Press releases
2026
Progress in strengthening cybersecurity
Switzerland is making progress in strengthening cybersecurity. The latest report on the implementation of the National Cyberstrategy (NCS) documents the status of work in 2025 and shows that projects are moving forward. The report also sets out the measures being taken in response to the growing importance of artificial intelligence (AI) in the field of cybersecurity. The Federal Council was informed of the report at its meeting on 20 May 2026.
‘Stay safe online and offline’ – Raising awareness at the 2026 BEA spring fair
The National Cyber Security Centre (NCSC) will be hosting an interactive exhibition at the BEA spring fair in Bern between 24 April and 3 May to raise public awareness of cybersecurity. Working alongside Swiss Crime Prevention (SCP), the Swiss Federal Railways (SBB), Swiss Post, the Lucerne University of Applied Sciences and Arts (eBanking – but secure! EBAS) and Netpathie, the NCSC will demonstrate the reality of digital threats and how simple measures can provide effective protection.
‘SUPER, right?’ – launch of the 2026 national cybersecurity awareness campaign
Phishing and scam attempts are widespread, and many are identified early enough for people to take the necessary cybersecurity measures. But it is becoming increasingly difficult to tell fraudulent messages from genuine ones. Scammers are increasingly using AI to personalise their messages, making them appear more convincing than ever. This is precisely what the new cybersecurity awareness campaign highlights under the slogan ‘SUPER, right?’. From 13 April to 10 May, the National Cyber Security Centre (NCSC), Swiss Crime Prevention (SCP), the cantonal and city police forces, Swiss Federal Railways (SBB), Swiss Post and the Swiss Insurance Association (SIA) are launching another edition of the national S-U-P-E-R.ch campaign to raise awareness of the importance of cybersecurity.
Cyberthreat level remains high – attacks becoming more targeted and complex
The semi-annual report published today by the National Cyber Security Centre (NCSC) outlines the relevant incidents and developments relating to cyberthreats against Switzerland and internationally in the second half of 2025. Alongside voluntary reports of cyber incidents, the report presents reportable cyberattacks against critical infrastructure for the first time. Such attacks have been mandatory reporting requirements since 1 April 2025. Although the number of voluntary reports has remained stable at a high level, the nature of these incidents is evolving and becoming more targeted. Effective protection requires close cooperation between government, businesses and society at both national and international levels.
NCSC Director Florian Schütz at the RSAC Conference in San Francisco
Florian Schütz, Director of the National Cyber Security Centre (NCSC), will be attending the RSAC Conference in San Francisco from 23 to 26 March. This leading global event in the field of IT and cybersecurity brings together representatives from industry, science, and public administration. During the conference, Mr Schütz will participate in various panels and hold bilateral talks with representatives from industry and international organisations.
Federal Councillors Martin Pfister, Ignazio Cassis and Beat Jans to attend the Munich Security Conference
Federal Councillors Martin Pfister, Ignazio Cassis and Beat Jans will attend the Munich Security Conference (MSC 26) from 13 to 15 February. In a rapidly changing security environment, this conference offers an opportunity for high-level discussions on how to strengthen Europe's security. It also provides a platform for promoting values such as peace and the rule of law.
The NCSC and SIA put cybersecurity in the spotlight at Swissbau 2026
The 2026 edition of Swissbau, the construction and real estate industry trade fair in Basel from 20 to 23 January, the National Cyber Security Centre (NCSC) and the Swiss Society of Engineers and Architects (SIA) will be focusing on cyber risks in the construction and real estate industry. Various events will highlight the increasing threat posed by cyberattacks and provide companies with specific recommendations for action on cybersecurity along the supply chain.
Cyber resilience in global dialogue: The NCSC at the WEF Annual Meeting 2026
This year, with Florian Schütz participating in the World Economic Forum (WEF) Annual Meeting, the National Cyber Security Centre (NCSC) is using this international platform to further engage with political, economic, and expert stakeholders on critical cybersecurity matters. To this end, the NCSC is organising a specialist event at the WEF Annual Meeting focusing on geopolitical developments, leadership roles in key technologies, and digital sovereignty. As in previous years, the NCSC is also supporting the WEF organisation in protecting cyberspace.
2025
Report on the influence of artificial intelligence in cybersecurity
The Federal Council has examined how artificial intelligence (AI) is influencing cybersecurity and whether the National Cyberstrategy (NCS) can keep pace with rapid developments in AI. In a report on the opportunities and risks of AI systems in cybersecurity, commissioned in response to postulate 23.3861 from Gerhard Andrey and approved on 12 December, the Federal Council concludes that while AI acts as a catalyst for existing trends in cybersecurity, it does not change the fundamentals. AI projects will now be identified more clearly in the NCS to ensure transparency and allow for more focused control.
NCSC Director Florian Schütz visits Japan for high-level cybersecurity talks
Florian Schütz, director of the National Cyber Security Centre (NCSC), is travelling to Japan to strengthen international cooperation in the field of cybersecurity. The trip underscores the strategic importance of bilateral and multilateral cooperation in the face of increasing geopolitical tensions and hybrid threats.
Federal Council to take action against scam websites
Digital crime in Switzerland has more than doubled in recent years. In response to Postulate 22.3457, which was submitted by National Council member Stefan Müller-Altermatt, the Federal Council examined the coordination between the relevant authorities, the police and the domain registry operators with regard to tackling scam websites. This assessment was carried out as part of a report on deactivating scam websites and coordinating the national response to online scams. Approved by the Federal Council at its 19 November meeting, the report concludes that, although the existing legal instruments are fundamentally effective, they must be applied more consistently.
Almost five-fold increase in reports of online investment ad scams
The latest semi-annual report from the National Cyber Security Centre (NCSC) shows that the centre continued to receive large numbers of reports in the first six months of 2025. The number of reports concerning fraud – over half of the total – also remains high. There has been a marked increase in reports of online investment advertising scams. Cybercriminals often misuse celebrities as decoys to gain the trust of potential victims. The semi-annual report also focuses on various targeted phishing campaigns aimed at bank customers, the ongoing ransomware threat and hacktivism at major events such as the WEF and the Eurovision Song Contest.
Cyberthreat alerts now also on Alertswiss
Alertswiss will now also provide warnings to the public and businesses about serious cyberthreats. The National Cyber Security Centre (NCSC) and the Federal Office for Civil Protection (FOCP) have stepped up their collaboration. Cyberalerts are now integrated into both the Alertswiss app and website. This provides an additional channel through which to inform and warn the public as quickly as possible in the event of large-scale or unprecedented cyberattacks, and to provide practical guidance.
Staying safe through a crisis: Emergency planning is the key to cyber resilience
Cyberattacks that paralyse public services or result in the disclosure of sensitive data can undermine the public's trust in government institutions. Past incidents and the 2025 Myni Gmeind survey on cybersecurity demonstrate that many communes could enhance their preparedness for cyberincidents. To help communes and organisations in Switzerland strengthen their cyber resilience, the National Cyber Security Centre (NCSC) has launched a project together with its partner network. As part of this project, the NCSC has developed an emergency planning model, a set of practical tools, and an educational video, all of which are available on its website. The NCSC is also offering Brown Bag Lunches to show communes and organisations how best to prepare for cyberincidents.
Digital Switzerland Advisory Board: Cybersecurity in Switzerland today
At the Digital Switzerland Advisory Board meeting on 30 October the focus was on information security and cybersecurity. Under the chairmanship of Federal Councillor Martin Pfister and with the participation of Federal Chancellor Viktor Rossi, representatives from the cantons, business, academia and civil society met to exchange views on the current state of national cybersecurity measures. The discussions centred on information security and cybersecurity in the context of the National Cyberstrategy, and highlighted specific areas for action and examples of what works in practice.
Concept for coordinated cyberincident response
Due to the close interconnection of digital systems, cyberincidents can have an immediate impact on many different organisations. Successfully managing these incidents requires a coordinated approach involving all affected stakeholders, including those from the business and economic community, the cantons, and the federal government. The National Cyber Security Centre (NCSC) has developed a plan for coordinated cyberincident response, setting out how the federal government organises itself to ensure effective, coordinated management of incidents.
NCSC Director Florian Schütz visiting WEF Annual Meeting on Cybersecurity and Singapore International Cyberweek
Florian Schütz, Director of the National Cyber Security Centre (NCSC), is representing Switzerland at two major international cybersecurity forums this month, one in Dubai and one in Singapore. By contributing to discussions on global cyber resilience, artificial intelligence and international cooperation, he is advocating for a secure and resilient digital future, and reinforcing Switzerland's role as an active partner in global cyberpolicy.
Cybercrime: the AKIRA group steps up its activities
Joint press release from the OAG, fedpol, and the NCSC - In recent months, the hacker group AKIRA has stepped up its activities in Switzerland. Around two hundred companies have been victims of ransomware attacks, with damages currently amounting to several millions of Swiss francs, and to several hundreds of millions of dollars worldwide. Since April 2024, the Office of the Attorney General of Switzerland (OAG) has been conducting criminal proceedings. The investigation is being coordinated by the Federal Office of Police (fedpol), in close cooperation with the National Cyber Security Centre (NCSC) and the authorities in several other countries that are affected. The Swiss authorities stress the importance of contacting them before taking any action and of the need to file a criminal complaint.
Pilot project for testing security vulnerabilities in open source software
The National Cyber Security Centre (NCSC) and the National Test Institute for Cybersecurity (NTC) have conducted a pilot project to test two open source software solutions TYPO3 and QGIS for security vulnerabilities. Vulnerabilities were found in both products, which have since been fixed by the developer community. The pilot project has shown that targeted testing can strengthen the security of open source software (OSS) and increase Switzerland's cyber resilience. The NCSC is currently examining how security testing of OSS can be established on a permanent and structured basis in the future.
Six-month reporting obligation for cyberattacks on critical infrastructures
Since 1 April 2025, there has been a legal obligation in Switzerland to report cyberattacks on critical infrastructure. The National Cyber Security Centre (NCSC) regards the results after the first six months as positive. So far, a total of 164 reports have been received from critical infrastructures. From 1 October 2025, the planned sanctions for failing to report attacks will come into force.
2025 National Cybersecurity Conference: ‘Cyber resilience: Regulation or personal responsibility?’
Current debate in the field of cybersecurity focuses on the optimal interplay between state regulation and individual responsibility. The theme of the National Cybersecurity Conference held today in Bern was ‘Cyber resilience: Regulation or personal responsibility?’ Around 250 representatives from the fields of politics, public administration, business and academia discussed the key challenges in ensuring digital security in Switzerland. Federal Councillor Martin Pfister opened the event and argued that personal responsibility and regulation should go hand in hand.
Cyber Security Month 2025: Together against phishing – how to protect your data
Phishing is and remains one of the biggest threats on the Internet. In October, the National Cyber Security Centre (NCSC) is organising an awareness campaign as part of the annual Cyber Security Month. This year's campaign focuses on the dangers of phishing and asks the question ‘How do I protect my data online?’. Much of the campaign content and a quiz were created in collaboration with the association Netpathie, working with young people. In a webinar, social engineer and campaign ambassador Ivano Somaini will demonstrate how cybercriminals use public or hacked data for attacks.
Florian Schütz, Director of the NCSC, to visit cybertech conferences in Tokyo and Osaka
The Director of the National Cyber Security Centre (NCSC), Florian Schütz, will be attending this year's cybertech conferences in Osaka and Tokyo. During his visit to Japan from 1 to 4 September, he will take part in various events, panels and bilateral talks with representatives from industry and government.
Federal Council to strengthen cyber resilience of digital products
Although preventing security vulnerabilities is crucial for cybersecurity, Switzerland currently has few regulations regarding the cyber resilience of digital products. The Federal Council aims to change this. At its meeting on 20 August, it tasked the DDPS, in collaboration with DETEC and the EAER, with drafting a bill to be submitted for consultation. This new legislation will raise security requirements for products containing digital components, responding to the demands of Motion 24.3810, ‘Conducting urgently needed cybersecurity checks’, which was submitted by the Security Policy Committee of the Council of States.
Shielding critical infrastructure against cyberattacks: three suspected criminals identified
The Office of the Attorney General (OAG) initiated criminal proceedings against persons unknown in response to a spate of DDoS attacks targeting a number of federal websites in June 2023, for which the pro-Russian collective "NoName057(16)" claimed responsibility. In the spring of 2025, several members of this collective could be identified following an extensive international investigation to which the OAG and fedpol contributed significantly. The OAG has broadened the criminal proceedings to include three ringleaders of this collective and issued warrants for their arrests. The operators of the more than 200 Swiss websites targeted where feasible received prior warning and support in warding off the attacks from the National Cyber Security Centre (NCSC). The whole process can be considered a success story, highlighting the value of international cooperation in the fight against cybercrime.
Report on the ‘Switzerland's most important digital data’ workshops
The National Cyber Security Centre (NCSC) is currently working on a framework for implementing Motion 23.3002 ‘Greater security for Switzerland's most important digital data’. The motion calls for federal government, the cantons, the communes and operators of critical infrastructures to enhance the security of their most important digital data. To implement the motion, the NCSC held practical workshops with critical infrastructure operators. The findings of these workshops have now been published in a report, which will serve as a basis for further action.
“Switzerland's Security 2025”: Global confrontation has direct effects on Switzerland
The security situation around Switzerland is deteriorating year by year. A global confrontation is emerging, with the USA on one side and China and Russia on the other. This has direct implications for Switzerland: the threat of espionage is high and proliferation activities are increasing. The terrorist threat remains elevated. Particularly concerning is the growing online radicalization of youth. In its new situation report “Switzerland's Security 2025,” the Federal Intelligence Service (FIS) assesses the threat landscape facing the country.
Cyberattack on Radix: Federal Administration data also affected
The foundation Radix has been targeted by a ransomware attack, during which data was stolen and encrypted. Radix’s customers include various federal offices. The data has been published on the dark web and will now be analysed by the relevant offices.
Florian Schütz to attend WEF Roundtable in Paris
The Director of the National Cyber Security Centre, Florian Schütz, will attend the international World Economic Forum Roundtable in Paris on 17 and 18 June. Under the slogan ‘Rethinking Cyber Resilience in an Era of Complexity’, international experts from politics, business and administration will discuss key issues, current initiatives and joint approaches to improving global cyber resilience in an increasingly complex digital world.
Simple cybersecurity for SMEs
Small and medium-sized enterprises (SMEs) face the challenge of protecting their IT systems against cyberattacks. Although awareness of cyber risks has increased, implementing protective measures often proves difficult. To support SMEs in taking their first steps towards cybersecurity, the National Cyber Security Centre (NCSC), ITSec4KMU and the Swiss Insurance Association (SIA) recently organised an information event where experts provided SMEs with a simple introduction to this important topic.
Enhanced cybersecurity cooperation in the financial sector: NCSC and Swiss FS-CSC strengthen partnership
The National Cyber Security Centre (NCSC) and the Swiss Financial Sector Cyber Security Centre (Swiss FS-CSC) are strengthening their partnership to bolster cybersecurity across Switzerland's financial sector. With the cooperation agreement, they are joining forces and implementing targeted measures against growing cyberthreats.
First implementation report on the National Cyberstrategy
At its meeting on 14 May the Federal Council took note of the first implementation report on the National Cyberstrategy (NCS). The report outlines the status of national efforts to strengthen cybersecurity. It was prepared by the NCS Steering Committee in collaboration with the National Cyber Security Centre (NCSC). The report clearly shows that progress has been made: key coordination structures have been established, ongoing projects implemented and new ones launched, and Switzerland’s international profile in the field of cybersecurity has been raised.
Cross-border cyberthreats require international solutions
The latest semi-annual report from the National Cyber Security Centre (NCSC) outlines how cybercriminals operate internationally and the methods they use for their attacks. In light of these global cyberthreats and our ever-growing dependence on global software, international cooperation is becoming increasingly important. To strengthen cybersecurity in Switzerland, a reporting obligation for cyberattacks on critical infrastructure came into force on 1 April. This was developed in close alignment with international standards and EU directives.
DDPS and other federal departments to provide security support for Eurovision Song Contest in Basel
From 11 to 17 May, Basel will host the Eurovision Song Contest, a major event that will see extensive support from various agencies of the Federal Department of Defence, Civil Protection and Sport, the Federal Office of Police, and the Federal Office for Customs and Border Security. These agencies will work alongside the organisers and cantonal authorities to ensure the security of the event, with the Confederation making a crucial contribution to public safety.
NCSC Director Florian Schütz to attend RSA Conference in San Francisco
The director of the National Cyber Security Centre (NCSC), Florian Schütz, will be attending the RSA Conference in San Francisco from 28 April to 1 May. The conference is one of the leading events in the field of cybersecurity bringing together representatives from industry, society and government to discuss a host of cyber-related topics. Florian Schütz will be accompanied by Ambassador Benedikt Wechsler and will take part in various panels and bilateral discussions with representatives from industry and international organisations.
‘No excuses – Do it!’- Launch of the 2025 national cybersecurity awareness campaign
People often neglect to set secure passwords and install security updates. The National Cyber Security Centre (NCSC), the Swiss Crime Prevention Unit (SCP), cantonal and municipal police forces, Swiss Federal Railways (SBB), Swiss Post and the Swiss Insurance Association (SIA) are launching the next stage of the ‘S-U-P-E-R.ch’ campaign to raise public awareness about cybersecurity under the slogan ‘No excuses – Do it now!’.
Reporting cyberattacks on critical infrastructure mandatory from 1 April
At its meeting on 7 March, the Federal Council introduced a reporting obligation for cyberattacks on critical infrastructure, which will come into force on 1 April. Operators of critical infrastructure will be required to report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of discovery. These reports will enable the NCSC to assist victims of cyberattacks and alert operators of critical infrastructure.
Cybersecurity: NCSC Director Florian Schütz attends various international events
To strengthen international cooperation in cybersecurity, Florian Schütz, director of the National Cyber Security Centre (NCSC), has been attending various international cybersecurity events over the past few days. He chaired a panel at the AI Action Summit in Paris on building trust in artificial intelligence, met with cybersecurity authorities ahead of the Munich Security Conference and took part in a discussion at the Munich Cybersecurity Conference on the latest developments and best practices.
Cyber Security Centre Director Florian Schütz attends WEF
At the World Economic Forum (WEF) in Davos, cybersecurity was a major theme at a number of side events attended by a small delegation from the National Cyber Security Centre (NCSC), led by Director Florian Schütz. Among other things, Mr Schütz took part in a panel discussion on policy and strategic approaches to strengthening trust in digital products and the use of artificial intelligence in post-quantum cryptography. The delegation also attended the Geneva Dialogue event (a platform for exchanging ideas on responsible behaviour in cyberspace) at the House of Switzerland, and held bilateral meetings with representatives of the cybersecurity industry.
2024
Federal Council adopts Digital Switzerland Strategy 2025
On 13 December, the Federal Council adopted the updated Digital Switzerland Strategy for 2025 and selected new focus themes, thereby setting its current priorities.
President Amherd and Federal Councillor Parmelin receive Swedish Minister for Civil Defence Bohlin in Bern
On 12 November, President Viola Amherd, head of the Federal Department of Defence, Civil Protection and Sport (DDPS) and Federal Councillor Guy Parmelin, head of the Federal Department of Economic Affairs, Education and Research (EAER), will receive Sweden’s Minister for Civil Defence Carl-Oskar Bohlin in Bern for an exchange on current security policy issues.
Digital Switzerland Advisory Board: Cybersecurity is an important basis for digitalisation
At the meeting of the Digital Switzerland Advisory Board on 8 November, the National Cyberstrategy (NCS) was the focus of discussions. Under the leadership of the President of the Swiss Confederation Viola Amherd and with the participation of Federal Chancellor Viktor Rossi, representatives of the cantons, business, science and civil society took stock of cybersecurity measures and highlighted the challenges and opportunities of the current strategy.
A cyberincident reported every 8.5 minutes
Cyberthreats are increasing significantly: so far this year, the National Cyber Security Centre (NCSC) has received, on average, a cyberincident report every 8.5 minutes. With 34,789 cyberincidents reported to the NCSC in the first half of 2024, numbers have almost doubled compared to the same period last year. The increase is due in particular to a massive rise in fraud attempts, which at 23,104 cases account for two thirds of all reports. Most of these cases involve telephone fraud, as explained in a separate report.
Florian Schütz attends Counter Ransomware Initiative annual summit
Florian Schütz, Director of the National Cyber Security Centre (NCSC), took part last week in the Counter Ransomware Initiative annual summit as head of the Swiss delegation. Approaches and solutions to combat ransomware attacks were discussed and concrete measures presented at the four-day summit. In a bilateral meeting, the NCSC director and the director of the Information Tech-nology Laboratory of the National Institute for Standards and Technology (NIST) agreed to boost their technical cooperation.
AI in cyberattacks – the NCSC's focus during European Cyber Security Month
Artificial intelligence (AI) is increasingly being used in cyberattacks, particularly social engineering attacks. For this year's European Cyber Security Month (ECSM), the National Cyber Security Centre (NCSC) will be raising public awareness of this cyberthreat. The ECSM takes place every October and is organised by the European Union Agency for Cybersecurity (ENISA) together with the European member states.
2024 National Cybersecurity Conference: focus on geopolitics and operational security
Cyberthreats play an important role in today's tense geopolitical climate, but they have long been an everyday risk for businesses and governments. The National Cybersecurity Conference held today highlighted how a comprehensive approach can be taken to tackle cyberthreats. In her opening remarks, President Viola Amherd stated that the foundations for cybersecurity are now in place so that emphasis can now be placed on setting strategic priorities. The conference, organised by the National Cyber Security Centre (NCSC) and the Swiss Security Network (SSN), was attended by over 280 participants from business, science, and cantonal and federal offices.
Cybersecurity in the supply chain
The increasing interconnectedness of systems along the supply chain provides cybercriminals with many different ways to attack an organisation. It is therefore important for companies and public authorities to understand their supply chains and be aware of the cyber risks they face. National Cyber Security Centre (NCSC) has launched a pilot project together with Planzer Transport AG so that companies, authorities and organizations in Switzerland can easily implement their cyber security requirements in the supply chain. A simple cycle was designed to demonstrate protective measures against cyber attacks in the supply chain. The pilot project also provides specific tools that are published on the NCSC website. At the Online Brownbag Lunch on 5 September 2024, the NCSC and Planzer Transport AG will demonstrate how organizations can correctly assess cyber risks in their supply chains.
Federal Council approves Switzerland's participation in two PESCO projects
At its meeting on 21 August, the Federal Council approved Switzerland's participation in two EU Permanent Structured Cooperation (PESCO) projects. The two projects, Military Mobility and Cyber Ranges Federation, offer the opportunity to expand international cooperation between armed forces. This will strengthen Switzerland's national defence capability. Switzerland’s work on the projects will be carried out in accordance with its neutrality obligations.
Florian Schütz in Seoul to take part in the OECD's Global Forum on Digital Security for Prosperity
Florian Schütz, Director of the National Cyber Security Centre (NCSC) and Chairman of the Working Party on Digital Security (WPDS) of the Organisation for Economic Co-operation and Development (OECD), will take part in the Global Forum on Digital Security for Prosperity, which is being held in Seoul from 10 to 11 July 2024. His schedule includes chairing a panel dealing with the topic of regulation in digital security. The aim of the event is to conduct a joint dialogue, exchange experiences and work on the development of public strategies in the field of digital security.
Summit on Peace in Ukraine: first NCSC report on Cyber Situation Network
Even before the Summit on Peace in Ukraine got under way, cyberattacks on the conference and network infrastructure in Switzerland were expected. A number of cyberattacks were then confirmed, but they were all detected early and quickly averted. In order to jointly counter the expected cyberattacks, Switzerland set up a Cyber Situation Network coordinated by the National Cyber Security Centre (NCSC). Today, the NCSC published an initial review of the work of the Cyber Situation Network.
Cyber Europe 2024: Focus on the energy sector
Cyber Europe 2024, the 7th edition of the European cyber exercise, will take place over the next two days. In recent years, exercises have been based on scenarios covering the healthcare sector, civil aviation and telecommunications. This year, the focus is on the energy sector. Switzerland is a co-organiser and an important partner of Cyber Europe 2024. Under the lead of the National Cyber Security Centre (NCSC), the exercise will also involve other federal agencies and around 30 organisations from the Swiss energy sector.
Introducing SMEs to cybersecurity
The National Cyber Security Centre (NCSC) joined forces with the association ITSec4KMU to organise an awareness-raising event on cybersecurity for SMEs. This free event held at the Cinématte in Bern gave more than 100 interested representatives from SMEs an easy introduction to this important topic. There are plans to repeat the event in other regions of Switzerland.
DDPS sets up National Cyberstrategy steering committee
A steering committee has been set up to manage the National Cyberstrategy (NCS) implementation process. It supports the federal, cantonal, business and academic bodies concerned in implementing the NCS in a targeted and effective manner. The Federal Department of Defence, Civil Protection and Sport (DDPS) appointed the members of the steering committee and informed the Federal Council of the appointments at the latter's meeting on 7 June.
High-level conference on peace in Ukraine: military support and airspace restriction
At its meeting on 22 May, the Federal Council approved a temporary restriction on the use of airspace during the high-level conference on peace in Ukraine, which Switzerland will be hosting on 15 and 16 June at the Bürgenstock resort in the canton of Nidwalden. The Swiss Air Force will provide air policing and advanced air surveillance services. The Armed Forces will also set up a subsidiary support service to complement the security measures of the cantonal authorities.
Federal Council launches consultation on Cybersecurity Ordinance
At its meeting on 22 May the Federal Council launched a consultation on the Cybersecurity Ordinance. The Ordinance sets out how the obligation to report cyberattacks on critical infrastructure is to be implemented, regulates how implementation of the National Cyberstrategy is to be organised and specifies the tasks of the new National Cyber Security Centre (NCSC). The Ordinance also specifies which authorities and companies are exempt from the reporting obligation. The consultation will run until 13 September 2024.
Florian Schütz in Birmingham: Greater international cooperation in cybersecurity
The director of the National Cyber Security Centre (NCSC), Florian Schütz, will be attending two key international events in the field of cybersecurity in Birmingham on 13–15 May. The trip is aimed at strengthening international cooperation on cybersecurity and the fight against ransomware.
Twice as many cyber incidents reported and rise in AI scam attempts
More than 30,000 cyber incidents were reported to the NCSC in the second half of 2023, twice as many as in the same period last year. The strategy of the new federal office is based on four pillars in order to strengthen cyber security for the general public, businesses and public authorities in the face of increasing threats and the emergence of AI-driven fraud.
Improve your digital health – launch of national cybersecurity awareness campaign focusing on updates and virus protection
Regular updates and up-to-date virus protection greatly improve cybersecurity. This is why the National Cyber Security Centre (NCSC), Swiss Crime Prevention (SCP) and cantonal and communal police forces are now launching a further part of the national S-U-P-E-R.ch campaign emphasising the importance of up-dates and virus protection. The campaign is supported by the internet security platform iBarry and "eBanking – but secure!" (EBAS).
Discussions between the National Cyber Security Centre and the French Cybersecurity Agency (ANSSI)
Florian Schütz, Director of the National Cyber Security Centre (NCSC), will meet with his French counterpart, Vincent Strubel, Director General of the French Cybersecurity Agency (ANSSI), on 3 April to discuss cybersecurity issues and strengthen relations between the two countries.
Hacker attack on Xplain: National Cyber Security Centre publishes data analysis report
The National Cyber Security Centre (NCSC) took over responsibility for incident management in the Federal Administration in the wake of the hacker attack on Xplain, a major provider of IT services to national and cantonal authorities. Part of its activities involved analysing the data that the perpetrators published on the darknet. The NCSC released a report today explaining its analysis and providing information on what type of data was affected and the challenges associated with analysing the data. The report does not evaluate the content of the data, nor does it analyse why certain data was leaked. The latter question will be clarified as part of the ongoing administrative investigation.
Florian Schütz takes part in the Common Good Cyber Workshop 2024 in Washington D.C.
On 26 and 27 February, Switzerland will once again play an active international role in efforts to improve cyber security. Florian Schütz, Director of the National Cyber Security Centre (NCSC), will take part in the Common Good Cyber Workshop 2024 in Washington D.C., organised by the NGO Global Cyber Alliance.
Several Federal Administration websites disrupted temporarily by DDoS attack
A DDoS attack disrupted temporarily access to a number of websites today, including some belonging to the Federal Administration. The Russian-linked hacker group ‘NoName’ claimed responsibility for the attack, citing Ukrainian President Zelenskyy's attendance at the WEF Annual Meeting. The cyberattack was promptly detected and the Federal Administration's specialists took the necessary action to restore access to the websites as quickly as possible. An attack of this kind had been expected, and appropriate security measures were in place. DDoS attacks are aimed at making websites unavailable. They do not result in any data being lost or compromised.
2023
Manuel Suter appointed Deputy Director of National Cyber Security Centre (NCSC)
The head of the DDPS, Federal Councillor Viola Amherd, has appointed Manuel Suter as Deputy Director of the NCSC as of 1 January 2024. The Federal Council was informed of the appointment at its meeting on 22 December.
Information sharing and community building to boost cyber-resilience in International Geneva
On 30 November, the Federal Department of Foreign Affairs (FDFA) and the National Cyber Security Centre (NCSC) held a 'Cyber Capacity and Community Building' event in Geneva in cooperation with the canton of Geneva and other partners. The event was aimed at boosting the cyber-resilience of international organisations and NGOs in International Geneva.
Federal Administration also impacted by Concevis hack
The software company Concevis has fallen victim to a ransomware attack, causing all of its servers to be encrypted. As far as is currently known, the stolen data is believed to include older operational data from the Federal Administration. In-depth analyses are still ongoing.
NCSC semi-annual report focuses on hacktivism
The National Cyber Security Centre (NCSC) today published its latest semi-annual report. This looks at the main cyberincidents that occurred in Switzerland and abroad in the first half of 2023, with a special focus on hacktivism.
Xplain hack: Federal Council approves investigation order
At its meeting of 23 August 2023, the Federal Council ordered an administrative investigation into the events surrounding the data leak at Xplain AG and approved the investigation order. As instructed by the Federal Council, the Federal Department of Finance (FDF) will appoint an investigative body. It will mandate the Geneva-based law firm OBERSON ABELS SA for this role. In its capacity as an independent body, it is to investigate whether the Federal Administration adequately complied with its duties when selecting, instructing, supervising and working with Xplain AG. Furthermore, measures are to be identified to prevent a similar incident from occurring in the future.
Xplain hack: Federal Council commissions a policy strategy crisis team on data leaks
During its meeting on 28 June 2023, the Federal Council commissioned a policy strategy crisis team on data leaks. The aim of the cross-departmental crisis team is to coordinate the ongoing efforts to deal with the ransomware attack on Xplain, which has also affected Federal Administration data, and to propose related measures. In addition, the Federal Council ordered that a mandate be drawn up for an administrative investigation. Moreover, it decided to review existing contracts with federal IT service providers and to amend them where necessary in order to improve service providers' cybersecurity and allow the federal government to react swiftly in the event of a successful attack. Finally, it ordered an examination of measures to ensure that the essential services currently provided by Xplain for the police and the security and migration authorities can be guaranteed in any case.
Xplain hack: initial findings from data analyses indicate need for action
Following the discovery of the ransomware attack on Xplain, intensive investigations concerning the data affected have been under way in the Federal Administration. The data analysed to date also includes operational data from various authorities and organisations. How this data got onto the Xplain infrastructure is now being meticulously clarified.
DDoS attack on Federal Administration: various Federal Administration websites and applications unavailable
Several Federal Administration websites are/were inaccessible on Monday 12 June 2023, due to a DDoS attack on its systems. The Federal Administration's specialists quickly noticed the attack and are taking measures to restore accessibility to the websites and applications as quickly as possible.
Federal Administration also impacted by Xplain hack
Based on the information currently available, it appears that operational data of the Federal Administration could also be affected by the ransomware attack on the IT company Xplain, which resulted in some of the stolen data being published on the darknet. In-depth analyses are still ongoing.
Florian Schütz appointed director of the new Federal Office for Cyber Security
At its meeting on 24 May, the Federal Council appointed Florian Schütz, currently the Federal Cyber Security Delegate and head of the National Cyber Security Centre (NCSC), as director of the new Federal Office for Cyber Security as of 1 January 2024.
NCSC semi-annual report focuses on cybersecurity in SMEs
The National Cybersecurity Centre's (NCSC) second semi-annual report deals with the most important cyberincidents of the second half of 2022 in Switzerland and internationally. It focuses on the most important issues surrounding cybersecurity in SMEs.
Federal Council and cantons define new national cyberstrategy
The new national cyberstrategy (NCS) was approved by the Federal Council during its meeting on 5 April 2023 and by the cantons during today's plenary session of the CCJPD. The strategy sets out the objectives and measures with which the federal government and the cantons, together with the business community and universities, intend to counter cyberthreats. A steering committee will be established to plan and coordinate the implementation of the strategy, and will also refine it. Its role is to be expanded and its independence increased.
2022
Switzerland takes part in discussions at OECD Digital Economy Ministerial Meeting
The OECD Digital Economy Ministerial Meeting was held on the Spanish island of Gran Canaria on 14 and 15 December. At the event, government officials from fifty different countries, including Switzerland, met with business leaders and civil society representatives to discuss topics such as artificial intelligence, data governance, the future of connectivity, cybersecurity and human rights in the digital age. The gathering concluded with the adoption of two ministerial declarations and a series of recommendations on cybersecurity.
NCSC to become federal office in DDPS
Based on the growing significance of cybersecurity and the good work done in recent years to establish the National Cybersecurity Centre (NCSC) in the Federal Department of Finance (FDF), the NCSC is to become a federal office. During its meeting on 2 December 2022, the Federal Council decided that the new federal office will be located in the Federal Department of Defence, Civil Protection and Sport (DDPS). It instructed the DDPS, in collaboration with the FDF, to define the structures of the new federal office by end-March 2023.
Federal Council submits dispatch on mandatory reporting of cyberattacks on critical infrastructures to Parliament
The Federal Council wants to introduce a reporting duty for cyberattacks on critical infrastructures. To this end, during its meeting on 2 December 2022, it adopted the dispatch on amending the Information Security Act and submitted it to Parliament. The proposal creates the legal basis for the reporting obligation for the operators of critical infrastructures and defines the tasks of the National Cybersecurity Centre (NCSC), which is intended to be the central reporting office for cyberattacks.
Federal Cybersecurity Delegate represented Switzerland at International Counter Ransomware Initiative Summit in Washington
On 31 October and 1 November 2022, the White House brought together 36 countries and the EU for the Second International Counter Ransomware Initiative Summit in Washington. Florian Schütz, the Federal Cybersecurity Delegate, put forward Switzerland's position in the five working groups. He also met with Chris Inglis, the US National Cyber Director, for a bilateral exchange.
NCSC semi-annual report with focus on cyberspace and armed conflicts
The latest semi-annual report of the National Cybersecurity Centre NCSC deals with the most important cyberincidents of the first half of 2022 both in Switzerland and internationally. The focus topic concerns cyberspace and armed conflicts.
Bug bounty programme carried out for the Confederation's eIAM central access system
The Federal Administration carried out a bug bounty programme for eIAM, the Confederation’s central access system, from 30 August to 11 October. System security was further strengthened through a review by ethical hackers.
Launch of the national cybersecurity awareness campaign
Cyberattacks via email and messenger services are on the rise. They can be detected by critically examining messages, thereby making it possible to avoid major financial losses and personal suffering. To promote public awareness, the National Cybersecurity Centre NCSC and Swiss Crime Prevention SCP, together with the cantonal and city police forces, are launching the S-U-P-E-R.ch national cybersecurity awareness campaign on 5 September 2022.
Federal Administration procures platform for bug bounty programmes
In order to increase the cybersecurity of the IT infrastructure and reduce cyber-risks effectively and cost-efficiently, the Confederation is procuring a centralised platform for bug bounty programmes. Under the auspices of the National Cybersecurity Centre (NCSC) and in collaboration with Bug Bounty Switzerland SA, ethical hackers will search the Federal Administration's IT systems for vulnerabilities.
National Cybersecurity Centre to become federal office
During its meeting on 18 May 2022, the Federal Council decided to turn the National Cybersecurity Centre (NCSC) into a federal office, and instructed the Federal Department of Finance FDF to prepare proposals by the end of 2022 regarding how the office should be structured and which department it should be part of.
Implementation of national cyberstrategy proceeding successfully and to be strengthened further
On 18 May 2022, the Federal Council took note of the report on the effectiveness assessment of the "2018-2022 national strategy for the protection of Switzerland against cyber-risks (NCS)" and decided to create a further 25 positions in the area of protection against cyber-risks.
NCSC semi-annual report with focus on supply chain attacks
The NCSC's latest semi-annual report deals with the most important cyberincidents of the second half of 2021 both in Switzerland and internationally. The focus topic concerns attacks on IT product supply chains.
Association founded to increase the cyber-resilience of the Swiss financial centre
On 5 April 2022, the Swiss Financial Sector Cybersecurity Centre (Swiss FS-CSC) association was founded in Zurich in the presence of Federal Councillor Ueli Maurer. The association aims to strengthen cooperation between financial institutions and authorities in the fight against cyberthreats, and to increase the resilience of the financial sector. The president of the association is August Benz, Deputy CEO of the Swiss Bankers Association.
Initiation of consultation on introduction of cyberattack reporting obligation
During its meeting on 12 January 2022, the Federal Council initiated the consultation on the proposed introduction of a reporting obligation for cyberattacks on critical infrastructures. The proposal creates the legal basis for the reporting obligation and defines the tasks of the National Cybersecurity Centre (NCSC), which is intended to be the central reporting office for cyberattacks. The consultation will last until 14 April 2022.
2021
Florian Schütz appointed Chair of the OECD Working Party on Security in the Digital Economy
On 23 November 2021, the Working Party on Security in the Digital Economy of the Organisation for Economic Co-operation and Development (OECD) appointed Florian Schütz, the Federal Cybersecurity Delegate, as its new Chair. Mr Schütz will formally start in this position as of 1 January 2022.
Second NCSC semi-annual report focuses on vulnerabilities
The National Cybersecurity Centre's (NCSC) second semi-annual report deals with the most important cyberincidents of the first half of 2021 in Switzerland and internationally. The main topic is dedicated to vulnerabilities in IT systems that can be exploited to carry out cyberattacks.
Cyberangriff auf EasyGov
Kriminellen Hackern ist es mutmasslich gelungen, eine Liste mit Namen von bis zu 130’000 Unternehmen zu entwenden, welche über die Plattform EasyGov im Jahr 2020 einen Covid-19-Kredit beantragt hatten. Weitere Daten ausser den Firmennamen wurden nach heutiger Erkenntnis nicht gestohlen. Das SECO, als Betreiberin von Easy-Gov, hat Sofortmassnahmen ergriffen und eine Untersuchung eingeleitet.
Successful bug bounty pilot project in Federal Administration
From 10 to 21 May 2021, the National Cybersecurity Centre (NCSC) conducted a bug bounty pilot project in collaboration with Bug Bounty Switzerland GmbH, the Federal Department of Foreign Affairs (FDFA) and Parliamentary Services (PS). The project was very successful and the lessons learned are to be incorporated into the implementation of further bug bounty programmes in the Federal Administration.
First NCSC semi-annual report with focus on healthcare
The National Cybersecurity Centre (NCSC) has been operational since 1 July 2020. The NCSC's first semi-annual report deals with the most important cyberincidents of the second half of 2020 in Switzerland and internationally. It replaces the former MELANI semi-annual report. The main topic is digitalisation in the healthcare sector and the challenges it faces with regard to current cyberthreats.
First bug bounty programme in the Federal Administration
On 10 May 2021, the Federal Administration and Bug Bounty Switzerland GmbH will launch a joint pilot project. The aim of the two-week test, which will be overseen by the National Cybersecurity Centre (NCSC), is to gather initial experience with bug bounty programmes and assess their future use in relation to the security of infrastructures in administrations and companies.
2020
29 October 2020
MELANI semi-annual report: cybersecurity situation during the coronavirus
19 October 2020
Implementation of 2018-2022 national strategy for protection of Switzerland against cyber-risks (NCS) on track
28 May 2020
Protection against cyber-risks: Federal Council approves ordinance and additional staff
29 October 2020
MELANI semi-annual report: cybersecurity situation during the coronavirus
2019
28 November 2019
Cybersecurity competence network: President Ueli Maurer holds second roundtable discussion with interested cantons
29 October 2019
Encryption Trojans still on the rise
14 June 2019
Florian Schütz to become federal Cyber Security Delegate
