situation and take crisis management measures 8. Unfortunately, detected cyber attacks are often kept secret, thereby depriving other potential victims of a timely warning. The companies and CI operators questioned are calling for forms of cooperation that would largely be based on voluntary participation. While individual responsibility remains central, cooperation should help to close gaps jointly and to obtain situation-relevant information in order to enhance one's own risk management. Over the past few years, progress has been made in terms of cooperation between CI operators, ICT service providers, system suppliers and the Confederation to reduce cyber risks. There is cooperation for long-term strategic planning, risk analysis and continuity management, primarily with the Federal Office for National Economic Supply, the cantons, critical infrastructure components, ICT service providers and system suppliers. In addition, there is a functioning public private partnership (PPP) between the Confederation's Reporting and Analysis Centre for Information Assurance (MELANI), the cantons and the private sector, whereby MELANI assists CI operators in Switzerland with their information assurance processes and promotes the exchange of information on cyber attacks between companies. Due to scarce human resources, MELANI's basic mandate can be accomplished only to a limited extent. Consequently, it is necessary to address as a matter of priority the extent to which MELANI is to cover the growing support needs of infrastructure operators in the future and the implications this will have on its resources. Tight profit margins and intense international competition mean it is impossible to set more stringent security requirements that apply only to Switzerland. The additional costs generated would put the Swiss economy at a competitive disadvantage. It is thus expected that protective requirements and implementation solutions are to be developed in an international context. International cooperation is to be intensified not only in the area of standards and regulations, however, but also with regard to risk identification and joint crisis management. This process should include not only state players, but also private sector representatives (especially CI operators, ICT service providers and system suppliers) and society in general. The lack of specialists and the acquisition and retention of expertise are a great challenge. The companies and CI operators questioned expect the research and development of expertise, along with the recruitment and training of specialists, to be promoted. 3.2 Confederation In recent years, the Confederation has taken various measures to strengthen the Federal Administration's security system and means to counter cyber attacks. At the federal level, various units are responsible for addressing preventive and reactive tasks in the area of cyber security: Office of the Attorney General of Switzerland (OAG) 8 Cf. study entitled "The evaluation and development of the Reporting and Analysis Centre for Information Assurance in Switzerland (MELANI)", published by the ETH Zurich in 2010. The study examines the effectiveness of MELANI, compares it with international information assurance models and derives development opportunities and recommendations. 14/42

Select target paragraph3