3
EXISTING STRUCTURES
This section sets out the structures Switzerland already has for reducing cyber risks, as well
as the roles of the individual players.
3.1
Private sector and operators of critical infrastructure
Those concerned 7
Switzerland as a business location is characterised by a strong service sector. Trade
relations and other business activities are based on information and communication
infrastructure along the entire value added chain. Data is stored and processed on companyowned and external computers. Communication and payment transactions are based on
Internet services (e.g. e-mail, Internet telephony, e-banking and stock exchange trading).
Contracts are increasingly concluded electronically (Internet trading, tender procedures,
etc.). This illustrates the extent of our private sector's dependency on correctly functioning
ICT and other critical infrastructure such as power supply. Consequently, protection against
cyber risks is of national importance for Switzerland as a business location.
Critical infrastructure ensures the availability of essential goods and services. Extensive
disruptions or breakdowns of such infrastructure would have serious implications for the
functioning of the state, the private sector and society. Protecting critical infrastructure –
including against cyber risks – is thus important. CI operators cannot regard the risks merely
according to purely economic principles; they have to make further-reaching efforts to
minimise the risks. This is why they are already subject to some special rules; however,
concrete and binding requirements regarding protection standards for the ICT used are
generally missing. Depending on the criticality and vulnerability of given infrastructure, as
well as the threat situation, requirements for security standards and other risk-reduction
measures should be set more comprehensively and precisely in association with the
competent public authorities.
The manufacturers and providers of ICT products and services bear significant responsibility
for the security of their products and thus also for the cyber security of their clients.
For the most part, private sector players act under their own responsibility and at their own
discretion. In order to gain an overview, companies selected for preparing the strategy were
questioned on their current assessments, measures and difficulties, as well as their outlook
for the future with regard to cyber security.
Perception of the problem
Cyber risks are indisputably a major issue for companies. However, the risk assessments
and measures taken differ considerably not only from one sector of the economy to another,
but also within sectors and branches, as well as within companies themselves.
Consequently, it is not possible to have a simple sector-specific classification of the
perception of the problem.
7
The DDPS questioned representatives from the private sector and operators of critical infrastructure (incl.
umbrella organisations and associations) about the measures they are taking or have already taken, where
deficiencies and difficulties lie and what factors influence their protective measures (e.g. financial considerations). The surveys gave a uniform picture on the whole.
12/42