Cyber risks are manifold; the private sector, society and the state are exposed to them. An effective strategy for protecting against cyber risks therefore has to be comprehensive and include all essential players, in both the public and private sector, operators of critical infrastructure (CI), users and producers. This strategy for the protection of Switzerland against cyber risks is directed primarily at federal bodies and was prepared in collaboration with representatives from all departments, various CI operators, ICT service providers, system suppliers and the private sector. It describes the roles of the various players and the type of collaboration required for better protection against cyber risks. It thus forms the basis for closer cooperation with the cantons in the implementation phase. A great deal of services are offered and used through electronic channels today. Consequently, the presence of all Internet players and their dependence on critical infrastructure are growing 4. The private sector is thus very vulnerable to cyber risks, e.g. attacks with the intent to commit fraud or obtain financial gain, or industrial espionage. It is thus essential to include the private sector, particularly CI operators, ICT service providers and system suppliers, in a strategy aimed at protecting against cyber risks.  Cyber attacks on critical infrastructure can have particularly severe consequences, as they can compromise vitally important functions or trigger fatal chain reactions. Therefore, (often private) CI operators play a key role as providers of important services with overriding security implications.  State authorities and administrations at all levels (Confederation, cantons, communes) can also be victims of cyber attacks. They can be affected in their legislative, executive or judiciary functions, but also as operators and users of critical infrastructure or research institutions.  Cyber risks also affect the population with all individual users of private and professional information and communication systems as well as critical infrastructure. An effective strategy against cyber risks must also take individual behaviour and the respective risks into account. First and foremost, the individual players are themselves responsible for maintaining and optimising protective measures for minimising cyber risks. This lies in the nature of things: cyber risks are inherent in existing tasks, responsibilities and processes. It is therefore in the best interests of users to devise and implement tailor-made solutions for area or branchspecific problems. This approach also corresponds to Switzerland's characteristic decentralised economic and state structure. The state provides subsidiary services to protect against cyber risks, e.g. by means of the exchange of information and intelligence findings. Where area-specific action under one's own responsibility is neither effective, efficient nor practicable, the state should provide additional subsidiary services to protect against cyber risks and support the other players. This strategy should show where the weaknesses currently lie with regard to cyber risks. It describes where the state and other players are to provide services in order to raise the level of protection in Switzerland. It has to be noted that efforts to ensure protection can collide with other equally legitimate interests. A comprehensive information base, including technical-operational and strategic- 4 Critical infrastructure refers to infrastructure whose disruption, failure or destruction would have serious implications for society, the private sector and the state. It includes, for example, control and switchgear for energy supply or telecommunications. An inventory of critical infrastructure will be compiled by the national strategy for the protection of critical infrastructure. 6/42

Select target paragraph3