercrime: In a narrower sense, cybercrime refers to criminal offences that are committed with the help of ICT or that exploit the vulnerabilities of these technologies and are thus only possible because of ICT. In a broader sense, cybercrime also includes all criminal offences in which ICT is used as a means of perpetration or storage medium, but which would also be possible without the use of ICT. Distinguishing it from the threats described below, cybercrime is characterised by the motive of enrichment. Cyberspace is well suited for this, given that the risk for perpetrators is low and substantial profits can be made due to the large number of easily accessible victims. It is therefore not astonishing that cybercrime has increased sharply in recent years. It equally affects businesses, authorities and the public, and is the threat most likely to occur. Since the aim of the attackers is not to endanger the functioning of society, the economy or the state as such, the direct impact is often limited to the victims concerned. However, cyber criminals accept high collateral damage or even exploit the fear of such damage to extort higher sums from the victims. For this reason, attacks by cyber criminals entail a high potential for damage to society and the economy as a whole. Veritable lines of business arise in the field of cybercrime with the potential to generate a lot of money. Due to intense competition but also the constant upgrading of defensive measures, the pressure for innovation among criminal actors is high, which is why attackers are constantly developing new methods. Accordingly, a further increase in the frequency and 3

Select target paragraph3