Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Critical infrastructure

Meeting the Swiss ICT Minimum Standard

The Swiss ICT Minimum Standard gives operators of critical infrastructure a concrete framework. Its strength — a highly operational set of controls — is also its difficulty: you have to know where you stand on each one, and prove it. Here is how we make the exercise manageable.

The challenge

A demanding framework, to be turned into a realistic path

Published by the Federal Office for National Economic Supply (FONES), the ICT Minimum Standard is aimed primarily at operators of critical infrastructure — energy, transport, water supply, healthcare, telecommunications — and at their suppliers. It is built around the five functions of the NIST Cybersecurity Framework: identify, protect, detect, respond, recover.

Its value lies in its granularity: dozens of concrete controls, each rated on a maturity scale. That is also where it stalls: a self-assessment run without method produces a spreadsheet nobody knows how to use, and in which everything looks urgent.

Our approach is to assess what exists honestly, concentrate the effort on the controls that genuinely reduce risk in your context — often IT/OT separation, remote access and backups — then document the evidence a review will ask for.

What is at stake
  • A self-assessment based on statements, with no supporting evidence
  • OT environments left outside the scope of the exercise
  • Supplier remote access insufficiently controlled
  • No detection or logging on the industrial perimeter
  • Recovery plans never tested in real conditions
Diagram

From five functions to a marked-out path

Path to compliance with the ICT Minimum Standard IdentifyProtectDetectRespond & recover1Scope &assets2Self-assessment3Prioritisedgaps4Technicalcontrols5Detection& logging6RecoveryexerciseMaturityevidenced
Identify, protect, detect, respond and recover: each function turns into assessable controls and evidence that will stand up to review.
Our approach

How we proceed

Progress in stages, calibrated on your actual criticality rather than on the whole framework at once.

01

Scope and mapping

Identification of the critical activities, of the systems that support them — business IT as much as industrial systems — and of the dependencies on suppliers. Without that foundation the assessment stays theoretical.

02

Guided self-assessment

A run through the controls of the standard with your teams, rating maturity on verifiable facts. We distinguish what is in place, what is partial and what is merely stated.

03

Prioritised roadmap

Translation of the gaps into an action plan ordered by risk reduction and by effort, in reachable stages rather than one large programme that is hard to fund.

04

Implementation and evidence

Deployment of the technical controls (segmentation, remote access, hardening, logging, backups) and assembly of the evidence: configurations, procedures, test reports.

05

Exercise and reassessment

Testing the response and recovery capability, then a fresh assessment to establish the progress objectively and to feed reporting to the board and the authority.

Services involved

Several disciplines, a single point of contact

The standard covers organisation, technology and recovery: we bring in GRC advisory, integration, offensive testing and monitoring according to the functions to strengthen.

Deliverables
  • Map of critical activities and the systems behind them
  • Rated self-assessment, control by control
  • Prioritised roadmap in stages
  • Evidence file (configurations, procedures, reports)
  • Exercise report and maturity reassessment
Frequently asked questions

Frequently asked questions

Formally it is a federal recommendation, but it is becoming binding in practice: several sector regulators, clients and insurers refer to it, and some cantons or industries impose it contractually. Treating it as a requirement is the prudent position today.

ISO 27001 certifies a management system; the ICT Minimum Standard assesses the maturity of a set of highly operational controls, with a Swiss anchoring and a critical-infrastructure focus. The two complement each other well: the ISMS brings the governance, the standard brings the technical granularity.

Yes, and that is often where the gaps concentrate. We apply an approach suited to OT availability and safety constraints — no intrusive scanning of a controller in production — drawing on our practice in ICS/SCADA environments.

The guided self-assessment usually runs over a few weeks. Closing the gaps then depends on what they are: we break it into stages of a few months so that each step brings a visible, fundable reduction in risk.

Where do you stand on the ICT Minimum Standard?

A guided self-assessment gives an honest picture of your maturity and the path to raise it.