National strategy for the protection of Switzerland against cyber risks 2018-2022 order to prevent such activities, Switzerland must therefore include cyber defence and cyber diplomacy in its preparations for potential conflict. 2.1.2 Human error and technical failures In addition to targeted and intentional cyber attacks, unintentional actions or natural and technological events may also lead to damage in cyberspace or the physical environment. These events are caused by human error in the provision and use of ICT (e.g. improper or careless use of ICT systems, faulty administration or configuration, loss of data carriers, etc.) or by technical failures, which in turn can have various causes (e.g. aging infrastructure or natural events, overuse, faulty design, inadequate maintenance). Events of this kind occur frequently with varying degrees of magnitude and are part of the everyday life of ICT departments in businesses and public authorities. Accordingly, the effects of these errors and failures can generally be controlled relatively well. Nevertheless, experience has shown that many major cyber incidents are not the result of targeted attacks, but rather of a chain of different circumstances such as human error or technical failure combined with inadequate preparation. Preventive measures against such events must therefore not be neglected in the planning and implementation of protective measures. Cyber risks due to human error or technical failures will remain very significant. The increasing complexity due to the networking of a wide range of areas also makes it difficult to estimate and limit the impact of these unintended events. Good preparation and precautionary planning for such incidents therefore remain key elements in dealing with cyber risks. 2.2 Current status of protection against cyber risks in Switzerland The basis for the work to date was the first NCS, which was adopted in 2012 and implemented by the end of 2017. But the strategic context of the NCS must also be taken into account. Various strategies of the federal government have a direct influence on how Switzerland protects itself against cyber risks and thus establish the framework for further work. 2.2.1 National strategy for the protection of Switzerland against cyber risks 2012-2017 The first NCS comprised 16 measures which were implemented in a decentralised manner by the competent organisational units in the Federal Administration in cooperation with associations and operators of critical infrastructures. The results of the NCS are described in detail in the MCS evaluation report.1 In order to assess the background for the NCS 2018-22, the following objectives achieved by the NCS are important: - - 1 Building capacities, capabilities and knowledge: A key concern of the NCS was the development of capacities, capabilities and knowledge in the competent organisations. In 2012, it was determined that many areas lack the necessary resources and expertise. Thanks to the implementation of the NCS measures, the situation has improved. Building processes, structures and foundations: Because cyber risks affect many different actors, it was very important to organise cooperation among the various bodies, to allocate responsibilities, and to develop the foundations. The planned processes, structures and foundations have been created and must now be used and continuously https://www.isb.admin.ch/isb/de/home/themen/cyber_risiken_ncs/ncs_strategie2012/wirksamkeitsueberpruefung.html 5

Select target paragraph3