{"id":132894,"date":"2022-05-26T09:53:10","date_gmt":"2022-05-26T09:53:10","guid":{"rendered":"https:\/\/swissfederalism.ch\/centro-nazionale-cibersicurezza-ncsc-ufficio-federale\/"},"modified":"2022-05-26T13:37:57","modified_gmt":"2022-05-26T13:37:57","slug":"national-cyber-security-centre-become-a-federal-office","status":"publish","type":"post","link":"https:\/\/swissfederalism.ch\/en\/national-cyber-security-centre-become-a-federal-office\/","title":{"rendered":"The National Cyber Security Centre (NCSC) will become a federal office"},"content":{"rendered":"<h1><span class=\"font-377884\">The National Cyber Security Centre (NCSC) will become a federal office<\/span><\/h1>\n<h3><span class=\"font-377884\"><em>The Federal Department of Finance (FDF) has the task of drawing up proposals by the end of 2022 concerning the structure of the new office and the department to which it will be attached.<\/em><\/span><\/h3>\n<figure id=\"attachment_131494\" aria-describedby=\"caption-attachment-131494\" style=\"width: 840px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/swissfederalism.ch\/costituzione-di-unassociazione-per-aumentare-la-ciber-resilienza-nel-mercato-finanziario-svizzero\/cyber-security\/\" rel=\"attachment wp-att-131494\"><img decoding=\"async\" class=\"size-large wp-image-131495\" src=\"https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-security-1024x683.jpg\" alt=\"cyber security\" width=\"840\" height=\"560\" srcset=\"https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-security-1024x683.jpg 1024w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-security-300x200.jpg 300w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-security-768x512.jpg 768w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-security-1536x1024.jpg 1536w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-security.jpg 1920w\" sizes=\"(max-width: 840px) 100vw, 840px\" \/><\/a><figcaption id=\"caption-attachment-131494\" class=\"wp-caption-text\"><span class=\"font-377884\">cyber security<\/span><\/figcaption><\/figure>\n<p><span class=\"font-377884\">In recent years, cyber security has become increasingly important at all levels. Already in 2019, the Federal Council laid a fundamental foundation for this by creating the NCSC, which is attached to the FDF General Secretariat. In addition to the expansion of the technical service GovCERT, a vulnerability management and a contact service that collects reports on cyber incidents from the population, authorities and companies were developed. With about 40 employees, the NCSC fulfils the central tasks in the area of protecting Switzerland against cyber threats and supports the operators of critical infrastructures in the prevention and resolution of incidents, manages the contact service for the private sector and the population in all questions concerning cyber security, and again, in view of the introduction of the obligation to report cyber attacks, the Federal Council will designate it as the central reporting service.<\/span><\/p>\n<p><span class=\"font-377884\"><strong><a href=\"https:\/\/swissfederalism.ch\/en\/gianluca-tirozzi-this-is-how-bitcorp-will-conquer-metaspace\/\">Gianluca Tirozzi: &#8220;This is how bitCorp will conquer metaspace!&#8221;<\/a><\/strong><\/span><\/p>\n<p><span class=\"font-377884\"><strong><a href=\"https:\/\/swissfederalism.ch\/en\/association-founded-to-increase-the-cyber-resilience-of-the-swiss-financial-centre\/\">Association founded to increase the cyber-resilience of the Swiss financial centre<\/a><\/strong><\/span><\/p>\n<h2><span class=\"font-377884\">Growing importance of cyber security<\/span><\/h2>\n<p><span class=\"font-377884\">Cyber security is becoming increasingly important, which means that the tasks of the NCSC are also becoming more extensive and important. The Federal Council considered various options such as separation from the central federal administration, joint management with the cantons or transformation into a public-private partnership. It came to the conclusion that, as an important task in state policy, cyber security should continue to be managed directly by a federal councillor by strengthening the NCSC and transforming it into a federal office.<\/span><\/p>\n<p><span class=\"font-377884\">The Federal Council has instructed the FDF to draw up proposals for the structure of the new office and the department to which it will be attached by the end of 2022.<\/span><\/p>\n<div class=\"contentHead\">\n<figure id=\"attachment_131498\" aria-describedby=\"caption-attachment-131498\" style=\"width: 840px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/swissfederalism.ch\/costituzione-di-unassociazione-per-aumentare-la-ciber-resilienza-nel-mercato-finanziario-svizzero\/cyber-security-2\/\" rel=\"attachment wp-att-131498\"><img decoding=\"async\" class=\"size-large wp-image-131499\" src=\"https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-security-1024x744.png\" alt=\"cyber security\" width=\"840\" height=\"610\" srcset=\"https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-security-1024x744.png 1024w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-security-300x218.png 300w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-security-768x558.png 768w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-security.png 1280w\" sizes=\"(max-width: 840px) 100vw, 840px\" \/><\/a><figcaption id=\"caption-attachment-131498\" class=\"wp-caption-text\"><span class=\"font-377884\">cyber security<\/span><\/figcaption><\/figure>\n<h2><span class=\"font-377884\">National Strategy against Cyber Risks<\/span><\/h2>\n<p><span class=\"font-377884\">The Federal Council took cognizance of the report on the effectiveness review of the National Strategy for Protecting Switzerland against Cyber Risks (NSCP) 2018-2022 and decided to increase resources by creating an additional 25 posts in this area.<\/span><\/p>\n<p><span class=\"font-377884\">The implementation of the current SNPC will end at the end of 2022. In the meantime, the Strategy will be updated and adjusted according to the threat situation. The basis for this work is the effectiveness review of the SNPC in the second half of 2021.<\/span><\/p>\n<p><span class=\"font-377884\">The implementation is proceeding according to plan and has so far yielded very good results: in cooperation with the universities, for instance, standards and quality seals have been developed, which allow organisations to systematically check and improve their cyber security. Thanks to the establishment of the National Cyber Security Testing Institute in Zug, nationwide expertise is now being developed for the in-depth analysis of IT products. In addition, as part of the project to introduce mandatory reporting of cyber attacks, the federal government has also drawn up a proposal to improve cyber security through regulatory measures. The involvement of numerous representatives of cantons, business circles and universities is crucial for the success of the SNPC, both in the drafting phase and in its implementation.<\/span><\/p>\n<h3><span class=\"font-377884\">Recommendations for further development<\/span><\/h3>\n<p><span class=\"font-377884\">In order for the future Strategy to have an even better effect, the results of the report on the effectiveness review of the SNPC 2018-2022 will be taken into account in its work. The latter shows, for example, that the Strategy focuses too much on critical infrastructure, large companies as well as national and cantonal authorities, while for SMEs, municipalities and the population the direct effects are still too limited. The experts also identified potential for optimisation in the management of implementation. Governance must be adapted so that priorities and new measures can be decided quickly and flexibly in the future.<\/span><\/p>\n<\/div>\n<div class=\"mod mod-nsbnewsdetails\">\n<p><span class=\"font-377884\"><strong><a href=\"https:\/\/www.newsd.admin.ch\/newsd\/message\/attachments\/71550.pdf\">Verifica dell\u2019efficacia della Strategia nazionale per la protezione della Svizzera contro i cyber-rischi 2018\u20132022<\/a><\/strong><\/span><\/p>\n<p><span class=\"font-377884\"><a href=\"https:\/\/www.newsd.admin.ch\/newsd\/message\/attachments\/71549.pdf\"><strong>\u00c9valuation de l\u2019efficacit\u00e9 de la strat\u00e9gie nationale de protection de la Suisse contre les cyberrisques pour les ann\u00e9es 2018 \u00e0 2022<\/strong><\/a><\/span><\/p>\n<p><span class=\"font-377884\"><a href=\"https:\/\/www.newsd.admin.ch\/newsd\/message\/attachments\/71548.pdf\"><strong>Wirksamkeits\u00fcberpr\u00fcfung \u00abNationale Strategie zum Schutz der Schweiz vor CyberRisiken 2018 bis 2022\u00bb<\/strong><\/a><\/span><\/p>\n<p><span class=\"font-377884\">Based on the results of the effectiveness review, the Federal Council decided to further increase resources for the protection against cyber risks. To this end, it authorised the creation of 25 posts, ten at the National Cyber Security Centre, six at the Federal Intelligence Service, two at the Federal Office of Information Technology and Telecommunication, two at the Federal Department of Foreign Affairs, and five at specialised offices in various critical areas (energy, transport, civil aviation, telecommunication and health). The prerequisites for the new SNPC are therefore in place. The new strategy will also be elaborated in close cooperation with various experts and will form the basis for a joint, effective and coordinated protection of Switzerland against cyber threats.<\/span><\/p>\n<figure id=\"attachment_132885\" aria-describedby=\"caption-attachment-132885\" style=\"width: 840px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/swissfederalism.ch\/centro-nazionale-cibersicurezza-ncsc-ufficio-federale\/hacker-cybersecurity\/\" rel=\"attachment wp-att-132885\"><img decoding=\"async\" class=\"size-large wp-image-132886\" src=\"https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/05\/hacker-cybersecurity-1024x640.jpg\" alt=\"Hacker\" width=\"840\" height=\"525\" srcset=\"https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/05\/hacker-cybersecurity-1024x640.jpg 1024w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/05\/hacker-cybersecurity-300x188.jpg 300w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/05\/hacker-cybersecurity-768x480.jpg 768w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/05\/hacker-cybersecurity-1536x960.jpg 1536w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/05\/hacker-cybersecurity.jpg 1920w\" sizes=\"(max-width: 840px) 100vw, 840px\" \/><\/a><figcaption id=\"caption-attachment-132885\" class=\"wp-caption-text\"><span class=\"font-377884\">Hacker<\/span><\/figcaption><\/figure>\n<h2><span class=\"font-377884\">NCSC semi-annual report on the most important cyber incidents in Switzerland and abroad in the second half of 2021<\/span><\/h2>\n<p><span class=\"font-377884\">Various third-party suppliers and providers are involved in the production of goods and services today. Attacks on individual suppliers or bidders can have serious repercussions on the entire supply chain (e.g. blocking of production), such as the well-known case of the software company Kaseya in the middle of 2021. Also in Switzerland, a DDoS attack against a hosting provider caused temporary disruptions on various websites in the city and canton of St. Gallen.<\/span><\/p>\n<h3><span class=\"font-377884\">Increasingly frequent fraud cases<\/span><\/h3>\n<p><span class=\"font-377884\">In the six months under review, the NCSC received a total of 11,480 reports of cyber incidents, many of them involving different types of fraud. In most cases, these were e-mails sent in the name of prosecuting authorities. Advance payment scams, investment scams, CEO scams, and ad-related scams were also reported. Hackers are acting in an increasingly targeted and complex manner. Before taking action, they spend time with the victim in order to gain his trust.<\/span><\/p>\n<h3><span class=\"font-377884\">Ransomware and data leakage<\/span><\/h3>\n<p><span class=\"font-377884\">Also in the second half of 2021, there were numerous ransomware attacks, with which attackers encrypt data and then demand a ransom. Increasingly, hackers resort to double extortion and copy data before encrypting it, in order to have more leeway and exert more pressure. If the victim is unwilling to pay the ransom, they threaten to publicly disseminate the data.<\/span><\/p>\n<h3><span class=\"font-377884\">Vulnerabilities in software components<\/span><\/h3>\n<p><span class=\"font-377884\">Software is often developed using existing components such as libraries or open source code. However, there may be vulnerabilities in these components, which, when found, must be fixed in all products containing the component in question. This problem emerged in December 2021 with the critical vulnerability in the popular Java library Log4j.<\/span><\/p>\n<h3><span class=\"font-377884\">Phishing remains trendy<\/span><\/h3>\n<p><span class=\"font-377884\">Since the start of the pandemic, the NCSC has received numerous reports of phishing attacks launched via messages (e-mails or text messages) announcing the imminent arrival of a package or delivery problems. Phishing attempts against webmail and Microsoft 365 (formerly Office 365) were also reported. Access data obtained in this way are often used to forge invoices. Among the most widespread ploys are also e-mails in which self-styled Internet service providers attempt to trick the victim into believing that an invoice has been paid twice.<\/span><\/p>\n<\/div>\n<figure id=\"attachment_131502\" aria-describedby=\"caption-attachment-131502\" style=\"width: 840px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/swissfederalism.ch\/costituzione-di-unassociazione-per-aumentare-la-ciber-resilienza-nel-mercato-finanziario-svizzero\/cyber-attack\/\" rel=\"attachment wp-att-131502\"><img decoding=\"async\" class=\"size-large wp-image-131503\" src=\"https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-attack-1024x683.jpg\" alt=\"cyber attack warning\" width=\"840\" height=\"560\" srcset=\"https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-attack-1024x683.jpg 1024w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-attack-300x200.jpg 300w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-attack-768x512.jpg 768w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-attack-1536x1024.jpg 1536w, https:\/\/swissfederalism.ch\/wp-content\/uploads\/2022\/04\/cyber-attack.jpg 1920w\" sizes=\"(max-width: 840px) 100vw, 840px\" \/><\/a><figcaption id=\"caption-attachment-131502\" class=\"wp-caption-text\"><span class=\"font-377884\">cyber attack warning<\/span><\/figcaption><\/figure>\n<p><span class=\"font-377884\">Source: FDF General Secretariat <a class=\"icon icon--after icon--external\" title=\"\" href=\"http:\/\/www.efd.admin.ch\/\" target=\"_blank\" rel=\"noopener\">efd.admin.ch\u00a0<\/a><\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cyber security is becoming increasingly important, which means that the tasks of the NCSC are also becoming more extensive and important. In this regard, the Executive came to the conclusion that cyber security should continue to be managed directly by a federal councillor by strengthening the NCSC and transforming it into a federal office.<\/p>\n","protected":false},"author":9,"featured_media":131495,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[185,1,133,137,1998],"tags":[727,1744,1222,616,752,685,1997],"class_list":["post-132894","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-in-evidenza","category-magazine","category-politica","category-svizzera","category-tecnologia","tag-crimine","tag-cyber-security","tag-digitalizzazione","tag-sicurezza","tag-svizzera","tag-switzerland","tag-ufficio"],"_links":{"self":[{"href":"https:\/\/swissfederalism.ch\/en\/wp-json\/wp\/v2\/posts\/132894","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/swissfederalism.ch\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/swissfederalism.ch\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/swissfederalism.ch\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/swissfederalism.ch\/en\/wp-json\/wp\/v2\/comments?post=132894"}],"version-history":[{"count":2,"href":"https:\/\/swissfederalism.ch\/en\/wp-json\/wp\/v2\/posts\/132894\/revisions"}],"predecessor-version":[{"id":132898,"href":"https:\/\/swissfederalism.ch\/en\/wp-json\/wp\/v2\/posts\/132894\/revisions\/132898"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/swissfederalism.ch\/en\/wp-json\/wp\/v2\/media\/131495"}],"wp:attachment":[{"href":"https:\/\/swissfederalism.ch\/en\/wp-json\/wp\/v2\/media?parent=132894"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/swissfederalism.ch\/en\/wp-json\/wp\/v2\/categories?post=132894"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/swissfederalism.ch\/en\/wp-json\/wp\/v2\/tags?post=132894"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}