
There has been a marked increase in Internet crime, with criminal gangs now behind more than 80 per cent of attacks on companies and private individuals. Florian Schütz, Federal Cyber Security Delegate, explains in an interview who is particularly at risk and how you can protect yourself from attacks, including when working from home.
Over the last few years, we have been able to raise awareness of cyber security among the corporate sector and the population at large. But we are still seeing considerable differences in approach – especially among companies. Some companies are ill-prepared and continue to believe that cyber security is not a key issue for them. Others are taking the issue seriously, however, and investing accordingly. If you look at Switzerland as a whole, we are somewhere in the middle of the pack as far as cyber security is concerned. So we still have a lot of work to do.
Particularly in the business world, all too often there is still a tendency to see IT purely as a support service. It helps with financial accounting and is used for communications. The truth is, however, that IT is now a key cornerstone of any business. That’s why IT engineers should also be represented on management boards, for example, so that they can raise topics such as cyber security at that level. This has long been the case at international technology companies.
‘Criminals only need to identify one vulnerability in order to penetrate the system, while engineers cannot afford to make even a single mistake.’
One particular challenge is to develop IT systems that are as resilient as possible. The thing is, it is not a fair fight. Criminals only need to identify one vulnerability in order to penetrate the system, while engineers cannot afford to make even a single mistake.

Clearly advises against paying ransoms to cybercriminals: Florian Schütz, Federal Cyber Security Delegate. (© Keystone-SDA, Gaëtane Bally)
It’s not about companies or sectors, but rather the degree of digitalisation. The more digitalised a company is, the more of a target it becomes for cybercriminals. And the greater the amount of damage they can cause, for example by stealing personal data.
No, absolutely not. Companies must not allow themselves to be blackmailed by cybercriminals. Anyone who pays the ransom ends up supporting the business model and, worse still, the organised criminals behind it. It is better to contact the police or us to discuss how to proceed.
You should always keep your system up to date. As well as setting up a firewall, that means downloading the latest security updates for your hardware and software and activating the most recent version of your antivirus program. If you protect your personal computer from attacks, you are also helping companies in the process, because personal computers are often misused for attacks on companies. It’s also helpful to back up your data so that it is not lost in the event of an attack or any other incident such as a fire.
It’s certainly not an easy undertaking, but a risk assessment can definitely help a company evaluate the risks present in its business processes. You can never be totally secure, however. And nor would you want to be: If risk were reduced to zero, a company would lose its agility. What is more, different companies have different risk profiles. A start-up can afford to take more risks than a company that is already firmly established.
‘Organised cyber crime, which accounts for 80 per cent of online crime, is a real problem. Ransomware attacks alone have increased by 30 per cent in recent times.’
There is no single biggest risk. Organised cyber crime, which accounts for 80 per cent of online crime, is a real problem. Ransomware attacks alone have increased by 30 per cent in recent times. The targets are often international organisations, meaning that close cooperation with foreign law enforcement authorities is important.
Things are at different stages of development. Some bits of critical infrastructure are well protected, while for others there is still work to be done. We are currently in the process of establishing a mandatory reporting system for cyber incidents. This will allow us to assess which infrastructure is most at risk. Fundamentally, however, attackers would have to be extremely motivated indeed to mount an attack on critical infrastructure. There are much easier ways of making money.
Yes, there is such a thing as cyber insurance. I cannot judge how good the coverage is. This sort of insurance could well be an attractive option for some companies. It is important that the insurance company plays by the rules and doesn’t give in to ransom demands either, even if this might well be cheaper than assuming the costs of recovering the data.
The National Cyber Security Centre (NCSC) is the Confederation’s competence centre for cyber security and thus the first point of contact for businesses, public administrations, educational institutions and the general public for cyber issues. It is responsible for the coordinated implementation of the national strategy for the protection of Switzerland against cyber risks. The NCSC provides protection and incident management support for critical infrastructure. It maintains a pool of experts to support the federal offices in the development and implementation of cyber security standards. It also serves as a point of contact, receiving reports of cyber incidents from the public and the business community, analysing them and providing those submitting reports with an assessment of the incident and recommendations for further action.
It has pros and cons. When incidents occur, the coordination of the response between individual cantons can be somewhat sluggish. Each canton has its own strengths, however. Zurich and Vaud are strong in law enforcement, Ticino has a good track record in digital education, and the canton of Zug is committed to security testing for products, to name but a few. We are working to further improve the links between the cantons so as to make them more resilient to cyber attacks.
Working from home blurs the boundaries between private and working life, and this also has implications for cyber security. Home computers are often used for both personal and work-related purposes, which can lead to security gaps that criminals are able to exploit to attack the company. With this in mind, people should either have separate personal and work devices, or employers should set up secure access to the company’s IT infrastructure. It is also advisable to lock your computer when you are not at your desk. Children are curious and could end up disclosing valuable data purely by accident.
I am not a quantum computer specialist. But quantum computers can also be used for encryption, a process known as quantum cryptography. There is some exciting research in this field being conducted in Switzerland. It will be interesting to see whether we can use quantum computing to improve the world’s cyber security.
Florian Schütz is the Federal Cyber Security Delegate. He is the point of contact for politicians, the media and the general public on all matters relating to cyber security. He heads the National Cyber Security Centre (NCSC) and is responsible for the coordinated implementation of the national strategy for the protection of Switzerland against cyber risks (NCS). Schütz has an MA in Computer Science and a Master of Advanced Studies in Security Policy and Crisis Management from ETH Zurich.
Nina Arquint, Präsidentin des Ausschusses Rückversicherung im SVV, gibt uns einen Einblick in das qualitative Risikomanagement von Swiss Re.

Thomas Helbling, Direktor des SVV, zeigt sich im Interview enttäuscht über den Entscheid des Bundesrats, der das Konzept einer Pandemieversicherung nicht weiterverfolgen will.

Toprisiken sind Gefahren mit immensem Schadenpotenzial, die zuoberst auf der Risikoliste der Schweiz stehen.
