National strategy for the protection of Switzerland against cyber risks – NCS implementation plan Introduction The Federal Council adopted the 2018-2022 national strategy for the protection of Switzerland against cyber risks (NCS) on 18 April 2018. The strategy builds on the first NCS for 2012-2017, expands on it and supplements it with further measures. It thus takes account of the greatly intensified threat situation. The strategy is intended to help ensure that Switzerland is appropriately protected against cyber risks and resilient to them when exploiting the opportunities offered by digitalisation. Derived from this vision, the NCS identifies seven strategic objectives which are to be achieved by means of 29 measures in a total of 10 areas of action. Figure 1 summarises the contents of the NCS: Figure 1 NCS contents This implementation plan defines concrete implementation projects for all 29 NCS measures and sets out the responsibilities, the performance targets to be achieved and the milestone schedule for these projects. The implementation plan was drawn up jointly in conjunction with the competent federal units, the cantons, the business community and universities at the end of 2018 and start of 2019, and is subdivided below according to the NCS areas of action. Due to the broad participation in its preparation, the implementation plan not only contains the planned work of the competent federal units, but also includes the most important activities of other players in connection with the NCS. As a result, it serves both as a basis for the work schedule and strategic controlling to check the implementation progress, as well as an instrument for the coordination of all players involved. This document reflects the current state of the implementation plan. However, adjustments must be possible at all times in the dynamic cyber risk environment. The bodies described in the following chapter are thus empowered to adjust the implementation plan if necessary. 4/79

Select target paragraph3