Strong cybersecurity foundations for businesses and public authorities
Cyberattacks can affect any business or public authority, regardless of size, sector or technical expertise. The consequences range from temporary system failures and the loss of confidential data to liability issues and reputational damage. Effectively protecting against such threats therefore requires both technical and organisational measures that work in tandem. The following section outlines how businesses and public authorities can take targeted steps to tighten their cybersecurity.
Technical and organisational measures
Cyberattacks are not directed solely at employees; inadequately protected IT systems can also provide a gateway for hackers. Although technical measures play a key role in ensuring that information is kept secure, they must be supported by organisational measures. If measures are costly and/or labour-intensive, it is essential to weigh up the costs against the risks of not implementing them.
Cybersecurity is more than just a technical task for the IT department – it is a key responsibility of senior management. It is their task to decide where to invest resources to protect critical processes and the impacts it is prepared to accept.
Organisational measures
Organisational measures relating to cybersecurity are important to ensure that information is handled responsibly and securely within a company or public authority. A key component of these measures is raising staff awareness because of the crucial role staff play in information security in their day-to-day work.
Organisational measures also ensure that roles and responsibilities are clearly defined and understood by everyone involved.
The key organisational measures are:
When assessing the dependence of business processes on IT, it is important to consider the following: what impact would a system failure or the unavailability of the data storage have? What financial implications can be expected? What measures can be taken to counter this?
The NCSC’s Cybersecurity and Resilience Methodology (CSRM) provides an effective introduction to this assessment. It helps to identify IT objects requiring protection and tighten security precisely where a failure would cause the most damage. The IT department is responsible for operational implementation, while responsibility for risk classification and business continuity management remains with senior management.
Even if all or part of the IT system is temporarily out of action, it must still be possible to continue working. This does not necessarily have to be the result of a cyberattack – power outages, natural disasters and other scenarios can also cause a partial or even complete failure of your IT systems.
Identify possible alternatives for the relevant systems at an early stage, and draw up an emergency plan setting out how the organisation can continue to operate in the event of a temporary IT failure, and keep the plan on hand.
For all tasks relating to the security of ICT systems, responsibility should be clearly assigned to the appropriate individuals within the organisation. Roles, responsibilities and decision-making authority for emergency and crisis management should also be clearly defined.
Many smaller organisations outsource their IT to specialist service providers. In today’s IT landscape, organisations also use cloud services such as Microsoft 365. This makes it crucial to define responsibilities clearly: the service provider protects the platform, but the organisation protects the actual data. Liability in the event that security regulations are breached or IT security is otherwise neglected is defined in the contract. The contract, therefore, must be worded clearly and unambiguously.
When using the cloud, the following applies: sensitive information should never be stored unencrypted, and before use, the data protection provisions and storage locations (ideally Switzerland or the EU) must be carefully reviewed to ensure compliance with the Swiss Data Protection Act (FADP). Before using a cloud service, you must read the provider's terms and conditions.
A data and information inventory must be drawn up, identifying and defining particularly sensitive data and information assets. The inventory serves as the basis for developing a security plan for these assets.
Careful consideration must be given to the information published on your own website or on social media, as this can be systematically collected by criminals. Those responsible for financial transactions and with access to online banking should not be named on the website. Details about those responsible for finances are often used as the basis for targeted fraud attempts (e.g. CEO fraud). When making payment orders, it is advisable to use a dedicated computer that is not used for general web browsing or receiving emails. Systematically applying dual-control approval for payments as well as restricting functions (e.g. country restrictions) significantly reduces the risk of financial misuse.
As a general rule, no confidential information or data should be disclosed via impersonal channels such as by telephone or email. Confidential information should always be encrypted or sent to external parties by post.
Raising all employees' awareness regarding the use of IT infrastructure is of paramount importance. Provide staff with regular training on how to deal with potential threats in the digital world, so that they can spot fraudulent phone calls or emails.
Employees also need to know who to contact if they have questions about IT security, or who to notify in the event of an IT security incident. A proactive reporting culture, in which employees can immediately report mistakes without fear or blame, is often the key to preventing more serious damage.
E-learning platform of the Conference of Cantonal Justice and Police Directors (CCJPD): elearningcyber.ch.
Passwords play an important role in protecting data and systems effectively, but they are not enough on their own. Multi-factor authentication (MFA) should be used for all business-critical access points. When choosing passwords, prioritise length over complicated sequences of special characters. Passwords should be at least twelve characters long and include a mix of upper- and lower-case letters, numbers and special characters. Avoid using the same password for multiple accounts. The NCSC recommends using a password manager, which is also useful for generating passwords for each application. Passwords and login details must never be shared with anyone.
Malware often finds its way onto computers via email attachments disguised as genuine invoices or job applications. It is therefore advisable to block the receipt of harmful email attachments and to ensure that macros in Office documents from unreliable sources cannot be executed.
Channels for employees to report suspicious incidents should be established. Send emails in text format only and use PDF documents where possible instead of Office documents containing macros. Links can be made transparent by writing them out in full.
Links to websites that request usernames, passwords or other personal details should also be avoided. Where possible, email recipients should be addressed by their first and last names to help prevent mass phishing attempts.
Use a dedicated computer for all digitally transmitted payment orders; do not use the same computer to browse the internet or check your emails. Establish procedures for all payment transactions and ensure they are consistently adhered to: the dual-control principle, joint signatures and restricting functions significantly reduce the risk of financial fraud. This is particularly important where several employees are authorised to make payments. Discuss possible security measures with your bank.
Technical measures include a range of technologies and processes designed to protect IT systems, networks and data from unauthorised access, tampering and outages. They are an important foundation for cybersecurity.
However, they should not be implemented in isolation – they must be supported by organisational measures.
The ICT infrastructure should be documented in an inventory list that is as detailed as possible. Only those who are familiar with their ICT infrastructure, services, computers and users will know what needs to be protected and monitored. Above all, organisations should know which systems are connected to the internet and are consequently visible to the public – these systems must be provided with particularly robust protection.
Data backups are the best insurance against ransomware attacks. A clearly defined process governing routine data backups – and one that is applied consistently – provides an effective safeguard. At least one copy of the data must be stored offline and at an external location – this is the only way to ensure that the backup itself is not encrypted during an attack.
Every organisation should consider how many days of data loss it can cope with and adjust its data backup schedule accordingly. The backup system should be checked regularly to ensure it is functioning correctly. It is also advisable to practise restoring backups from time to time, so that employees are familiar with the process in the event of an emergency. Previous versions of the backup should be retained for a period of several months.
Outdated hardware and software are a common point of entry for malware. Consequently, systems must be kept fully updated. This also applies to a website's content management system (CMS) and to hardware such as printers and routers. Any installed software must be updated immediately as soon as security updates become available.
All computers should be installed with antivirus software providing real-time scanning. In addition, systems should be updated regularly and a full system scan carried out periodically.
A firewall should be used on every computer, and the company network should be protected from the internet by an additional firewall. Defining firewall rules helps to control which incoming and outgoing connections are permitted. A restrictive approach should be taken here, allowing only the necessary connections in both directions. Furthermore, a DNS server should be chosen that blocks well-known websites containing malicious content.
Remote access to the company network must under no circumstances be protected by simple authentication alone (i.e. username and password). At the very least, two-factor authentication should be used, or it must be ensured that a secure connection is established via a virtual private network (VPN). This also applies to access by external ICT officers.
Organisational networks should be divided into individual segments, e.g. separate networks for production, human resources and accounting. Giving access rights across multiple sections should be avoided. Systematic network segmentation prevents malware from spreading unchecked. It also reduces the risk of outdated systems that can no longer be updated – such as industrial control systems used in manufacturing facilities – becoming a gateway for attackers. Your IT service provider can offer advice on planning and implementation.
Further information
Industrial espionage in Switzerland – Prevention through awareness The short film “Im Visier” forms part of the Federal Intelligence Service “Prophylax” prevention and awareness-raising programme. The film aims to highlight the risks posed by espionage to Switzerland's business and research sectors.
E-learning programme on cyber- and information security for local authorities The plenary assembly of the Conference of Cantonal Justice and Police Directors (CCJPD) has approved a cyber training programme for the public sector. The e-learning programme is also available to towns, cities and communes.
E-Learning platform of the Conference of Cantonal Justice and Police Directors (CCJPD): elearningcyber.ch
The following labels were developed in collaboration with NCS partners and are supported by the NCSC. They help to assess cybersecurity within your organisation: