Meeting the Swiss ICT Minimum Standard
The Swiss ICT Minimum Standard gives operators of critical infrastructure a concrete framework. Its strength — a highly operational set of controls — is also its difficulty: you have to know where you stand on each one, and prove it. Here is how we make the exercise manageable.
A demanding framework, to be turned into a realistic path
Published by the Federal Office for National Economic Supply (FONES), the ICT Minimum Standard is aimed primarily at operators of critical infrastructure — energy, transport, water supply, healthcare, telecommunications — and at their suppliers. It is built around the five functions of the NIST Cybersecurity Framework: identify, protect, detect, respond, recover.
Its value lies in its granularity: dozens of concrete controls, each rated on a maturity scale. That is also where it stalls: a self-assessment run without method produces a spreadsheet nobody knows how to use, and in which everything looks urgent.
Our approach is to assess what exists honestly, concentrate the effort on the controls that genuinely reduce risk in your context — often IT/OT separation, remote access and backups — then document the evidence a review will ask for.
- A self-assessment based on statements, with no supporting evidence
- OT environments left outside the scope of the exercise
- Supplier remote access insufficiently controlled
- No detection or logging on the industrial perimeter
- Recovery plans never tested in real conditions
From five functions to a marked-out path
How we proceed
Progress in stages, calibrated on your actual criticality rather than on the whole framework at once.
Scope and mapping
Identification of the critical activities, of the systems that support them — business IT as much as industrial systems — and of the dependencies on suppliers. Without that foundation the assessment stays theoretical.
Guided self-assessment
A run through the controls of the standard with your teams, rating maturity on verifiable facts. We distinguish what is in place, what is partial and what is merely stated.
Prioritised roadmap
Translation of the gaps into an action plan ordered by risk reduction and by effort, in reachable stages rather than one large programme that is hard to fund.
Implementation and evidence
Deployment of the technical controls (segmentation, remote access, hardening, logging, backups) and assembly of the evidence: configurations, procedures, test reports.
Exercise and reassessment
Testing the response and recovery capability, then a fresh assessment to establish the progress objectively and to feed reporting to the board and the authority.
Several disciplines, a single point of contact
The standard covers organisation, technology and recovery: we bring in GRC advisory, integration, offensive testing and monitoring according to the functions to strengthen.
- Map of critical activities and the systems behind them
- Rated self-assessment, control by control
- Prioritised roadmap in stages
- Evidence file (configurations, procedures, reports)
- Exercise report and maturity reassessment
Frequently asked questions
Where do you stand on the ICT Minimum Standard?
A guided self-assessment gives an honest picture of your maturity and the path to raise it.