The Council of Europe Convention on Cybercrime, which entered into force in Switzerland on
1 January 2012, obliges the contracting states to criminalise computer fraud, data theft,
document forgery with the aid of a computer and penetration of a protected computer
system. The Convention governs how evidence in the form of electronic data can be
collected and stored during a criminal investigation. The investigating authorities should be
able to access electronic data rapidly in order to prevent its forgery or destruction in the
course of the proceedings. The Swiss Criminal Code and its criminal law provisions,
particularly the provisions of so-called computer criminal law in the Swiss Criminal Code
(SCC) 29, especially Articles 143, 144bis and 272-274 are applicable in cybercrime cases. The
Council of Europe Convention also governs international cooperation between states in
criminal matters (e.g. mutual assistance and extradition). Cooperation between the various
countries should be organised rapidly and efficiently.
3.7
Conclusion
The analysis of existing structures shows that there are many capabilities present in the
private sector (particularly major ICT service providers and system suppliers), in the
Confederation and in the cantons that make it possible to comprehend the cyber aspects of
existing missions and responsibilities and thus identify the associated risks. There are also
approaches and concepts for improving the cyber security situation and means that enable
the exchange of information and coordination between individual players. Large companies,
cantonal police forces and the Confederation have units with specialist expertise. Various
Swiss research institutions also run projects relating to cyber security and the identification
and assessment of cyber risks. Often, however, all the stakeholders from the technical and
operating level to the strategic and political level are not included in the processes, or they
abstain deliberately.
Surveys with representatives from the private sector and CI operators also show that large
gaps and weaknesses exist for dealing with cyber attacks. Therefore, the capabilities and
perceptions at the various levels vary considerably; they are often inadequate, only partially
coordinated and largely dictated by commercial interests. The measures planned or
introduced to improve cyber security reflect differing risk assessments and are
correspondingly heterogeneous. They lead to uncoordinated approaches; the exchange of
information between the players barely functions and is often limited to a single entity or
area.
Cyber security deficiencies are often due to a lack of financial and human resources. This
applies not only to the private sector, but also particularly to the Confederation, where human
resources are insufficient, with the result that even in a normal situation core tasks can only
be performed in a sketchy manner. Another problem is the generally perceived lack of ICT
specialists.
In terms of cooperation between the private sector and the authorities, there are various
weak points and a need for clarification regarding the distribution of tasks, capabilities and
powers. The analysis of existing structures showed in particular that the Federal
Administration lacks sufficient means for identifying risks and comprehensively evaluating
information and situation assessments for the private sector, CI operators and authorities.
Consequently, satisfactory cyber risk protection cannot be achieved due to an insufficient
exchange of information. Moreover, cooperation with critical ICT service providers and
29
SR 311.0 Swiss Criminal Code of 21 December 1937
26/42