Categories: Politics

An internal audit report reveals holes in the DDPS’s cyber defenses: Reports of possible hacker attacks continue to circulate for weeks

class=”sc-cffd1e67-0 iQNQmc”>

1/5
The Swiss army is expanding its command network in 2019. There are vulnerabilities in the digital defense of the Ministry of Defense.
Lisa Aeschlimannnews reporter

Imagine this: a criminal hacker group is trying to gain access to federal systems. A Defense employee (VBS) clicks on the link of the suspicious email. But he only reports and records the whole thing weeks later in a kind of Excel file for his unit.

Reports of so-called information security incidents – such as security gaps, threats, breaches or even cyber attacks – remain with the DDPS for days or even weeks. And this despite the fact that, according to regulations, incidents must be reported “immediately” to the responsible authority. This is evident from a recently published report.

At the end of 2023, the DDPS internal audit department checked the state of cybersecurity in the department – ​​the report was not so good. According to the accountants, there is a lack of efficient communication between administrative units, the correct recording of incidents and their rapid forwarding.

Criticism of inefficient recording and forwarding of notifications

Last year, several cyber attacks highlighted the security risks for Switzerland. In May, the ransomware group Play attacked the IT company Xplain, which produces software for numerous authorities, such as the Federal Police Office (Fedpol) and migration agencies. Addresses of federal councilors and police officers or hooligan lists ended up on the darknet.

In November, criminals again attacked a federal and cantonal software provider called Concevis. As with Xplain, the federal government had not checked whether the company met IT security requirements.

The accountants write in the report that the number of cyber attacks has almost doubled in the past two years. The larger incidents – in which the DDPS or parts thereof were affected – showed that the incident management processes still need to be set up: “The audit showed that reports were sometimes communicated and recorded in the central register with a delay of several days or weeks. I’ve been.” However, in order to respond quickly, immediate recording is essential.

Advertisement
More about military cybersecurity
Strengthen defense capabilities
Amherd wants more money for the army
Xplain hack in the federal government
Military police data also ended up on the dark web
The Federal Council is against it
The Federal Public Prosecution Service is pushing for a new cyber authority
IT security neglected
Army surveillance cameras are poorly protected
Should Switzerland arm itself?
“We still have a lot of catching up to do in the field of cybersecurity”
Because of the switch to VBS?
The cyber specialists are fleeing from the federal government

They are also critical of the inefficient recording and forwarding of reports. Complete reporting requires ‘time-consuming manual work steps’. Data consolidation, coordination and reporting are mainly done manually. Translated, this means: The data is collected individually and entered manually instead of using software; the exchange takes place in person or via email. This is inefficient and error-prone. The employees are insufficiently trained.

“Data quality does not yet meet the requirements”

Security reports are also processed decentrally. Each administrative unit uses its own system for this. In their statements, federal offices complain about the lack of coordination and inadequate sharing. The auditors: “The current interim solutions have many limitations and the data quality does not yet meet the requirements.”

In a letter, Federal Councilor Viola Amherd (61) obliged the heads of the DDPS to take several measures recommended by the auditors: they must, among other things, improve the quality of reporting and data, increase employee awareness and training, and improve their skills increase “digital preparedness” and have it regularly checked by an independent body.

The DDPS writes that work is underway to implement the recommendations. Employees are already being trained. “This is now being strengthened, especially in the area of ​​information security.” Exchanges with federal agencies will also be intensified. However, a uniform, digital solution is still a long time coming: a new recording system will not be available until 2025.

Advertisement

Source:Blick

Share
Published by
Livingstone

Recent Posts

Terror suspect Chechen ‘hanged himself’ in Russian custody Egyptian President al-Sisi has been sworn in for a third term

On the same day of the terrorist attack on the Krokus City Hall in Moscow,…

1 year ago

Locals demand tourist tax for Tenerife: “Like a cancer consuming the island”

class="sc-cffd1e67-0 iQNQmc">1/4Residents of Tenerife have had enough of noisy and dirty tourists.It's too loud, the…

1 year ago

Agreement reached: this is how much Tuchel will receive for his departure from Bayern

class="sc-cffd1e67-0 iQNQmc">1/7Packing his things in Munich in the summer: Thomas Tuchel.After just over a year,…

1 year ago

Worst earthquake in 25 years in Taiwan +++ Number of deaths increased Is Russia running out of tanks? Now ‘Chinese coffins’ are used

At least seven people have been killed and 57 injured in severe earthquakes in the…

1 year ago

Now the moon should also have its own time (and its own clocks). These 11 photos and videos show just how intense the Taiwan earthquake was

The American space agency NASA would establish a uniform lunar time on behalf of the…

1 year ago

This is how the Swiss experienced the earthquake in Taiwan: “I saw a crack in the wall”

class="sc-cffd1e67-0 iQNQmc">1/8Bode Obwegeser was surprised by the earthquake while he was sleeping. “It was a…

1 year ago