methods can also be used in order to attack industrial control systems 5 in a targeted manner using malware that has been specifically developed for that purpose. Attackers enjoy several advantages in cyberspace, enabling them to protect themselves and their attacks from (early) discovery and (successful) prosecution: anonymity, geographic distance, legal barriers, eradication of traces by forging technical data and the increasing technical complexity of their methods of attack. Based on the identified methods and tools, it is often impossible to unambiguously attribute attacks to the perpetrators and conclude what their motives are. All attackers have the same methods and tools at their disposal, but these can serve various purposes and serve other clients. The most frequent cyber attacks can be carried out by attackers quite simply, as the resources and technical know-how required can often be obtained easily and at low cost. Most attacks are uncoordinated acts of vandalism, espionage and fraudulent acts online that usually cause only limited damage (e.g. reputational damage) and can be remedied quite easily. Although protection against such attacks is important, this strategy focuses particularly on attacks with the potential for greater damage that can directly or indirectly severely compromise the ability of the private sector, state and society to function properly. More major damage can also be inflicted with specific attacks on particularly well-protected targets. Such attacks are much more costly and require substantially more effort. It is unrealistic to think that absolute protection against cyber attacks can be achieved. That is why it is essential for reactive and preventive capabilities to be in harmony; these capabilities have to be geared towards an approach aimed at minimising risks, limiting damage and restoring the initial situation. 2.2 Players and motives The perpetrators are individuals, groups and states. They differ significantly in their intentions and in their technical and financial resources. State or state-financed players generally have greater financial, technical and personnel resources and are better organised, which explains their relatively high potential for doing damage. With their attacks, they seek to spy on, blackmail or compromise a state, individual authorities, the armed forces, the private sector or research institutions. They can also be intent on acting in other ways against national or economic interests in order to pursue political power and economic interests. Foreign companies, institutions and persons in Switzerland are also at risk. In October 2009, espionage malware was discovered in the Federal Department of Foreign Affairs. It reached the network via e-mail and remained undetected for a long time. The armament companies RUAG and Mowag were attacked in a similar manner a few years earlier. In June 2010, Stuxnet malware was discovered. It had allegedly been developed to damage Iran's uranium enrichment plants by inserting a software error in their SCADA systems. Because of its technical complexity, it is assumed that only state players could have launched this attack. 5 Internationally, so-called SCADA systems (Supervisory Control and Data Acquisition) are talked about. These ICT systems are used for monitoring and controlling technical processes. 10/42

Select target paragraph3