Swiss perspectives in 10 languages

Swiss electricity grid vulnerable to cyberattack

Warning sign by electricity pylons
The threat of cyberattacks against energy providers has never been stronger. © Keystone / Gaetan Bally

Swiss electricity providers are vulnerable to a Colonial Pipeline style ransomware attacks, according to a report from the Swiss Federal Office for Energy.

While certain weaknesses against cyberattacks have previously been identified, progress towards protecting Switzerland’s electricity grid appears to be slow, says the Neue Zürcher ZeitungExternal link newspaper.

Several companies surveyed by the energy ministry reportExternal link have only achieved basic protection against cyberattacks – a score of one on a sliding scale of 0-4.

Energy providers should have reached a score of 2.6 by now, energy ministry expert Matthias Galus told the NZZ. The report called the results “sobering” and said they demonstrated a “fundamental need for action”.

Only 124 of 750 firms targeted by the survey responded. “This low participation rate for a topic that is so important for the security of [energy] supply in the digital era amazed me,” he said.

The Association of Swiss Electricity Companies did not comment directly on the survey but told the Swiss News Agency Keystone-SDA that its members took cyber security seriously and are working towards long-term solutions.

US example

The threat of cyberattacks on energy providers was highlighted by a successful ransomware attack on the United States oil and gas provider Colonial Pipeline earlier this year, which seriously disrupted supply to the southeastern US.

In 2018, the Swiss government set minimum IT security standards for critical infrastructure but allowed companies to self-regulate their compliance.

Last year, the government set up a study to better identify weak points with the aim of tightening up legislation by the end of this year. The plan is to oblige critical infrastructure firms (in areas such as energy, healthcare, water supply, transport and finance) to report directly to the National Cybersecurity centre.

The recent energy ministry survey noted that “the current lead of the EU states in the field of cyber security and resilience currently appears to be considerable.”

In compliance with the JTI standards

More: SWI swissinfo.ch certified by the Journalism Trust Initiative

You can find an overview of ongoing debates with our journalists here. Please join us!

If you want to start a conversation about a topic raised in this article or want to report factual errors, email us at english@swissinfo.ch.

SWI swissinfo.ch - a branch of Swiss Broadcasting Corporation SRG SSR

SWI swissinfo.ch - a branch of Swiss Broadcasting Corporation SRG SSR