Cyber risks are manifold; the private sector, society and the state are exposed to them. An
effective strategy for protecting against cyber risks therefore has to be comprehensive and
include all essential players, in both the public and private sector, operators of critical
infrastructure (CI), users and producers. This strategy for the protection of Switzerland
against cyber risks is directed primarily at federal bodies and was prepared in collaboration
with representatives from all departments, various CI operators, ICT service providers,
system suppliers and the private sector. It describes the roles of the various players and the
type of collaboration required for better protection against cyber risks. It thus forms the basis
for closer cooperation with the cantons in the implementation phase.
A great deal of services are offered and used through electronic channels today.
Consequently, the presence of all Internet players and their dependence on critical
infrastructure are growing 4. The private sector is thus very vulnerable to cyber risks, e.g.
attacks with the intent to commit fraud or obtain financial gain, or industrial espionage. It is
thus essential to include the private sector, particularly CI operators, ICT service providers
and system suppliers, in a strategy aimed at protecting against cyber risks.
Cyber attacks on critical infrastructure can have particularly severe consequences, as
they can compromise vitally important functions or trigger fatal chain reactions. Therefore,
(often private) CI operators play a key role as providers of important services with
overriding security implications.
State authorities and administrations at all levels (Confederation, cantons, communes)
can also be victims of cyber attacks. They can be affected in their legislative, executive or
judiciary functions, but also as operators and users of critical infrastructure or research
institutions.
Cyber risks also affect the population with all individual users of private and professional
information and communication systems as well as critical infrastructure. An effective
strategy against cyber risks must also take individual behaviour and the respective risks
into account.
First and foremost, the individual players are themselves responsible for maintaining and
optimising protective measures for minimising cyber risks. This lies in the nature of things:
cyber risks are inherent in existing tasks, responsibilities and processes. It is therefore in the
best interests of users to devise and implement tailor-made solutions for area or branchspecific problems. This approach also corresponds to Switzerland's characteristic
decentralised economic and state structure. The state provides subsidiary services to protect
against cyber risks, e.g. by means of the exchange of information and intelligence findings.
Where area-specific action under one's own responsibility is neither effective, efficient nor
practicable, the state should provide additional subsidiary services to protect against cyber
risks and support the other players. This strategy should show where the weaknesses
currently lie with regard to cyber risks. It describes where the state and other players are to
provide services in order to raise the level of protection in Switzerland.
It has to be noted that efforts to ensure protection can collide with other equally legitimate
interests. A comprehensive information base, including technical-operational and strategic-
4
Critical infrastructure refers to infrastructure whose disruption, failure or destruction would have serious implications for society, the private sector and the state. It includes, for example, control and switchgear for energy
supply or telecommunications. An inventory of critical infrastructure will be compiled by the national strategy
for the protection of critical infrastructure.
6/42