Working with IT service providers
While larger companies often have their own IT departments, many smaller companies outsource these tasks. It is important to ensure that responsibilities for IT security are clearly defined between you and your IT service provider, particularly when it comes to technical and organisational measures. Your contract should also clearly set out who is liable if agreed security measures are not implemented and this results in damage.
To ensure that your company is not just functional, but also resilient and legally compliant, you should ask your service provider the following questions:
Where exactly is my data stored, and how will you help me comply with the Swiss Data Protection Act (FADP)?
Under the revised FADP (German, French and Italian), you need to know whether your data is stored in Switzerland, the EU or a third country (such as the USA). A competent partner should not only be able to tell you where your data is stored, but also offer you a data processing agreement (DPA) that sets out how your data will be handled in compliance with data protection law.
What is your backup policy, and when was your most recent successful restore test?
Simply copying data is not enough. A professional service provider must be able to guarantee that the backups will actually work in an emergency. Ask specifically whether restore tests are carried out. Backups should also follow the 3-2-1 principle: three copies, two different storage devices, one copy off-premises and, ideally, offline. This helps limit the damage caused by ransomware attacks.
How will you ensure that all our systems and access to cloud services are protected with multi-factor authentication (MFA)?
Passwords alone are no longer enough to provide adequate protection. Because passwords can be stolen, guessed or intercepted, a second layer of protection is required – one that attackers can't get their hands on so easily. Your service provider should proactively urge you to set up MFA for all key services, such as Microsoft 365, remote maintenance access, and accounting software. If your partner describes this as “optional” or “too complicated for users”, you should be wary.
What proactive monitoring measures are included in the service?
Good partners don't wait for you to call and tell them something has stopped working. They should use systems that alert them automatically if a hard drive is running out of space, a security update has failed or suspicious login attempts have been detected. Ask whether this kind of managed service is included in your package.
What happens if there is a cyberattack at night or at the weekend? How can we reach you?
Cyberattacks don't keep office hours. It is essential to know whether your service provider has an emergency phone number and how quickly it can respond. These response times are usually defined in service-level agreements (SLAs). You should also clarify in advance what charges apply to emergency support outside normal business hours.
By asking these questions, you will signal to the service provider that security and data protection are important to you. A reputable provider will welcome these questions and be able to give you detailed information. If a provider is evasive about these issues or downplays their importance, it could be a sign that it is focusing more on short-term problem-solving than on long-term security.
It is important to remember, however, that responsibility cannot simply be outsourced or delegated. If an incident occurs, your company may ultimately still be held liable.
Follow the minimum requirements
- Carry out security checks when accepting newly integrated IT systems.
- Familiarise yourself with the relevant terms and conditions and other requirements governing the use of IT services. These requirements should form part of your contractual arrangements with external IT service providers.
- Confidentiality obligations must be clearly defined where third parties maintain or support ICT systems. Unnecessary access to particularly sensitive personal data should not be permitted.
- Appropriate checks must also be carried out and agreements put in place with companies that store your data, including cloud providers.
Further information
CyberSeal quality label
The CyberSeal quality label for IT service providers was launched as part of a public-private partnership involving the NCSC, Mobiliar, Secnovum and digitalswitzerland. IT service providers awarded the CyberSeal label guarantee their customers an appropriate level of protection against cyber risks through suitable technical and organisational measures.
“Cyber Safe” label
The “Cyber Safe” label was developed by the Swiss association responsible for the cybersecurity quality label. It defines minimum requirements specifically for communes and SMEs. An online questionnaire (German and French) can be used to assess the cyber risks faced by communes and SMEs.
Digital Public Services Switzerland
Digital Public Services Switzerland is responsible for the General Terms and Conditions for ICT services, a role it took over from the Swiss Informatics Conference (“Schweizerische Informatikkonferenz SIK”) on 1 January, 2022. It develops and negotiates these terms and conditions for use in ICT contracts.
Data Protection
Privatim (Conference of Swiss Data Protection Commissioners):
Practical information on data protection as well as a list of the relevant data protection supervisory authorities (German and French)
Federal Data Protection and Information Commissioner (FDPIC):
Data processing by private companies and federal bodies
Choosing an ICT service provider
Certifications based on recognised data protection and information security standards, or audit reports from independent third parties, can help you choose a suitable provider. You do not necessarily need to select a certified provider. What matters is that the ICT service provider can demonstrate that it meets your requirements and can provide the level of availability and security you need. Consider having this independently reviewed or verified.
Carry out security audits
The services agreed in the contract should be periodically reviewed in accordance with recognised audit standards, such as COBIT («Control Objectives for Information and Related Technology»), which was developed by the Information Systems Audit and Control Association (ISACA). Use independent auditors for this purpose. The ICT service provider may also commission either an ISAE 3402 Type 2 assurance report (International Standard on Assurance Engagements) or a SOC 2 report (Service Organisation Control). These audits assess aspects of security, availability, processing integrity and confidentiality.
