{"id":23518,"date":"2024-07-05T13:44:19","date_gmt":"2024-07-05T12:44:19","guid":{"rendered":"https:\/\/www.riskinsight-wavestone.com\/?p=23518"},"modified":"2024-07-05T13:44:21","modified_gmt":"2024-07-05T12:44:21","slug":"switzerland-strengthens-cyber-regulations-essential-sectors-targeted","status":"publish","type":"post","link":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/","title":{"rendered":"Switzerland Strengthens Cyber Regulations: Essential Sectors Targeted"},"content":{"rendered":"\n<p><span class=\"TextRun SCXW220345832 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW220345832 BCX0\">Historically, Switzerland has distinguished itself from its neighbors<strong> by <\/strong><\/span><\/span><strong><span class=\"TextRun SCXW220345832 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW220345832 BCX0\">adopting a less stringent approach to information system security regulations<\/span><\/span><\/strong><span class=\"TextRun SCXW220345832 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW220345832 BCX0\"><strong>.<\/strong> Preference <\/span><span class=\"NormalTextRun SCXW220345832 BCX0\">has been <\/span><span class=\"NormalTextRun SCXW220345832 BCX0\">given to <\/span><\/span><span class=\"TextRun SCXW220345832 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW220345832 BCX0\">subsidiarity<\/span><\/span><span class=\"TextRun SCXW220345832 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW220345832 BCX0\">, a legal principle whereby<strong> the <\/strong><\/span><\/span><strong><span class=\"TextRun SCXW220345832 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW220345832 BCX0\">Confederation does not legislate in areas where the Cantons can<\/span><\/span><\/strong><span class=\"TextRun SCXW220345832 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW220345832 BCX0\"><strong>.<\/strong> Apart from two federal laws (<\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW220345832 BCX0\">nLPD<\/span><span class=\"NormalTextRun SCXW220345832 BCX0\">, LSI) and several sectoral regulations (<\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW220345832 BCX0\">CySec<\/span><span class=\"NormalTextRun SCXW220345832 BCX0\"> Rail Directive, <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW220345832 BCX0\">Finma<\/span><span class=\"NormalTextRun SCXW220345832 BCX0\"> regulations, Directive for the security of smart metering systems data, etc.), this approach has allowed Cantons to <\/span><span class=\"NormalTextRun SCXW220345832 BCX0\">maintain<\/span><span class=\"NormalTextRun SCXW220345832 BCX0\"> autonomy in managing cyber issues. However, <\/span><\/span><strong><span class=\"TextRun SCXW220345832 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW220345832 BCX0\">the growing need for cybersecurity is leading to an increase in cyber regulations and their binding nature.<\/span><\/span><span class=\"EOP SCXW220345832 BCX0\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/strong><\/p>\n<h1><b><span data-contrast=\"auto\">Cybersecurity Regulations in Switzerland<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/h1>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-23528 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174249.png\" alt=\"\" width=\"773\" height=\"243\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174249.png 773w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174249-437x137.png 437w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174249-71x22.png 71w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174249-768x241.png 768w\" sizes=\"auto, (max-width: 773px) 100vw, 773px\" \/><\/p>\n<p>Two new binding national texts came into effect on <strong>July 1st, 2024<\/strong>, to establish a <strong>minimum cybersecurity threshold<\/strong> for the <strong>electricity supply and railway transport sectors<\/strong>. This article will focus particularly on the revision of the <strong>Electricity Supply Ordinance<\/strong> (OApEl).<\/p>\n<h1><b><span data-contrast=\"auto\">Global Trend towards Cybersecurity Standardization<\/span><\/b><\/h1>\n<p>The cybersecurity landscape is <strong>shaped by various national and international frameworks<\/strong> and <strong>legislations:<\/strong><\/p>\n<ul>\n<li>The <strong>NIST Cybersecurity Framework<\/strong> (CSF) of 2017 in the United States has become a standard for federal agencies to manage and reduce cybersecurity risks, following a presidential executive order indirectly mandating its use.<\/li>\n<li>In Europe, the 2016 <strong>Network and Information Systems (NIS) Directives<\/strong>, complemented by NIS 2 in 2023, aim to enhance the resilience of essential service operators (OSE) and strengthen the security of network and information systems.<\/li>\n<li>In France, the 2018 <strong>Military Programming Law<\/strong> (LPM) for the years 2019-2025 imposes obligations on operators of vital importance (OIV) to secure critical infrastructures against cyber threats.<\/li>\n<\/ul>\n<p>These initiatives <strong>demonstrate a concerted global effort to bolster cybersecurity<\/strong> in response to <strong>increasingly sophisticated threats<\/strong>.<\/p>\n<h1><b><span data-contrast=\"auto\">Changes for the Swiss Electricity Sector<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/h1>\n<p><span data-contrast=\"auto\">In this context, <\/span><b><span data-contrast=\"auto\">Switzerland\u2019s minimal National ICT standard is now mandatory for the electricity supply sector.<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-23526 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174358.png\" alt=\"\" width=\"736\" height=\"194\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174358.png 736w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174358-437x115.png 437w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174358-71x19.png 71w\" sizes=\"auto, (max-width: 736px) 100vw, 736px\" \/><\/p>\n<ul>\n<li>The <strong>National ICT Standard <\/strong>in Switzerland, implemented by the Federal Office for National Economic Supply (OFAE), aims to <strong>protect infrastructures against cyber risks<\/strong>. It covers identification, protection, detection, response, and recovery, drawing inspiration from NIST standards to assess cybersecurity maturity and provide guidance. Unlike the European NIS directives and the French LPM, this standard is not inherently binding.<\/li>\n<li>The <strong>Swiss Electricity Supply Ordinance<\/strong> (OApEl) specifies the Electricity Supply Act (LApEl) and regulates the electricity market to ensure supply security, with a cybersecurity component in its article 8b on data protection. Unlike the ICT standard, it is binding. <strong>Its new version, which makes the Minimum ICT Standard mandatory for electricity sector players, took effect on July 1, 2024.<\/strong><\/li>\n<\/ul>\n<h1><b><span data-contrast=\"auto\">Mandatory Compliance for Swiss Electricity Actors<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/h1>\n<p><b><span data-contrast=\"auto\">Actors that must comply with the National ICT Standard<\/span><\/b><span data-contrast=\"auto\"> under OApEl within 24 months of its effective date :\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-23524 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174534.png\" alt=\"\" width=\"651\" height=\"521\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174534.png 651w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174534-239x191.png 239w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174534-49x39.png 49w\" sizes=\"auto, (max-width: 651px) 100vw, 651px\" \/><\/p>\n<p>The revised OApEl&#8217;s minimum requirements are binding upon their enactment, with no transitional period. <strong>The Federal Electricity Commission<\/strong> (<strong>ElCom) is now responsible for defining and monitoring compliance<\/strong>. The concerned entities must self-assess over two years and demonstrate compliance to the ElCom. If measures are not promptly implemented, the ElCom engages with companies. In justified cases, an extension may be exceptionally granted.<\/p>\n<h2><b><span data-contrast=\"auto\">Surveillance Role of the ElCom<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/h2>\n<p>Under Article 22, paragraph 1 of the LApEl, <strong>the ElCom monitors compliance with OApEl provisions and related ordinances<\/strong>. Thus, <strong>the ElCom now has a specific mission in the cybersecurity framework for Swiss electricity actors:<\/strong><\/p>\n<ul>\n<li><strong>Monitoring:<\/strong> The ElCom monitors compliance with cyber protection measures using the NIST cybersecurity framework and minimum legislative requirements.<\/li>\n<li><strong>Investigation:<\/strong> In its monitoring process, The ElCom uses self-assessment surveys to document companies&#8217; cybersecurity practices.<\/li>\n<li><strong>Awareness Interviews:<\/strong> The ElCom conducts awareness interviews with companies deemed crucial for network security and stability.<\/li>\n<li><strong>Audits:<\/strong> The ElCom can conduct targeted audits in response to anomalies identified during surveys or interviews or based on external indications.<\/li>\n<\/ul>\n<p style=\"text-align: center;\"><em><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-23522 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174624.png\" alt=\"\" width=\"887\" height=\"290\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174624.png 887w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174624-437x143.png 437w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174624-71x23.png 71w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174624-768x251.png 768w\" sizes=\"auto, (max-width: 887px) 100vw, 887px\" \/>\u00a0<\/em><em>Legal Compliance Timeline\u00a0<\/em><\/p>\n<h2><b><span data-contrast=\"auto\">Expected Maturity Levels<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/h2>\n<p>The revised OApEl defines <strong>three protection levels (A, B, C)<\/strong> to ensure cybersecurity measures are proportional to the potential impact on the Swiss ecosystem. Each level has <strong>specific measures and sets expectations for NIST maturity scores (\/4).<\/strong><\/p>\n<p><strong>Membership to each level is proportionate to the volume of electricity produced and\/or distributed by network managers and their providers<\/strong>, as well as by producers (excluding nuclear), storage operators, and their providers:<\/p>\n<ul>\n<li><strong>Level A:<\/strong> More than 450 GWh\/year (operators) or more than 800 MW (producers)<\/li>\n<li><strong>Level B:<\/strong> Between 450 and 112 GWh\/year (operators) or between 800 and 100 MW (producers)<\/li>\n<li><strong>Level C:<\/strong> Less than 112 GWh\/year (operators) or less than 100 MW (producers)<\/li>\n<\/ul>\n<p><strong>Each level has expected maturity scores for NIST control points.<\/strong> For example, for NIST ID-AM 2 (Develop a process for inventorying and continuously maintaining a comprehensive list of your ICT equipment), a NIST maturity level of 4\/4 is expected for level A, 3\/4 for level B, and 2\/4 for level C.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-23520 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174722.png\" alt=\"\" width=\"366\" height=\"579\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174722.png 366w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174722-121x191.png 121w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/Capture-decran-2024-07-04-174722-25x39.png 25w\" sizes=\"auto, (max-width: 366px) 100vw, 366px\" \/><\/p>\n<h2><b><span data-contrast=\"auto\">Analysis<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/h2>\n<p>A detailed analysis of OApEl expectations reveals five particularly critical areas, and four others that may appear surprisingly low given the sector and associated risks.<\/p>\n<p><strong>Major compliance points (highest expected scores)<\/strong><\/p>\n<ul>\n<li>Governance<\/li>\n<li>Access Management<\/li>\n<li>Awareness and Training<\/li>\n<li>Protection and Security Solutions<\/li>\n<li>Risk Analysis<\/li>\n<\/ul>\n<p><strong>Minor Compliance Points (Lowest Expected Scores)<\/strong><\/p>\n<ul>\n<li>Communication during and after an incident<\/li>\n<li>Detection and Investigation<\/li>\n<li>Mitigation and Isolation<\/li>\n<li>Business Environment<\/li>\n<\/ul>\n<p><strong>It is recommended for affected organizations not to neglect preparation for incident communication, response, and isolation capabilities.<\/strong> These elements are crucial for the sector&#8217;s criticality to the Swiss economy and the need for operational cooperation for effective crisis management.<\/p>\n<h1><strong>Conclusion<\/strong><\/h1>\n<p>With the revision of OApEl, Switzerland&#8217;s legal framework gains a new binding sectoral text that will push market actors in the electricity sector to meet expected maturity levels as set by this new regulation.<\/p>\n<p>In perspective with the CySec Rail directive and Finma circulars, Swiss cybersecurity is becoming standardized at the national level, although the texts remain disparate. Indeed, OApEl mainly relies on NIST via the Minimum ICT Standard, while the CySec Rail Directive (for railways) combines elements from ISO 2700X and NIST, and Finma circulars (for the financial sector) formalize sector-specific requirements.<\/p>\n<p>Consequently, it is not unimaginable that other sectors will be impacted soon.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Historically, Switzerland has distinguished itself from its neighbors by adopting a less stringent approach to information system security regulations. Preference has been given to subsidiarity, a legal principle whereby the Confederation does not legislate in areas where the Cantons can&#8230;.<\/p>\n","protected":false},"author":1429,"featured_media":23515,"comment_status":"open","ping_status":"closed","sticky":true,"template":"page-templates\/tmpl-one.php","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3977,3274],"tags":[],"coauthors":[4022,4475],"class_list":["post-23518","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-focus","category-manufacturing-industry-4-0-en"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Switzerland Strengthens Cyber Regulations: Essential Sectors Targeted - RiskInsight<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Switzerland Strengthens Cyber Regulations: Essential Sectors Targeted - RiskInsight\" \/>\n<meta property=\"og:description\" content=\"Historically, Switzerland has distinguished itself from its neighbors by adopting a less stringent approach to information system security regulations. Preference has been given to subsidiarity, a legal principle whereby the Confederation does not legislate in areas where the Cantons can....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/\" \/>\n<meta property=\"og:site_name\" content=\"RiskInsight\" \/>\n<meta property=\"article:published_time\" content=\"2024-07-05T12:44:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-07-05T12:44:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/mountains-5958421_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jordan Bertin, R\u00e9mi Pactat\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jordan Bertin, R\u00e9mi Pactat\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/\"},\"author\":{\"name\":\"Jordan Bertin\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/2b26827cb043e683d2375cd3fff863cd\"},\"headline\":\"Switzerland Strengthens Cyber Regulations: Essential Sectors Targeted\",\"datePublished\":\"2024-07-05T12:44:19+00:00\",\"dateModified\":\"2024-07-05T12:44:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/\"},\"wordCount\":969,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/mountains-5958421_1280.jpg\",\"articleSection\":[\"Focus\",\"Manufacturing &amp; Industry 4.0\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/\",\"name\":\"Switzerland Strengthens Cyber Regulations: Essential Sectors Targeted - RiskInsight\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/mountains-5958421_1280.jpg\",\"datePublished\":\"2024-07-05T12:44:19+00:00\",\"dateModified\":\"2024-07-05T12:44:21+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#primaryimage\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/mountains-5958421_1280.jpg\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/mountains-5958421_1280.jpg\",\"width\":1280,\"height\":853},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Switzerland Strengthens Cyber Regulations: Essential Sectors Targeted\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"name\":\"RiskInsight\",\"description\":\"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants\",\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\",\"name\":\"Wavestone\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"width\":50,\"height\":50,\"caption\":\"Wavestone\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/2b26827cb043e683d2375cd3fff863cd\",\"name\":\"Jordan Bertin\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/author\/j0rd4n-b3rt1n\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Switzerland Strengthens Cyber Regulations: Essential Sectors Targeted - RiskInsight","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/","og_locale":"en_US","og_type":"article","og_title":"Switzerland Strengthens Cyber Regulations: Essential Sectors Targeted - RiskInsight","og_description":"Historically, Switzerland has distinguished itself from its neighbors by adopting a less stringent approach to information system security regulations. Preference has been given to subsidiarity, a legal principle whereby the Confederation does not legislate in areas where the Cantons can....","og_url":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/","og_site_name":"RiskInsight","article_published_time":"2024-07-05T12:44:19+00:00","article_modified_time":"2024-07-05T12:44:21+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/mountains-5958421_1280.jpg","type":"image\/jpeg"}],"author":"Jordan Bertin, R\u00e9mi Pactat","twitter_misc":{"Written by":"Jordan Bertin, R\u00e9mi Pactat","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#article","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/"},"author":{"name":"Jordan Bertin","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/2b26827cb043e683d2375cd3fff863cd"},"headline":"Switzerland Strengthens Cyber Regulations: Essential Sectors Targeted","datePublished":"2024-07-05T12:44:19+00:00","dateModified":"2024-07-05T12:44:21+00:00","mainEntityOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/"},"wordCount":969,"commentCount":0,"publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/mountains-5958421_1280.jpg","articleSection":["Focus","Manufacturing &amp; Industry 4.0"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/","url":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/","name":"Switzerland Strengthens Cyber Regulations: Essential Sectors Targeted - RiskInsight","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#primaryimage"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/mountains-5958421_1280.jpg","datePublished":"2024-07-05T12:44:19+00:00","dateModified":"2024-07-05T12:44:21+00:00","breadcrumb":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#primaryimage","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/mountains-5958421_1280.jpg","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2024\/07\/mountains-5958421_1280.jpg","width":1280,"height":853},{"@type":"BreadcrumbList","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2024\/07\/switzerland-strengthens-cyber-regulations-essential-sectors-targeted\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.riskinsight-wavestone.com\/en\/"},{"@type":"ListItem","position":2,"name":"Switzerland Strengthens Cyber Regulations: Essential Sectors Targeted"}]},{"@type":"WebSite","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","name":"RiskInsight","description":"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants","publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization","name":"Wavestone","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","width":50,"height":50,"caption":"Wavestone"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/2b26827cb043e683d2375cd3fff863cd","name":"Jordan Bertin","url":"https:\/\/www.riskinsight-wavestone.com\/en\/author\/j0rd4n-b3rt1n\/"}]}},"_links":{"self":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/23518","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/users\/1429"}],"replies":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/comments?post=23518"}],"version-history":[{"count":2,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/23518\/revisions"}],"predecessor-version":[{"id":23537,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/23518\/revisions\/23537"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media\/23515"}],"wp:attachment":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media?parent=23518"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/categories?post=23518"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/tags?post=23518"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/coauthors?post=23518"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}