Findings The structures at federal level for handling cyber risks have been organised in a decentralised manner up to now. Relatively little has been spent and the resources are often insufficient for assuming additional tasks. Tasks are usually assigned to those organisational units whose mandates have significant cyber aspects. This approach has the great advantage that precisely those units required for managing an incident can be involved on a case-by-case basis. As every attack on ICT infrastructure is different, this flexible form of emergency organisation is of key significance and corresponds to the assumption that the cyber problem is not a distinct phenomenon, but has to be dealt with within the framework of existing processes. Furthermore, this approach promotes synergies and prevents the establishment of complex bodies before a problem and its actual magnitude have been clarified. The existing system thus works well from a reactive viewpoint. Certain anticipatory and preventive capabilities exist, but they are insufficient (e.g. human and financial resources; sharing of intelligence, technical and police information in support of the private sector, CI operators, ICT service providers, system suppliers and research; risk analyses and the ensuing definition of security requirements, sustainability). It is thus understood that the decentralised structures at federal level have to be reinforced and possible synergies have to be used more effectively in order to be able to identify cyber risks comprehensively and to meet the requirements during major cyber attacks and disruptions. 3.3 Cantons Like the private sector, the cantons are also very heterogeneous. There are cantons that are hardly larger than medium-sized cities based on their population. There are also substantial economical and structural differences. The services they provide and their structures and activities (e.g. health, transport, energy) thus vary just as much as their needs regarding dealing with dangers and threats. Consequently, it is understandable that not all cantons have the same qualitative and quantitative ability to combat risks, particularly those in cyberspace. Within their territory, the cantons are responsible for maintaining public order and safety. Only those cantons that have a large police force and cultivate close ties with the private sector and organisations active in the security field (e.g. customs, security services of neighbouring countries) are capable of anticipating problems in the area of cyber crime, collecting the necessary information and conducting extensive investigations. However, no canton is in a position to do this systematically. All cantons are thus dependent on subsidiary support from the Confederation, particularly for coordination and intelligence issues. The cantons' preventive measures for minimising cyber risks are a necessary part of a comprehensive concept, as each canton operates critical infrastructure. Most of them have organisational and control structures, security delegates in various services, forensic IT police or specialised management cells for a crisis situation. Like at the federal level, these means are often inadequately coordinated and are insufficient for comprehensively countering current cyber risks. The problem is aggravated in smaller cantons, which are often forced to delegate specific services to third parties. Furthermore, the legal regulations with regard to information technologies are frequently either insufficient or not well-known enough. Classification systems (internal, confidential, 21/42

Select target paragraph3