Categories: Politics

Cybersecurity in Switzerland: “We are attacked every day, every hour, every minute”

class=”sc-cffd1e67-0 iQNQmc”>

1/5
Florian Schütz is director of the new Federal Office for Cybersecurity.
Rafael Rauch And Cecile Rey

Blick: Mr. Schütz, you are wearing a pin on the occasion of the 150th anniversary of the Basel Zolli on Veston. What animal do you think of when you think of cyber attacks?
Florian Schütz: Many hacker groups use animals as group symbols. For example, pro-Russian activists have used the bear as a symbol of Russia in their attacks. Eagles and hawks are also common. I think the elephant is a good metaphor. Cyber ​​defense is the elephant in the room: Everyone thinks cybersecurity is important, but concrete steps are still a long time coming.

The federal government entrusted the private company Xplain with secret documents, which were then stolen and leaked in a data theft. How dramatic is that?
The good news is that of the 121 classified objects, none fell under the highest level of secrecy. But the mere fact that confidential and internal documents have been leaked is worrying.

More about cyber attacks in Switzerland
Cyber ​​extortion
Switzerland says no to ransom payments
23 million to the city of Bern
How cyber attacks are plaguing communities
Harder practice required
The National Council wants to deport Russian spies more consistently
Gaps in the DDPS’s cyber defenses
Reports of hacker attacks continue to circulate for weeks

What are your biggest takeaways from the Xplain debacle?
The federal government must improve data management. We need a central overview of which supplier has which data. We have a very decentralized system, every office works differently. It took us a long time to analyze the data to find out who was actually affected by the data breach. For further information we must wait for the completion of the administrative investigation.

What do secret documents have to do with a private provider?
The federal government depends on outside IT vendors because if it wanted to develop every piece of software it uses itself, we would need a huge development department. It makes sense to purchase certain IT products. But this raises the question of what data the supplier actually needs. And how we ensure that the data is deleted later.

Whatever is published is publishedFlorian Schütz, director of the Federal Cybersecurity Office

The data breach also affects lists with the names of hooligans. Are they still floating around on the dark web?
I think so. You can’t delete virtually anything on the dark web. Servers of hacker groups are seized during international raids. But you still can’t assume that the data will no longer be on the dark web afterwards. Whatever is published is published.

What is a good password?
Nowadays, a password alone is no longer sufficient. We need two-factor authentication, for example password plus code via smartphone.

Advertisement

Still: what would be a good password?
I recommend memorizing a sentence and using the first letter of each word. You can replace an e with a 3 or an s with a dollar sign, i.e. “3$” instead of “es”. This makes the password harder to crack.

Are data thefts and server sabotage damaging Switzerland’s image?
No country is safe from cyber attacks. 95 percent of the incidents have a criminal nature. As a rich country, Switzerland is particularly vulnerable. The hackers know: she can pay.

Should Swiss companies pay – or accept leaks?
We strongly advise against accepting the demands of the blackmailers. Because each attack funds six to ten more attacks, making the problem worse. If no company paid more, we would have significantly fewer hacker attacks.

Have you reported an attack today?
Cyber ​​attacks happen every day, every hour, every minute. It’s 9:30 am. Today we have had 21 reports so far, for example in the area of ​​PayPal phishing. But also several emails with blackmail along the lines of: “We hacked your video camera and filmed you while you were watching porn.” In most cases this is fictional. Still, some feel caught and pay out of sheer panic. But not all cases reported to us were successful attacks.

Advertisement

Why are cyber attacks so difficult to control?
Many companies don’t do their homework. You know something needs to be done, but you don’t act consistently.

Why is that?
In management there are often more pressing problems. Cybersecurity is an invisible threat. It only becomes concrete when there is an acute problem. But economic interests also play a role. Cyber ​​security costs money.

Personal

Florian Schütz (42) has been director of the new Federal Office for Cybersecurity since this year. He studied computer science at the ETH in Zurich and worked for Siemens and Ruag, among others. From 2016 to 2019, he led the risk and safety department of fashion retailer Zalando in Germany.

Florian Schütz (42) has been director of the new Federal Office for Cybersecurity since this year. He studied computer science at the ETH in Zurich and worked for Siemens and Ruag, among others. From 2016 to 2019, he led the risk and safety department of fashion retailer Zalando in Germany.

The Swiss army discusses the risks of the new Microsoft Office because Word, Excel and Co. will be cloud-based in the future.
Outsourcing data to a provider that makes correspondingly high security investments makes perfect sense from a technical perspective. However, organizational security aspects must also be taken into account. This means that data from providers in the US can end up on an American server. US courts could force these companies to hand over the data.

Russia intercepted an explosive conversation between high-ranking representatives of the German Bundeswehr who consulted each other via Webex. Are programs like Webex or WhatsApp a no-go for you?
At the federal level we have clear guidelines: we use Threema as a messenger. We have special systems for secret exchanges.

Advertisement

You used to work for Zalando. What distinguishes the Bund from a fashion mail order company?
Zalando has other priorities. Delivery times are very important when trading online. We have done everything we can to ensure that delivery times cannot be affected by hacker attacks.

Source:Blick

Share
Published by
Livingstone

Recent Posts

Terror suspect Chechen ‘hanged himself’ in Russian custody Egyptian President al-Sisi has been sworn in for a third term

On the same day of the terrorist attack on the Krokus City Hall in Moscow,…

1 year ago

Locals demand tourist tax for Tenerife: “Like a cancer consuming the island”

class="sc-cffd1e67-0 iQNQmc">1/4Residents of Tenerife have had enough of noisy and dirty tourists.It's too loud, the…

1 year ago

Agreement reached: this is how much Tuchel will receive for his departure from Bayern

class="sc-cffd1e67-0 iQNQmc">1/7Packing his things in Munich in the summer: Thomas Tuchel.After just over a year,…

1 year ago

Worst earthquake in 25 years in Taiwan +++ Number of deaths increased Is Russia running out of tanks? Now ‘Chinese coffins’ are used

At least seven people have been killed and 57 injured in severe earthquakes in the…

1 year ago

Now the moon should also have its own time (and its own clocks). These 11 photos and videos show just how intense the Taiwan earthquake was

The American space agency NASA would establish a uniform lunar time on behalf of the…

1 year ago

This is how the Swiss experienced the earthquake in Taiwan: “I saw a crack in the wall”

class="sc-cffd1e67-0 iQNQmc">1/8Bode Obwegeser was surprised by the earthquake while he was sleeping. “It was a…

1 year ago