Findings
The structures at federal level for handling cyber risks have been organised in a
decentralised manner up to now. Relatively little has been spent and the resources are often
insufficient for assuming additional tasks. Tasks are usually assigned to those organisational
units whose mandates have significant cyber aspects. This approach has the great
advantage that precisely those units required for managing an incident can be involved on a
case-by-case basis. As every attack on ICT infrastructure is different, this flexible form of
emergency organisation is of key significance and corresponds to the assumption that the
cyber problem is not a distinct phenomenon, but has to be dealt with within the framework of
existing processes. Furthermore, this approach promotes synergies and prevents the
establishment of complex bodies before a problem and its actual magnitude have been
clarified. The existing system thus works well from a reactive viewpoint. Certain anticipatory
and preventive capabilities exist, but they are insufficient (e.g. human and financial
resources; sharing of intelligence, technical and police information in support of the private
sector, CI operators, ICT service providers, system suppliers and research; risk analyses and
the ensuing definition of security requirements, sustainability). It is thus understood that the
decentralised structures at federal level have to be reinforced and possible synergies have to
be used more effectively in order to be able to identify cyber risks comprehensively and to
meet the requirements during major cyber attacks and disruptions.
3.3
Cantons
Like the private sector, the cantons are also very heterogeneous. There are cantons that are
hardly larger than medium-sized cities based on their population. There are also substantial
economical and structural differences. The services they provide and their structures and
activities (e.g. health, transport, energy) thus vary just as much as their needs regarding
dealing with dangers and threats. Consequently, it is understandable that not all cantons
have the same qualitative and quantitative ability to combat risks, particularly those in
cyberspace.
Within their territory, the cantons are responsible for maintaining public order and safety.
Only those cantons that have a large police force and cultivate close ties with the private
sector and organisations active in the security field (e.g. customs, security services of
neighbouring countries) are capable of anticipating problems in the area of cyber crime,
collecting the necessary information and conducting extensive investigations. However, no
canton is in a position to do this systematically. All cantons are thus dependent on subsidiary
support from the Confederation, particularly for coordination and intelligence issues.
The cantons' preventive measures for minimising cyber risks are a necessary part of a
comprehensive concept, as each canton operates critical infrastructure. Most of them have
organisational and control structures, security delegates in various services, forensic IT
police or specialised management cells for a crisis situation. Like at the federal level, these
means are often inadequately coordinated and are insufficient for comprehensively
countering current cyber risks. The problem is aggravated in smaller cantons, which are
often forced to delegate specific services to third parties.
Furthermore, the legal regulations with regard to information technologies are frequently
either insufficient or not well-known enough. Classification systems (internal, confidential,
21/42