Cyber Resilience Assessment: How Resilient Are Swiss Municipalities and Companies Against Cyberattacks?
The Federal Office for Cybersecurity (BACS) has developed a standardized tool for assessing cyber resilience and tested it for the first time under real-world conditions in the canton of Aargau. The results show that while basic IT security measures are in place, many organizations still lack a comprehensive, process-oriented resilience strategy.
Editorial
-
July 6, 2026
Photo: depositphoto/maxkabakov
The ability to maintain essential services even after cyberattacks and IT disruptions is becoming increasingly important for organizations. In practice, however, there is often no structured framework for assessing an organization’s own level of cyber resilience and comparing it with that of other stakeholders. The BACS has therefore, in accordance with its Cybersecurity and Resilience Methodology (CSRM) developed the cyber resilience assessment. It enables organizations to conduct a self-assessment based on six resilience objectives and provides the foundation for benchmarking.
Unlike many established IT security frameworks, such as NIST CSF or ISO 27001, the cyber resilience assessment deliberately focuses on an organization’s business-critical processes and their dependencies on IT and OT systems.
Pilot Project in the Canton of Aargau
A pilot project was conducted in the canton of Aargau from mid-February through the end of March 2026 for practical testing. A total of 25 organizations participated: 14 municipalities and 11 other organizations from the service, industrial, IT and telecommunications, electricity supply, and construction sectors. The organizations conducted the self-assessment independently. Depending on the organization, completing the assessment checklist took up to one workday. The pilot served not only to gather initial insights into the content but also to test the digital survey tool. Feedback on the user interface and the clarity of individual questions is being incorporated directly into the tool’s further development.
Key Findings from the Pilot Project
The analysis reveals a consistent pattern across the various sectors: Many organizations have basic security measures in place, such as data backup, access controls, and IT system protection. However, there are significant weaknesses when it comes to systematically integrating these measures with their own business processes. The shortcomings are particularly evident in three areas:
First, in the structured mapping of IT and OT dependencies along business processes.
Second, in emergency and disaster recovery planning, where clear priorities and regular drills are often lacking.
Third, in the management of dependencies on external IT service providers—a pattern of vulnerability that is evident across all sectors.
In summary, it can be said that in many organizations, cyber resilience is still based on individual measures rather than on a holistic, process-oriented approach. While basic IT security measures are often in place, cyber resilience as a comprehensive approach has not yet been sufficiently embedded in many organizations.
Added Value for Organizations, Cantons, and the Federal Government
For participating organizations, the Cyber Resilience Assessment provides a structured assessment of their current status. It highlights strengths, identifies blind spots, and allows for the prioritization of measures. Benchmarking also allows for comparison with similar organizations, making it a valuable tool for clearly demonstrating the need for action to senior management. For cantons and the federal government, widespread use of CyRA provides an aggregated view of the resilience status of entire sectors. This lays the foundation for targeted support and awareness-raising measures, as well as evidence-based governance—particularly in the identified areas of supplier management and process-oriented governance of IT and OT security. The utility of the tool increases significantly with the breadth of the data set.
This provides cantons, associations, and the federal government with an aggregated view of the resilience levels of entire sectors.
Current Status and Outlook
The cyber resilience assessment is currently in the prototype stage. The pilot project in the canton of Aargau was the first practical test under real-world conditions. Based on the findings, the digital assessment tool is now being further developed with the goal of making it available to a broader user base. Among other things, this will involve improving the user interface, making individual questions easier to understand, and reducing the effort required to complete the assessment. In the future, shared IT systems, applications, and data will not need to be recorded separately for each process but can instead be assigned to multiple business-critical processes. In the medium term, consolidation into a single assessment catalog is planned to further improve the comparability of results. As the database grows, the cyber resilience assessment can become a central tool for evidence-based management of cyber resilience at the regional and national levels.
Source: BACS
(Visited 78 times, 2 visits today)
More articles on the topic
Progress in strengthening cyber security
Digital hygiene: routines to protect our data
2025: 71 percent of companies worldwide affected by at least one case of identity theft
SECURITY NEWS
Stay informed about current security topics - practical and reliable. Receive exclusive content directly to your inbox. Don't miss any updates.