Blog
Blog

The ICT minimum standard: improving cyber resilience systematically

ISMS Framework 1 October 2024 By fortControl editorial team

Digital processes have become indispensable in everyday business. At the same time, dependence on IT systems, cloud services, networks and external service providers keeps growing. A cyber incident therefore no longer affects IT alone — it affects core business processes, customers, supply chains and, in the worst case, the entire operation.

The Swiss ICT minimum standard offers companies a practical framework for assessing and systematically improving their cyber resilience.

Originally developed above all for operators of critical infrastructure, it can also serve as guidance for ordinary SMEs. For the electricity and gas sectors, binding sector-specific requirements now apply. For other companies, the ICT minimum standard remains a voluntary but valuable instrument for systematically improving their own cyber security.

What is the ICT minimum standard?

The ICT minimum standard was developed by the Swiss national economic supply organisation to give companies and organisations a practical instrument for improving their ICT resilience. Since March 2024, responsibility for the ICT minimum standards has rested with the Federal Office for Cybersecurity BACS.

The general ICT minimum standard is aimed in particular at operators of critical infrastructure, but in principle it can be used by any company and any organisation.

Its major advantage: it translates cyber security into concrete measures and a structured assessment process. That makes it possible to ask not only “Are we sufficiently protected?” but far more concretely: “Where do we stand today, where are the gaps and what do we need to improve?”

108 measures for greater cyber resilience

The current general ICT minimum standard 2023 is based on the NIST Cybersecurity Framework Core and comprises 108 measures along five functions.

  1. 1 Identify
  2. 2 Protect
  3. 3 Detect
  4. 4 Respond
  5. 5 Recover
The five functions of the ICT minimum standard 2023, based on the NIST Cybersecurity Framework Core.

Identify
Which systems, data, processes, dependencies and risks are relevant for the company?

Protect
Which organisational and technical measures are necessary to protect important systems and information appropriately?

Detect
How does the company recognise unusual activity or possible security incidents in good time?

Respond
Which processes, responsibilities and communication channels take effect when a cyber incident occurs?

Recover
How can affected systems, data and business processes be restored as quickly and in as orderly a manner as possible after an incident?

These five areas make one thing clear: cyber resilience means more than prevention. A company must not only try to prevent attacks. It must also be able to detect when something happens, respond appropriately and then restore operations.

From gut feeling to a structured status assessment

One of the biggest challenges in cyber security is assessing your own security level realistically. Many companies have already implemented numerous measures: firewalls are in place, backups are created, employees are trained and access rights are managed.

But is that enough? And above all: where are the remaining gaps?

The ICT minimum standard creates a structured basis for this. With the accompanying self-assessment, companies can evaluate the implementation status of each measure. The results show in which areas a good level has already been reached and where there is potential for improvement. The assessment can also serve as a basis for external reviews or comparisons.

This makes cyber security more measurable. A general judgement such as “we are basically well positioned” becomes a traceable assessment.

An assessment alone does not improve security

The assessment, however, is only the first step. The real value comes afterwards.

If it is found, for example, that responsibilities for security incidents are not clearly defined, a concrete measure has to follow. The same applies when backups are not tested regularly, access rights are not reviewed consistently or important systems are not sufficiently documented.

An effective process therefore combines several steps: assess, identify gaps, prioritise measures, define responsibilities, track implementation, review again.

Only then does an assessment become a continuous improvement process.

Cyber resilience has to fit the company

Not every company needs the same security measures to the same degree. A small consultancy has different dependencies and risks than an energy utility, a manufacturing business or a company with extensive critical infrastructure.

That is precisely why the ICT minimum standard follows a risk-based approach. The requirements and the target protection level should fit the respective organisation and its risk profile. The standard explicitly does not see itself as a competitor to international standards such as ISO or other established frameworks, but as a compatible and comparatively accessible entry point into systematically improving ICT resilience.

For SMEs this is particularly interesting. They do not have to start with a complex major project, but can first determine systematically where the greatest risks and the most urgent need for action lie.

Critical infrastructure: recommendation or obligation?

An important distinction is needed here. For many companies and sectors, the general ICT minimum standard serves as a recommendation and orientation aid. In individual areas, however, sector-specific minimum standards are now binding.

  • Electricity sector: binding requirements since 1 July 2024.
  • Gas sector: binding requirements since 1 July 2025.
  • For further areas such as water supply, waste water, public transport, food supply, waste disposal or district heating and cooling, sector-specific standards exist that currently have the character of recommendations.

It is therefore always worth checking which standard is relevant for your own sector and whether regulatory requirements arise from it. What that looks like in practice for the gas sector is shown in the article Cyber security for gas suppliers.

And what does an ISMS have to do with it?

The ICT minimum standard is very well suited to determining the current state of cyber resilience and making concrete improvement potential visible.

In the long run, however, another question arises: how are risks, measures and responsibilities managed on a lasting basis?

This is exactly where an information security management system — ISMS for short — comes in. An ISMS creates the organisational framework in which information security is managed continuously. Risks are assessed regularly. Measures are assigned to owners. Objectives are defined. Results are reviewed. Changes in the company and new threats feed into further development.

The ICT minimum standard and an ISMS are therefore not in conflict. The ICT minimum standard can show where the company stands. An ISMS helps to manage the resulting tasks over the long term.

From assessment to measure with fortControl

With larger assessments in particular, the question quickly arises of how results are processed further. Which requirements are met? Where are the gaps? Which measures were derived from them? Who is responsible? By when do the measures have to be implemented? And how has the security level developed since the last assessment?

Anyone spreading this information across various Excel files, documents and emails quickly loses the link between assessment and implementation.

fortControl helps companies map the ICT minimum standard in a structured way within an information security management system. Controls can be assessed and improvement potential made visible. Concrete measures can be derived from identified gaps, responsibilities assigned and their implementation tracked.

The decisive advantage does not lie in filling in a checklist digitally. It lies in turning the assessment into a manageable process.

Review regularly instead of ticking off once

Cyber resilience is not a state that is reached once and then remains unchanged. New systems are introduced. Cloud services are added. Suppliers change. Employees join or leave. New vulnerabilities become known and attack methods change.

Even a good assessment can therefore lose relevance over time. Companies should reassess their cyber resilience regularly and whenever significant changes occur, and check whether existing measures are still appropriate and effective.

A historical view helps here: how were individual areas rated in the last assessment? Which measures have been implemented since then? Where has the security level improved? And where is action still needed?

That is exactly how progress becomes visible.

The ICT minimum standard as a pragmatic entry point

Not every company immediately needs a complex information security programme or an ISO/IEC 27001 certification. But every company should know how well prepared it is for a cyber incident.

The ICT minimum standard offers a practical and structured entry point. It helps to examine relevant security areas systematically, to classify existing measures and to make gaps visible.

The real benefit, however, only arises when concrete improvements follow from these insights: determine your status, identify risks, derive measures, take responsibility, review progress.

With fortControl these steps can be combined into one continuous process. A security check thus becomes continuous management of your own cyber resilience — and individual measures grow into a resilient security structure.

Loslegen

Risiken im Blick. Sicherheit im Griff.

Lernen Sie fortControl in einer persönlichen Demo kennen.

fortControl – Risikomanagement und Informationssicherheit einfach steuern.