4 4.1 SYSTEM FOR PROTECTING AGAINST CYBER RISKS Overriding goals The Federal Council recognises that the cyber problem is primarily linked to its influence on existing tasks and responsibilities of authorities, the private sector and society. Minimising cyber risks is thus a matter for the relevant responsible parties. The Federal Council wishes to promote the opportunities and advantages cyberspace entails for Switzerland's economy, politics and population. However, it also notes that developments in this area are associated with risks, and that corresponding measures to minimise these are necessary. This national strategy governs the application of the described measures in times of peace and thus explicitly excludes war. With the national strategy for the protection of Switzerland against cyber risks, the Federal Council pursues the following overriding goals:  Cyber risks are to be recognised and evaluated at an early stage in order for risk reducing and preventive measures to be taken in cooperation with all those involved in the private sector, political circles and society  The resilience of critical infrastructure to cyber attacks – in other words, the ability to resume normal operations as quickly as possible – is to be increased in cooperation with their operators, ICT service providers, system suppliers and the Confederation's programme to protect critical infrastructure (CIP programme)  Prerequisites are to be ensured for an effective reduction of cyber risks, particularly, cyber crime, cyber espionage and cyber sabotage, and where necessary created anew These goals can be achieved in the existing decentralised structures in various ways. In any case, acting with personal responsibility in the different private sector areas as well as dialogue and cooperation between the private sector and the authorities are essential prerequisites. The exchange of information on a permanent basis should create transparency and trust, and the state should intervene only if public interests are at stake and if acting in accordance with the principle of subsidiarity. Dealing with cyber risks is an interdisciplinary task that has to be assumed by the private sector, CI operators, ICT service providers, system suppliers, as well as cantonal and federal authorities. This must be understood as part of an integrated business, production or administration process. All players from the administrative and technical levels up to the strategic and political levels must be included in these processes. An effective approach to dealing with dangers and threats stemming from the Internet presupposes recognition that existing tasks and responsibilities of authorities, the private sector and the population have cyber aspects. Every organisational unit in political circles, the private sector and society bears responsibility for recognising these cyber aspects and integrating the resulting risks in their processes in order to reduce them. To this end, the existing decentralised structures should have the necessary powers and possibly be strengthened in order to fully assume the cyber-specific aspects of their tasks and responsibilities. 28/42

Select target paragraph3