3 EXISTING STRUCTURES This section sets out the structures Switzerland already has for reducing cyber risks, as well as the roles of the individual players. 3.1 Private sector and operators of critical infrastructure Those concerned 7 Switzerland as a business location is characterised by a strong service sector. Trade relations and other business activities are based on information and communication infrastructure along the entire value added chain. Data is stored and processed on companyowned and external computers. Communication and payment transactions are based on Internet services (e.g. e-mail, Internet telephony, e-banking and stock exchange trading). Contracts are increasingly concluded electronically (Internet trading, tender procedures, etc.). This illustrates the extent of our private sector's dependency on correctly functioning ICT and other critical infrastructure such as power supply. Consequently, protection against cyber risks is of national importance for Switzerland as a business location. Critical infrastructure ensures the availability of essential goods and services. Extensive disruptions or breakdowns of such infrastructure would have serious implications for the functioning of the state, the private sector and society. Protecting critical infrastructure – including against cyber risks – is thus important. CI operators cannot regard the risks merely according to purely economic principles; they have to make further-reaching efforts to minimise the risks. This is why they are already subject to some special rules; however, concrete and binding requirements regarding protection standards for the ICT used are generally missing. Depending on the criticality and vulnerability of given infrastructure, as well as the threat situation, requirements for security standards and other risk-reduction measures should be set more comprehensively and precisely in association with the competent public authorities. The manufacturers and providers of ICT products and services bear significant responsibility for the security of their products and thus also for the cyber security of their clients. For the most part, private sector players act under their own responsibility and at their own discretion. In order to gain an overview, companies selected for preparing the strategy were questioned on their current assessments, measures and difficulties, as well as their outlook for the future with regard to cyber security. Perception of the problem Cyber risks are indisputably a major issue for companies. However, the risk assessments and measures taken differ considerably not only from one sector of the economy to another, but also within sectors and branches, as well as within companies themselves. Consequently, it is not possible to have a simple sector-specific classification of the perception of the problem. 7 The DDPS questioned representatives from the private sector and operators of critical infrastructure (incl. umbrella organisations and associations) about the measures they are taking or have already taken, where deficiencies and difficulties lie and what factors influence their protective measures (e.g. financial considerations). The surveys gave a uniform picture on the whole. 12/42

Select target paragraph3