SUMMARY
Information and communication infrastructure has fundamentally changed the private sector,
state and society. The use of cyberspace (e.g. Internet and mobile networks) has brought
many advantages and opportunities. However, digital networking also exposes information
and communication infrastructure to criminal, intelligence, politico-military or terrorist abuse
or functional impairment. Disturbances, manipulation and specific attacks carried out via
electronic networks are the risks that an information society entails. It is to be expected that
these risks will tend to increase in the future.
As the protection of information and communication infrastructure from cyber threats is in
Switzerland's national interest, the Federal Council commissioned the national strategy for
the protection of Switzerland against cyber risks. The Federal Council is pursuing the
following strategic goals:
Early identification of threats and dangers in the cyber field
Improvement of the resilience of critical infrastructure
Effective reduction of cyber risks, especially cyber crime and cyber sabotage
This strategy also takes account of several parliamentary proposals calling for stronger
measures against cyber risks.
Essential basic conditions and prerequisites for reducing cyber risks are and remain acting
with personal responsibility, national cooperation between the private and public sector, and
cooperation with foreign countries. The mutual exchange of information on a permanent
basis is to create transparency and trust. The state should intervene only if public interests
are at stake or if acting in accordance with the principle of subsidiarity.
Dealing with cyber risks is to be understood as part of an integrated business, production
and administration process in which all players from the administrative and technical levels
up to top management must be included. An effective approach for handling cyber risks is
founded on the principle that a great many existing tasks and responsibilities of authorities,
the private sector and the population exhibit cyber-specific aspects. The rationale underlying
the national strategy is that every organisational unit, be it political, economic or social, bears
responsibility for identifying these cyber aspects, addressing the risks entailed in their
particular processes and reducing them insofar as possible. The decentralised structures in
the public and private sector are to be strengthened for these tasks, and existing resources
and processes are to be used consistently.
The ongoing combination of technical and non-technical information is necessary to analyse
and assess cyber risks comprehensively in order for it to be possible to disseminate the
findings from the investigations.
A crisis situation is characterised by a successful attack with considerable consequences
and requires a specific form of crisis management from the players involved, including
criminal prosecution.
Against this background, this strategy proposes a series of concrete measures with seven
spheres of action:
3/42