National Cyberstrategy (NCS)
1 Introduction
Cybersecurity has become a crucial issue at all levels. It is a key component of security
policy, an essential prerequisite for digitalisation, a central factor in data protection, an
opportunity for Switzerland as a business and research location, and an increasingly
important element of foreign policy. However, as well as affecting these public-policy issues,
it has long since become a factor in the daily interaction of all citizens with digital
technologies. It follows from this that a national cybersecurity strategy must take into account
a wide range of issues and measures. At the same time, a strategy must aim to sort and
weight this broad array of topics and relate them to one another. As a first step in that
process, this introductory chapter describes the different threats to be countered. Secondly, it
sets out the basis on which the strategy is built. Cybersecurity is no longer a new issue, and
some groundwork has already been done in Switzerland. It is important to build on this work,
but at the same time to challenge and supplement it where necessary. Thirdly, it describes
where the responsibilities lie. Given the cross-cutting nature of cybersecurity, this has
repeatedly proven to be one of the major challenges.
1.1 The cyberthreat situation
In this strategy, a cyberthreat is defined as a circumstance that has the potential to cause a
cyberincident. A cyberincident is in turn defined as an event, involving the use of information
and communication technology (ICT) resources, that adversely affects the confidentiality,
availability or integrity of information or the traceability of its processing. Based on these
definitions, a wide range of possible cyberthreats can be pinpointed. These are set out
below. In order to identify suitable countermeasures, a systematic overview of those factors
that directly influence the cyberthreat situation is also necessary.
Threat from cyberattacks
Cyberattacks are cyberincidents that are intentionally caused. Protection against such
threats is a key objective of cybersecurity measures. This is vital because the threat from
cyberattacks has been persistently high for years and the dependence of the economy and
society on functioning ICT environments continues to grow. Given the multiplicity of possible
cyberattacks, it is important to distinguish between different phenomena in order to assess
the situation and the potential mechanisms for dealing with it. Key criteria in this regard are
the purpose of the attacks, the actors behind the attacks, and those affected. On this basis,
five types of cyberattacks can be distinguished, although it should be noted that they often
occur in combination and that there are overlaps between them.
Cybercrime: As distinct from the threats described below, cybercrime primarily covers
offences against property. Cybercrime encompasses all criminal acts and omissions in
cyberspace. A distinction is made between "cybercrime" and "digitalised crime".
"Cybercrime" refers to offences that target the internet, information technology systems or
their data and require technical investigative work on the part of the prosecution authorities.
"Digitalised crime" refers to offences that until now have predominantly been committed in
the analogue world. Due to increasing digitalisation, traditional offences are increasingly
being committed using information technology.
Cybercrime is the threat most likely to occur. Since the aim of the attackers is not to
endanger the functioning of society, the economy or the state as such, the direct impact is
usually limited to the victims concerned. However, cybercriminals are prepared to accept
high collateral damage or will exploit the possibility of such damage to extort higher sums
from the victims. For this reason, attacks by cybercriminals entail a high potential for damage
to society and the economy as a whole.
4