system suppliers is not systemised enough. In addition, synergies between existing public
authority units must be better utilised, and the reporting systems and lines of communication
must be examined with regard to the exchange of information and its efficiency. Furthermore,
there is a lack of risk analyses and definitions for ICT infrastructure security requirements
derived from such analyses, as well as the ensuing distribution of responsibilities and
additional costs.
Too often, the Internet is still regarded as a legal vacuum by a whole range of players and
day-to-day security in its use is insufficient. In particular, criminal prosecution authorities do
not always have sufficient means and capabilities to take efficient action against offences. In
addition, the interfaces and the exchange of information with preventive units in the area of
minimising cyber risks have not been clarified enough in order to achieve a successful mix of
preventive and repressive measures.
Overall, it can be noted that the current system is scarcely in a position to actively ward off
major, targeted cyber attacks or to eliminate their consequences in the necessary timeframe
if they are severe. The companies and CI operators questioned are therefore calling for
minimum security requirements to be defined and implemented in conjunction with the
authorities and for the measures to improve the security situation, deal with attacks and raise
awareness to be better coordinated. Moreover, the Confederation is also being asked to
institutionalise the exchange of information, provide a comprehensive and up-to-date picture
of the cyber situation, and ensure more extensive subsidiary support.
The various legal foundations in existence reflect the cyber aspects of existing tasks and
responsibilities. Accordingly, a solution in the form of a single cyber-specific act is
inappropriate. The existing body of laws therefore has to be adapted on an ongoing basis to
cyberspace developments within their scope by means of revisions.
Furthermore, increasing international networking and cooperation to minimise cyber risks can
be observed.
Based on this recognised need for action, this strategy proposes a series of concrete
measures, which are presented below.
27/42