Cookies

This website uses cookies that require your consent.

Skip to content

"How fit are Swiss companies in terms of ICT security - and what can they expect?"

Information and communication technologies (ICT) have long been the backbone of modern companies - especially in critical infrastructures. But how well are Swiss companies positioned in terms of cyber security? Which sectors are under particular pressure? And how can the path to a minimum ICT standard be achieved in practice?

We spoke to Michael Gempp, ICT security expert at CTE. He helps companies set up robust OT and IT infrastructures and knows the challenges first-hand.

What exactly does the ICT minimum standard cover - and why is it so important for companies?

Michael Gempp: The ICT Minimum Standard defines the basic requirements for information and communication technology—that is, IT and OT—for organizations with heightened security needs. The goal is to establish a uniform minimum level of cybersecurity. This is particularly essential for operators of critical infrastructure, as an incident can have far-reaching consequences. But other industries also benefit: The standard serves as a pragmatic guide for systematically improving an organization’s security posture.

How do you go about reviewing a company's ICT security situation?

Michael Gempp: We begin with a structured assessment—both technical and organizational. In doing so, we examine existing systems, processes, interfaces, and responsibilities. Using a structural analysis, we evaluate the current state against the requirements of the minimum ICT standard. From this, we derive specific measures—prioritized, practical, and tailored to the company.
You don't have to implement everything immediately - but you need to know where you stand.
Michael Gempp, IT System & Security Architect CTE AG

Which sectors are particularly affected or under particular pressure?

Michael Gempp: Above all, companies that rely heavily on automated processes or networked control systems—such as energy providers, public transportation operators, water utilities, healthcare institutions, and the manufacturing industry. In these sectors, it is not only system availability that is critical, but also the integrity and traceability of the systems. Regulations such as CySec-Rail or industry-specific requirements further heighten the pressure to take action.

Where are the most common security gaps - and why do they often go unnoticed?

Michael Gempp: Many vulnerabilities stem from a lack of organization: unclear responsibilities, ambiguous processes, and inadequately documented systems. This affects the technical environment and creates security gaps that are then exploited. In OT, security is too often viewed as a purely technical issue, yet there is a lack of comprehensive security management. And because nothing “visible” happens in day-to-day operations, people underestimate just how vulnerable they actually are.
Graphic ICT minimum standard with the five main areas.
The five areas of the ICT minimum standard form independent fields of action for cyber security. We implement specific sub-areas of these for our customers as required.

How realistic is it to implement the ICT minimum standard as an SME?

Michael Gempp: Absolutely realistic. While the standard sets out clear requirements, not everything has to be implemented immediately or in full. What’s important is that companies know where they stand—and that they understand their risks. With a targeted assessment and a realistic action plan, many areas can be improved step by step without overburdening operations.

Where is the journey heading? What developments do you see in the field of ICT security in the coming years?

Michael Gempp: The pressure will increase—due to new regulations, but also because of the growing reliance on digital processes. IT and OT are converging more closely, which raises the bar for security and governance. In the future, companies will increasingly need to prepare for audits, compliance requirements, and structured processes. Those who are prepared now will have a clear advantage later on.

What is your personal advice to companies that want to address this issue now?

Michael Gempp: Many vulnerabilities stem from a lack of organization: unclear responsibilities, ambiguous processes, and inadequately documented systems. This affects the technical environment and creates security gaps that are then exploited. In OT, security is too often viewed as a purely technical issue, yet there is a lack of comprehensive security management. And because nothing “visible” happens in day-to-day operations, people underestimate just how vulnerable they actually are.
Photo of Michael Gempp, Business Unit Manager for Industrial IT at ControlTech Engineering AG.

Would you like to know where you stand in relation to the ICT minimum standard?

Schedule a no-obligation consultation with Michael Gempp, Business Unit Manager for Industrial IT.

Please contact us.