1
INTRODUCTION
Global digital networking has created unforeseen possibilities, both good and bad. The state,
the private sector and society make use of information and communication infrastructure and
access to cyberspace (Internet, mobile networks and applications, e-business, egovernment, computer-based control programmes). However, this also means that
vulnerability and exposure to disruptions, manipulations and attacks have increased. Like the
benefits, the possibilities that information and communication infrastructure provides for
criminal, intelligence, terrorist or military abuse or impairment are practically unlimited. It is
likely that the underlying trend towards more networking, and thus the growing complexity of
information and communication infrastructure, will continue.
Switzerland's functioning as a holistic system (state, private sector, traffic, energy supply,
communication, etc.) depends on a growing number of mutually networked information and
communication facilities (computers and networks). This infrastructure is vulnerable.
Country-wide or long-lasting disruptions and attacks could have severe adverse effects for
Switzerland's technical, economic and administrative performance. Such attacks can be
launched by a variety of perpetrators and have various motives: individual perpetrators,
political activists, criminal organisations intent on fraud or blackmail, state spies or terrorists
who want to disrupt and destabilise the state and society. Information and communication
technologies (ICT) are particularly attractive as targets not only because they offer many
possibilities for abuse, manipulation and damage, but also because they can be used
anonymously and with little effort.
Protecting 1 information and communication infrastructure from such disturbances and attacks
is in Switzerland's national interest. Although measures have been taken in recent years to
reduce cyber risks 2, it has become evident that these have not been sufficient for all cases.
Because it is to be expected that there will be an increase in disruptions and attacks on
information and communication infrastructure (thereby affecting further facilities as well), the
Federal Council instructed the Federal Department of Defence, Civil Protection and Sport
(DDPS) on 10 December 2010 to prepare a national strategy for the protection of
Switzerland against cyber risks. This strategy is to demonstrate what these risks look like at
present, how well Switzerland is equipped to counter them, where the shortcomings lie and
how they can be eliminated in the most effective and efficient manner. This national strategy
for the protection of Switzerland against cyber risks is the result of that work 3.
1
This refers to all measures to protect information and communication infrastructure against unauthorised
penetration and impairment of its functions, but not the fight against the dissemination of illegal content such
as child pornography. The focus is on technical aspects, not on debating content such as false and misleading
information and propaganda.
2
Risks are defined according to the extent of damage expected and the likelihood of threats and dangers occurring. Both are taken into account in the strategy.
3
The strategy takes into account various parliamentary procedural requests calling for stronger measures
against cyber risks: 08.3100 – Burkhalter motion: National strategy for fighting Internet crime; 08.3101 – Frick
postulate: Protecting Switzerland more effectively against cyber crime; 10.3136 – Recordon postulate: Analysis of the cyber war threat; 10.3625 – SKI-NR motion: Measures against cyber war; 10.3910 – postulate of the
FDP – The Liberals: management and coordination unit for cyber threats; 10.4102 – Darbellay postulate: Concept to protect Switzerland's digital infrastructure.
5/42