1 INTRODUCTION Global digital networking has created unforeseen possibilities, both good and bad. The state, the private sector and society make use of information and communication infrastructure and access to cyberspace (Internet, mobile networks and applications, e-business, egovernment, computer-based control programmes). However, this also means that vulnerability and exposure to disruptions, manipulations and attacks have increased. Like the benefits, the possibilities that information and communication infrastructure provides for criminal, intelligence, terrorist or military abuse or impairment are practically unlimited. It is likely that the underlying trend towards more networking, and thus the growing complexity of information and communication infrastructure, will continue. Switzerland's functioning as a holistic system (state, private sector, traffic, energy supply, communication, etc.) depends on a growing number of mutually networked information and communication facilities (computers and networks). This infrastructure is vulnerable. Country-wide or long-lasting disruptions and attacks could have severe adverse effects for Switzerland's technical, economic and administrative performance. Such attacks can be launched by a variety of perpetrators and have various motives: individual perpetrators, political activists, criminal organisations intent on fraud or blackmail, state spies or terrorists who want to disrupt and destabilise the state and society. Information and communication technologies (ICT) are particularly attractive as targets not only because they offer many possibilities for abuse, manipulation and damage, but also because they can be used anonymously and with little effort. Protecting 1 information and communication infrastructure from such disturbances and attacks is in Switzerland's national interest. Although measures have been taken in recent years to reduce cyber risks 2, it has become evident that these have not been sufficient for all cases. Because it is to be expected that there will be an increase in disruptions and attacks on information and communication infrastructure (thereby affecting further facilities as well), the Federal Council instructed the Federal Department of Defence, Civil Protection and Sport (DDPS) on 10 December 2010 to prepare a national strategy for the protection of Switzerland against cyber risks. This strategy is to demonstrate what these risks look like at present, how well Switzerland is equipped to counter them, where the shortcomings lie and how they can be eliminated in the most effective and efficient manner. This national strategy for the protection of Switzerland against cyber risks is the result of that work 3. 1 This refers to all measures to protect information and communication infrastructure against unauthorised penetration and impairment of its functions, but not the fight against the dissemination of illegal content such as child pornography. The focus is on technical aspects, not on debating content such as false and misleading information and propaganda. 2 Risks are defined according to the extent of damage expected and the likelihood of threats and dangers occurring. Both are taken into account in the strategy. 3 The strategy takes into account various parliamentary procedural requests calling for stronger measures against cyber risks: 08.3100 – Burkhalter motion: National strategy for fighting Internet crime; 08.3101 – Frick postulate: Protecting Switzerland more effectively against cyber crime; 10.3136 – Recordon postulate: Analysis of the cyber war threat; 10.3625 – SKI-NR motion: Measures against cyber war; 10.3910 – postulate of the FDP – The Liberals: management and coordination unit for cyber threats; 10.4102 – Darbellay postulate: Concept to protect Switzerland's digital infrastructure. 5/42

Select target paragraph3