methods can also be used in order to attack industrial control systems 5 in a targeted manner
using malware that has been specifically developed for that purpose.
Attackers enjoy several advantages in cyberspace, enabling them to protect themselves and
their attacks from (early) discovery and (successful) prosecution: anonymity, geographic
distance, legal barriers, eradication of traces by forging technical data and the increasing
technical complexity of their methods of attack. Based on the identified methods and tools, it
is often impossible to unambiguously attribute attacks to the perpetrators and conclude what
their motives are. All attackers have the same methods and tools at their disposal, but these
can serve various purposes and serve other clients.
The most frequent cyber attacks can be carried out by attackers quite simply, as the
resources and technical know-how required can often be obtained easily and at low cost.
Most attacks are uncoordinated acts of vandalism, espionage and fraudulent acts online that
usually cause only limited damage (e.g. reputational damage) and can be remedied quite
easily. Although protection against such attacks is important, this strategy focuses
particularly on attacks with the potential for greater damage that can directly or indirectly
severely compromise the ability of the private sector, state and society to function properly.
More major damage can also be inflicted with specific attacks on particularly well-protected
targets. Such attacks are much more costly and require substantially more effort.
It is unrealistic to think that absolute protection against cyber attacks can be achieved. That
is why it is essential for reactive and preventive capabilities to be in harmony; these
capabilities have to be geared towards an approach aimed at minimising risks, limiting
damage and restoring the initial situation.
2.2
Players and motives
The perpetrators are individuals, groups and states. They differ significantly in their intentions
and in their technical and financial resources.
State or state-financed players generally have greater financial, technical and personnel
resources and are better organised, which explains their relatively high potential for doing
damage. With their attacks, they seek to spy on, blackmail or compromise a state, individual
authorities, the armed forces, the private sector or research institutions. They can also be
intent on acting in other ways against national or economic interests in order to pursue
political power and economic interests. Foreign companies, institutions and persons in
Switzerland are also at risk.
In October 2009, espionage malware was discovered in the Federal Department of
Foreign Affairs. It reached the network via e-mail and remained undetected for a long
time. The armament companies RUAG and Mowag were attacked in a similar manner
a few years earlier. In June 2010, Stuxnet malware was discovered. It had allegedly
been developed to damage Iran's uranium enrichment plants by inserting a software
error in their SCADA systems. Because of its technical complexity, it is assumed that
only state players could have launched this attack.
5
Internationally, so-called SCADA systems (Supervisory Control and Data Acquisition) are talked about. These
ICT systems are used for monitoring and controlling technical processes.
10/42