There are companies that are highly aware of the problem. These include mainly large
companies that have significant resources in terms of capital, personnel, infrastructure and
specific expertise (e.g. forensics, risk and crisis management, computer emergency
response teams). In most cases, these companies operate internationally and have large
networks. Companies active primarily in the area of security (e.g. the armament industry)
have an increased need for protection and for the most part are independently capable of
warding off uncoordinated cyber attacks to which Switzerland is exposed on a daily basis.
CI operators are also highly aware of the problem. According to the survey, they expect the
requirements for security standards to be defined more comprehensively and more precisely
– in conjunction with the supervisory authorities – depending on how critical and vulnerable
given infrastructure is.
The largest group is comprised of small and medium-sized enterprises with average
awareness of the problem. They usually use commercially available security infrastructure
and concepts (e.g. firewalls, anti-virus programs). Their ability to improve their protective
measures in cyberspace is limited primarily by their financial resources.
The last group consists of companies whose awareness of the problem is low. They lack the
resources for protective measures against cyber risks or do not understand the need for
them.
Measures
Very few of the private sector players questioned would be capable of warding off a targeted
high-intensity cyber attack (with regard to simultaneity, complexity, potential for damage and
duration).
Many companies have security standards (e.g. ISO 2700x, NERC) and apply these. They
also take technical and organisational precautions (e.g. operation of autonomous systems,
deployment of security officers). Moreover, measures are taken to enhance the security
awareness of staff; however, the decision-makers are often neglected. The measures put in
place help ensure that weaknesses within the company are identified and protective
measures are improved continually over the long term. However, the vast majority of small
and medium-sized enterprises do little in the area of security. The acceptance of risks is
often determined by purely economic considerations. Cyber risks are an integral part of
overall business processes and thus cannot be tackled in an isolated fashion or solely on a
technical level. Furthermore, the information base for making decisions is often incomplete,
and cyber-specific details are marginal. In order to achieve a level of protection that is as
complete as possible and does not distort competition, companies and CI operators expect
uniform requirements and standards to be prepared and implemented in cooperation with all
those who are responsible and affected.
Optimising the exchange of information between private sector players, particularly CI
operators, ICT service providers, system suppliers, and the authorities is decisive for
resolving problems and minimising damage. Up to now, however, there has apparently been
little cooperation beyond company boundaries (incl. authorities). The large economic
associations have given too little attention to cyber security and their role in this regard. The
survey showed that there is a need to further develop and consolidate forms of cooperation
between the private sector and the authorities in order to exchange information on the
13/42