There are companies that are highly aware of the problem. These include mainly large companies that have significant resources in terms of capital, personnel, infrastructure and specific expertise (e.g. forensics, risk and crisis management, computer emergency response teams). In most cases, these companies operate internationally and have large networks. Companies active primarily in the area of security (e.g. the armament industry) have an increased need for protection and for the most part are independently capable of warding off uncoordinated cyber attacks to which Switzerland is exposed on a daily basis. CI operators are also highly aware of the problem. According to the survey, they expect the requirements for security standards to be defined more comprehensively and more precisely – in conjunction with the supervisory authorities – depending on how critical and vulnerable given infrastructure is. The largest group is comprised of small and medium-sized enterprises with average awareness of the problem. They usually use commercially available security infrastructure and concepts (e.g. firewalls, anti-virus programs). Their ability to improve their protective measures in cyberspace is limited primarily by their financial resources. The last group consists of companies whose awareness of the problem is low. They lack the resources for protective measures against cyber risks or do not understand the need for them. Measures Very few of the private sector players questioned would be capable of warding off a targeted high-intensity cyber attack (with regard to simultaneity, complexity, potential for damage and duration). Many companies have security standards (e.g. ISO 2700x, NERC) and apply these. They also take technical and organisational precautions (e.g. operation of autonomous systems, deployment of security officers). Moreover, measures are taken to enhance the security awareness of staff; however, the decision-makers are often neglected. The measures put in place help ensure that weaknesses within the company are identified and protective measures are improved continually over the long term. However, the vast majority of small and medium-sized enterprises do little in the area of security. The acceptance of risks is often determined by purely economic considerations. Cyber risks are an integral part of overall business processes and thus cannot be tackled in an isolated fashion or solely on a technical level. Furthermore, the information base for making decisions is often incomplete, and cyber-specific details are marginal. In order to achieve a level of protection that is as complete as possible and does not distort competition, companies and CI operators expect uniform requirements and standards to be prepared and implemented in cooperation with all those who are responsible and affected. Optimising the exchange of information between private sector players, particularly CI operators, ICT service providers, system suppliers, and the authorities is decisive for resolving problems and minimising damage. Up to now, however, there has apparently been little cooperation beyond company boundaries (incl. authorities). The large economic associations have given too little attention to cyber security and their role in this regard. The survey showed that there is a need to further develop and consolidate forms of cooperation between the private sector and the authorities in order to exchange information on the 13/42

Select target paragraph3