Skip to main content

Implement protective measures

Specific protective measures complement baseline protection; they are determined based on identified risks and consistently implemented to specifically protect information assets, systems, and data against relevant cyber threats.

Emergency planning is the key to cyber resilience

Cyberattacks that paralyse public services or result in the disclosure of sensitive data can undermine the public's trust in government institutions. Past incidents and the "2025 Myni Gmeind" survey on cybersecurity demonstrate that many communes could enhance their preparedness for cyberincidents. To help communes and organisations in Switzerland strengthen their cyber resilience in a simple and hands-on way, the NCSC has launched a project together with its partner network. As part of this project, an emergency planning model was developed to provide practical guidance on enhancing cyber resilience.

Measures to secure content management systems (CMS)

The number of websites has truly exploded over the past few years, not least because easy-to-use website creation tools are available that do not require any technical know-how and are increasingly affordable. Content management systems (CMS) can be used to design and launch a website with just a few clicks. There are now dozens of such CMS used by private individuals, SMEs and large companies alike.

Measures for security in the Internet of Things (IoT)

Smart devices, such as speakers, light switches and fridges, can be vulnerable to attack. The NCSC recommends taking preventive measures to improve the cybersecurity of your IoT devices.

Measures to protect industrial control systems (ICSs)

Securing industrial control systems (ICSs) protects data, infrastructure, processes and people. The NCSC has summarised the key measures.

Measures to counter DDoS attacks

A DDoS (distributed denial of service) is a type of attack on computer systems with the aim of making them unavailable. This can have far-reaching economic consequences for the victim.

Security.txt - Include your security contact on your website

In case of cybersecurity problems in a company or organisation, it is very important to quickly inform the relevant security contact. Often, however, these contacts are not easy to find on websites, or are not even listed. The "security.txt" standard provides a way to publish the security contact of an organisation or company in a uniform way, thus making it quicker to find.

Secure use of remote access

An increasing number of companies are using remote methods to access their corporate networks. However, this technology also increases the risk of cyberattacks.