National strategy for the protection of Switzerland against cyber risks 2018-2022 - - improved. Focus on the protection of critical infrastructures: The NCS measures mainly related to the protection of critical infrastructures. Risk and vulnerability analyses were carried out for the critical sub-sectors, measures were identified, support in the event of incidents was expanded, and a picture of the situation of cyber threats was developed. This work formed the core of the NCS and can now be deepened and expanded. Strengthening cooperation with third parties: In addition to improving coordination within the administration, cooperation with other partners is also important. The NCS has strengthened cooperation with the cantons, the private sector and various international partners. The establishment of these cooperation arrangements has strengthened mutual trust and promoted the exchange of information. This provides a good basis for further deepening and expanding cooperation at all levels. 2.2.2 Strategic context Various strategies of the federal government define guidelines that are relevant to the topic of cyber risks. They form the strategic context for the protection of Switzerland against cyber risks. The basic strategies are: - - - Federal Council report on Swiss security policy: In the Security Policy Report 2016, the Federal Council defines the basic strategic orientation of Switzerland's security policy. The report explains the major and growing significance of cyber threats for security policy and defines important terms in the context of the issue. The report refers to the NCS as the basis for protecting Switzerland against cyber risks and emphasises that the protection of ICT systems and infrastructures must play an even greater role in future security policy. Federal Council strategy for a digital Switzerland: The strategy shows how Switzerland intends to take advantage of the opportunities offered by digitalisation. One of the core strategic objectives is to create transparency and security so that the people of Switzerland are able to exercise self-determination in regard to the information that concerns them. The prerequisite for this is that the state continues to perform its responsibility of protecting society and the economy in the digital age. In addition, the strategy and the associated action plan define the objectives and measures for positioning Switzerland in the field of digitalisation and the associated transformation processes in the international context. In the area of cyber security, this is to be achieved in particular through implementation of the NCS. National strategy for critical infrastructure protection: The CIP strategy defines the term "critical infrastructures" and sets out which sectors and sub-sectors are considered critical in Switzerland. It contains measures aimed at improving Switzerland's resilience with regard to critical infrastructures. The NCS covers all risks for critical infrastructures in the cyber area. 2.3 Need for action: Necessary further development of the NCS The objectives achieved as defined in the first NCS and the strategic context form the basis for further work. But the comparison between the current threat situation and its expected development with the existing arrangements for protecting Switzerland against cyber risks clearly shows that maintaining the status quo is not sufficient to ensure an adequate level of protection. There is a need for action at various levels. On the one hand, the aim is to further expand existing capacities and capabilities and to make use of the processes, structures and foundations created for the implementation of the measures. On the other hand, strategic adjustments must also be made. The NCS must become more effective as a national 6

Select target paragraph3