Skip to main content

Strong cybersecurity foundations for businesses and public authorities

Cyberattacks can affect any business or public authority, regardless of size, sector or technical expertise. The consequences range from temporary system failures and the loss of confidential data to liability issues and reputational damage. Effectively protecting against such threats therefore requires both technical and organisational measures that work in tandem. The following section outlines how businesses and public authorities can take targeted steps to tighten their cybersecurity.

Technical and organisational measures

Cyberattacks are not directed solely at employees; inadequately protected IT systems can also provide a gateway for hackers. Although technical measures play a key role in ensuring that information is kept secure, they must be supported by organisational measures. If measures are costly and/or labour-intensive, it is essential to weigh up the costs against the risks of not implementing them.

Cybersecurity is more than just a technical task for the IT department – it is a key responsibility of senior management. It is their task to decide where to invest resources to protect critical processes and the impacts it is prepared to accept.

Organisational measures

Organisational measures relating to cybersecurity are important to ensure that information is handled responsibly and securely within a company or public authority. A key component of these measures is raising staff awareness because of the crucial role staff play in information security in their day-to-day work.

Organisational measures also ensure that roles and responsibilities are clearly defined and understood by everyone involved.

The key organisational measures are:

Technical measures

Technical measures include a range of technologies and processes designed to protect IT systems, networks and data from unauthorised access, tampering and outages. They are an important foundation for cybersecurity.

However, they should not be implemented in isolation – they must be supported by organisational measures.

ICT minimum standard

The most important technical measures are:

Further information

Industrial espionage in Switzerland – Prevention through awareness
The short film “Im Visier” forms part of the Federal Intelligence Service “Prophylax” prevention and awareness-raising programme. The film aims to highlight the risks posed by espionage to Switzerland's business and research sectors.

Industrial espionage in Switzerland – Protection through prevention and awareness-raising (German)

E-learning programme on cyber- and information security for local authorities
The plenary assembly of the Conference of Cantonal Justice and Police Directors (CCJPD) has approved a cyber training programme for the public sector. The e-learning programme is also available to towns, cities and communes.

E-Learning platform of the Conference of Cantonal Justice and Police Directors (CCJPD): elearningcyber.ch

If you have any questions, please email: info@elearningcyber.ch

Guidance and practical resources

The following guidelines have been developed in collaboration with partners of the National Cyberstrategy (NCS):

ICT minimum standard as a checklist for your basic technical security

Alliance Digital Security Switzerland: Cybersecurity Check

Trust Valley: Digital security: a practical guide for SMEs

Cybersecurity labels

The following labels were developed in collaboration with NCS partners and are supported by the NCSC. They help to assess cybersecurity within your organisation:

Cyber-safe.ch – The Swiss cybersecurity label (German and French)

Alliance Digital Security Switzerland: CyberSeal - The Seal of Approval (specifically for IT service providers)