SWITZERLAND Trends and Developments Contributed by: David Vasella, Jürg Schneider, Hugh Reeves and Yannick Caballero Cuevas, Walder Wyss Ltd
Walder Wyss Ltd Seefeldstrasse 123
8008 Zurich Switzerland
Tel: +41 586 585 858 Fax: +41 586 585 959 Email: reception@walderwyss.com Web: www.walderwyss.com
Regulation in the Face of Risk: Switzerland’s Approach to Cybersecurity and AI Governance Cyber threats are rapidly evolving, becoming ever more sophisticated and harder to detect. One ongo - ing but no less concerning trend is the increase of ransomware attacks, which have affected numerous companies and other organisations in Switzerland. Moreover, the National Cyber Security Centre (NCSC), the English designation for the Bundesamt für Cyber- sicherheit integrated within the Federal Department of Defence, Civil Protection and Sport (DDPS), reported a significant increase in phishing cases (eg, phishing attempts impersonating the Federal Tax Administra - tion or Switzerland’s popular payment app TWINT). This highlights the ongoing threat of phishing attacks, which often target individuals to gain access to sensi - tive information or systems. Recent attacks include an attempt to infiltrate the IT systems of SBB, Switzerland’s national railway, via email malware. This attack was partially successful, but no customer data was stolen. Another notable incident was a ransom attack on media companies, when a ransomware group breached the IT infra - structure of Neue Zürcher Zeitung and CH Media, two leading media outlets, stealing confidential data and encrypted files and extorting the companies. No ransom was paid, apparently, but sensitive employee and customer data later surfaced on the dark web. A hacker attack on a guardianship authority in the town of Saxon was successful, with sensitive client infor - mation stolen and published, affecting some 6,000 residents. Other notable incidents include an attack on the sewing machine manufacturer Bernina, which, according to media reports, paid a ransom; an attack on an education network used by the city of Basel-
Stadt, leading to the theft of personal data of more than 750 persons; and a distributed denial-of-service (DDoS) attack during Ukrainian President Zelenskyy’s video address to the Swiss Parliament. Other attacks targeted the city of Baden and the Canton of Schwyz. The most widely publicised attack, however, was when a ransomware group attacked security soft - ware provider Xplain, which supplies numerous Swiss government agencies. The attackers claimed to have stolen over 900 GB of sensitive data, including infor - mation linked to the Swiss Army, customs, and police. An investigation report commissioned by the Con - federation was issued on 28 March 2024. Noting the joint responsibility of Xplain and the Confederation in connection with this cyber-attack, the report pointed to the Confederation’s failure in its duties to select, instruct and supervise the personal data subcontrac - tor, in this case the company Xplain. In particular, the investigation report showed that no data processing contract had been concluded between the relevant federal administration units and Xplain. In an Xplain repeat, hackers hit Concevis, another major software vendor for the federal and cantonal governments. These attacks illustrate that a key threat is the rise of sophisticated, hard-to-detect ransomware attacks, including on critical infrastructure providers, and that even advanced countries like Switzerland are vulner - able to potentially crippling cyber-attacks. Recent regulatory updates While the increase in reported attacks highlights the urgency of robust cybersecurity, the issue is hardly new. Switzerland has responded to these challenges
386 CHAMBERS.COM
Powered by FlippingBook