National strategy for the protection of Switzerland against cyber risks 2018-2022
-
-
improved.
Focus on the protection of critical infrastructures: The NCS measures mainly related
to the protection of critical infrastructures. Risk and vulnerability analyses were carried
out for the critical sub-sectors, measures were identified, support in the event of incidents
was expanded, and a picture of the situation of cyber threats was developed. This work
formed the core of the NCS and can now be deepened and expanded.
Strengthening cooperation with third parties: In addition to improving coordination
within the administration, cooperation with other partners is also important. The NCS has
strengthened cooperation with the cantons, the private sector and various international
partners. The establishment of these cooperation arrangements has strengthened mutual
trust and promoted the exchange of information. This provides a good basis for further
deepening and expanding cooperation at all levels.
2.2.2 Strategic context
Various strategies of the federal government define guidelines that are relevant to the topic
of cyber risks. They form the strategic context for the protection of Switzerland against cyber
risks. The basic strategies are:
-
-
-
Federal Council report on Swiss security policy: In the Security Policy Report 2016,
the Federal Council defines the basic strategic orientation of Switzerland's security policy.
The report explains the major and growing significance of cyber threats for security policy
and defines important terms in the context of the issue. The report refers to the NCS as
the basis for protecting Switzerland against cyber risks and emphasises that the
protection of ICT systems and infrastructures must play an even greater role in future
security policy.
Federal Council strategy for a digital Switzerland: The strategy shows how
Switzerland intends to take advantage of the opportunities offered by digitalisation. One
of the core strategic objectives is to create transparency and security so that the people
of Switzerland are able to exercise self-determination in regard to the information that
concerns them. The prerequisite for this is that the state continues to perform its
responsibility of protecting society and the economy in the digital age. In addition, the
strategy and the associated action plan define the objectives and measures for
positioning Switzerland in the field of digitalisation and the associated transformation
processes in the international context. In the area of cyber security, this is to be achieved
in particular through implementation of the NCS.
National strategy for critical infrastructure protection: The CIP strategy defines the
term "critical infrastructures" and sets out which sectors and sub-sectors are considered
critical in Switzerland. It contains measures aimed at improving Switzerland's resilience
with regard to critical infrastructures. The NCS covers all risks for critical infrastructures in
the cyber area.
2.3 Need for action: Necessary further development of the
NCS
The objectives achieved as defined in the first NCS and the strategic context form the basis
for further work. But the comparison between the current threat situation and its expected
development with the existing arrangements for protecting Switzerland against cyber risks
clearly shows that maintaining the status quo is not sufficient to ensure an adequate level of
protection. There is a need for action at various levels. On the one hand, the aim is to further
expand existing capacities and capabilities and to make use of the processes, structures and
foundations created for the implementation of the measures. On the other hand, strategic
adjustments must also be made. The NCS must become more effective as a national
6