National strategy for the protection of Switzerland against cyber risks 2018-2022
1 Introduction
Switzerland is in the process of digitalisation. Comprehensive digital interconnectivity is
already a characteristic of our society, economy and state, and rapid technological progress
will continue to drive this development. This process opens up great opportunities, and
Switzerland is willing to use these to secure and expand welfare in our country for the long
term.
However, it must be borne in mind that digitalisation brings not only opportunities but also
risks. The associated, increasing dependence on information and communication
technologies (ICT) makes our country more vulnerable to breakdowns, disruptions and
misuse of these technologies.
How relevant this vulnerability is can be seen with regard to the development of threats in
cyberspace. Rampant cybercrime, the accumulation of espionage activities with the help of
cyber attacks, cases of cyber sabotage against critical infrastructures such as hospitals and
energy providers, the spread of stolen or manipulated information for the purpose of
disinformation and propaganda, and the increase in hybrid forms of conflict in which cyber
attacks are used to destabilise states and societies make clear how diverse these threats are
and how rapidly they are developing.
The combination of the increased dependence on functioning ICT and the intensified threat
situation means that the resulting risks, which we refer to as cyber risks, must necessarily be
taken into account in the development of the digital society. From the perspective of security
policy, measures must be taken to safeguard the independence and security of the country
from emerging or intensifying threats and dangers in cyberspace. From the perspective of
economic and social policy, Switzerland must protect itself from cyber risks in order to be
able to make consistent use of the opportunities offered by digitalisation and to maintain its
locational advantage as a safe and secure country. However, complete protection against
cyber risks cannot be achieved with proportionate measures. Switzerland must therefore
increase its resilience to cyber incidents.
The national strategy for the protection of Switzerland against cyber risks (NCS) presented
here sets out how these goals are to be achieved by 2022. It builds on the first NCS
implemented from 2012 to 2017; further develops it in line with Switzerland's vulnerabilities,
the significantly changed and intensified threat situation since 2012, and the foreseeable
future development thereof; and it supplements it with further measures. It thus provides the
strategic framework for improving prevention, early identification, response, and resilience in
all areas relevant to cyber risks.
Protection against cyber risks is a joint responsibility of the private sector, society and the
state. This means firstly that all actors are responsible for their own protection. The NCS
supports and coordinates these individual protection efforts. Beyond this, it formulates
additional measures where cyber risks have a significant impact on the development and
welfare of our society. This joint responsibility also gives rise to shared implementation of the
NCS. The federal government, the cantons, the private sector and society should implement
the NCS measures in close cooperation with each other and contribute their respective
competencies.
The challenges in dealing with cyber risks are great, and they will continue to be virulent.
This makes it all the more important that all players approach these challenges together and
in a coordinated manner. Effective cooperation of all competent bodies to the extent possible
and systematic international networking are crucial to creating a secure environment for the
digitalisation of society and the economy. The NCS 2018-22, which was jointly developed by
the federal government, the cantons and the private sector, is intended to serve as an
instruction manual and guidance in this regard. The implementation plan, which is part of the
strategy, defines the competencies and implementation responsibilities for the measures
determined in the strategy.
2