National strategy for the protection of Switzerland against cyber risks 2018-2022
specialisation of criminal activities in cyberspace must be expected.
Cyber espionage: Cyber espionage is an activity for gaining unauthorised access to
information in cyberspace for political, military or economic purposes. It is carried out by both
state and non-state actors. The attackers focus on companies as well as governmental,
social and international institutions. The Swiss economy is one of the most innovative in the
world, and many international companies have their headquarters or important data centres
here. Switzerland is also home to many international organisations and often hosts
international negotiations. This makes Switzerland an attractive target for cyber espionage.
The impact can vary greatly depending on the type and volume of data the attackers gain
access to. The impact is usually not immediately apparent, since political and economic
disadvantages arise only when the attackers make use of the knowledge they have gained.
Cyber espionage will become even more attractive, given that it is an efficient way of
gathering information. Attackers have developed methods to stay undetected as long as
possible after the networks have been breached. Since Switzerland is highly dependent on
foreign manufacturers in regard to its ICT, there remains the risk that these producers, in
cooperation with the intelligence services of their countries, deliberately leave vulnerabilities
open for the purpose of espionage.
Cyber sabotage and cyber terrorism: Cyber sabotage refers to activities aiming to disrupt
or destroy the reliable and error-free functioning of ICT in cyberspace; depending on the type
of sabotage and the target attacked, this may also have physical effects. The motivation for
such acts can vary considerably. For example, frustrated employees may decide to sabotage
an organisation's ICT. If an act of sabotage is carried out by perpetrators with terrorist
motives, it is referred to as cyber terrorism. Cyber sabotage and cyber terrorism aim not only
to achieve the greatest possible damage, but also to intimidate and to demonstrate power
with the intention of destabilising an organisation or even society as a whole. While various
acts of sabotage have been observed internationally, including against the energy supply of
states, no major cases have come to light in Switzerland so far. However, should Switzerland
or organisations in or from Switzerland become a target of state or non-state actors with the
necessary capabilities for political reasons, the probability of such an event would increase
considerably. The potential damage is very great.
The relevance of this threat will continue to increase with the progressive digitalisation of
society and the economy. The increasing digital networking of physical devices via the
internet of things also permits new forms of digital manipulation – again with a direct impact
on the physical world.
Disinformation and propaganda: The threat posed by targeted spreading of false
information or of information illegally obtained through cyber attacks with the aim of
discrediting political, military or civil society actors has become increasingly prominent. Such
activities have been observed in various countries in the run-up to important elections. In
Switzerland as well, the possibility must be considered that state or non-state actors may
attempt to undermine the confidence of citizens in the state and institutions.
Given that the importance of social media as a source of information continues to grow, it
must also be assumed that these channels are used for propaganda, with an extremely nontransparent mix of false information, political arguments and stolen information.
Cyber attacks in conflicts: While a war waged exclusively in cyberspace (cyber war) is
currently considered to be an unrealistic scenario, it has been seen that cyber attacks of all
kinds are used as a means of warfare in various conflicts. Typically, these are hybrid conflicts
in which political, economic and criminal means are used in addition to military force. One
aim of hybrid warfare is to disguise responsibilities in a conflict. Cyber attacks are a proven
instrument for this purpose, since they are difficult to attribute unambiguously, and since they
cost comparatively little, have an immediate impact, can be employed over arbitrarily large
distances, and allow political-military effects to be achieved in the grey area below the
threshold of an actual war.
The considerable investments made by many states to protect and actively defend against
cyber threats underscore the importance of cyber resources in conflicts. Accordingly, the
importance of targeted cyber attacks for strategic purposes is expected to increase further. In
4