4
4.1
SYSTEM FOR PROTECTING AGAINST CYBER RISKS
Overriding goals
The Federal Council recognises that the cyber problem is primarily linked to its influence on
existing tasks and responsibilities of authorities, the private sector and society. Minimising
cyber risks is thus a matter for the relevant responsible parties.
The Federal Council wishes to promote the opportunities and advantages cyberspace entails
for Switzerland's economy, politics and population. However, it also notes that developments
in this area are associated with risks, and that corresponding measures to minimise these
are necessary.
This national strategy governs the application of the described measures in times of peace
and thus explicitly excludes war.
With the national strategy for the protection of Switzerland against cyber risks, the Federal
Council pursues the following overriding goals:
Cyber risks are to be recognised and evaluated at an early stage in order for risk reducing
and preventive measures to be taken in cooperation with all those involved in the private
sector, political circles and society
The resilience of critical infrastructure to cyber attacks – in other words, the ability to
resume normal operations as quickly as possible – is to be increased in cooperation with
their operators, ICT service providers, system suppliers and the Confederation's
programme to protect critical infrastructure (CIP programme)
Prerequisites are to be ensured for an effective reduction of cyber risks, particularly, cyber
crime, cyber espionage and cyber sabotage, and where necessary created anew
These goals can be achieved in the existing decentralised structures in various ways. In any
case, acting with personal responsibility in the different private sector areas as well as
dialogue and cooperation between the private sector and the authorities are essential
prerequisites. The exchange of information on a permanent basis should create transparency
and trust, and the state should intervene only if public interests are at stake and if acting in
accordance with the principle of subsidiarity.
Dealing with cyber risks is an interdisciplinary task that has to be assumed by the private
sector, CI operators, ICT service providers, system suppliers, as well as cantonal and federal
authorities. This must be understood as part of an integrated business, production or
administration process. All players from the administrative and technical levels up to the
strategic and political levels must be included in these processes. An effective approach to
dealing with dangers and threats stemming from the Internet presupposes recognition that
existing tasks and responsibilities of authorities, the private sector and the population have
cyber aspects. Every organisational unit in political circles, the private sector and society
bears responsibility for recognising these cyber aspects and integrating the resulting risks in
their processes in order to reduce them. To this end, the existing decentralised structures
should have the necessary powers and possibly be strengthened in order to fully assume the
cyber-specific aspects of their tasks and responsibilities.
28/42