On 5 May the US Cybersecurity and Infrastructure Security Agency CISA launched an initiative that on the surface seems relevant only for operators of critical infrastructure: CI Fortify. The core message is that organisations should prepare to keep their essential processes running even when IT systems are compromised, telecommunications fail and internet connections go wobbly, all at the same time.
That sounds like a scenario for energy companies and hospitals, and it is, but only if you stop reading there. Anyone who digs deeper will find lessons in it that matter to every Swiss SME, and most of them are uncomfortable.
What CI Fortify asks for
At its heart the initiative comes down to two things: isolation and recovery. Isolation means you can cut critical systems loose from compromised networks and unreliable external dependencies. Recovery means you get operations back up after an incident within a timeframe you have set beforehand, not “eventually”.
The striking part is what CISA assumes as the baseline: attackers are already in the network, telecoms and internet can go down at the same time, and suppliers and outside service providers are unreachable. That sounds paranoid but it is simply what multiple state-backed threat actors have demonstrated over the past few years (Volt Typhoon inside US infrastructure, Sandworm in Ukraine).
Worth noting is that CI Fortify is not a regulation and carries no legal weight, not even in the US. But CISA is making clear that these expectations will become the yardstick after the next big incident, in regulatory reviews, insurance claims and courtrooms. That is the part you should not skim past.
What does this have to do with Swiss SMEs?
Honestly, at first glance not a lot, because Swiss SMEs do not run power grids or water treatment plants. But they sit inside supply chains that feed into critical infrastructure: a hospital supplier here, an IT service provider for a municipality there, a pharma logistics firm. These are all links in a chain that is increasingly being judged on resilience, whether you signed up for that or not.
And forget the supply chain for a moment, because the central question CI Fortify poses applies to literally every business: what happens when your IT goes down, not for an hour but for three days? Can you still process orders? Send invoices? Talk to clients? Run payroll?
Switzerland does not really push companies on this. The new Information Security Act (ISG) and its accompanying ordinance set reporting duties for critical infrastructure operators, but for the vast majority of SMEs there are no binding requirements around business continuity whatsoever. That does not mean the risk is not real, it just means nobody makes you plan for it, which makes the problem worse rather than better.
Common gaps
We run assessments at Swiss companies regularly, and it is the same story over and over. Backups exist but nobody has ever tested whether a restore actually works (a surprising number of times it does not). IT documentation is patchy or stale, sometimes both; nobody knows who is supposed to make which call in an emergency. And the reliance on specific cloud services is almost never thought through to its logical end, because what happens when Microsoft 365 is unreachable for three days? The honest answer is usually: chaos.
The almost funny part is that most of these gaps can be closed with remarkably little effort. A documented emergency plan, a tested backup restore and a basic communication chain for when things go wrong, that is one to two working days total. Most SMEs spend more time on their annual stocktake, but the stocktake has a deadline on the calendar and the emergency plan does not. Until it does.
Five questions as a self-test
Can you name your business-critical systems? Not IT systems in general, but the three to five without which your operations grind to a halt.
Have you tested your backups in the last six months, not whether they run but whether a full restore actually works?
Is there a plan for how you reach clients and partners when your email and phone both go down at the same time?
Do your employees know who to call when they walk into the office one morning and nothing works?
Have you agreed a defined response time with your IT provider, and is it written into the contract?
More than two “no”s? Then a short foundational project is worth your while. Not full-blown business continuity management per ISO 22301 (that would be overkill for most SMEs), but a pragmatic emergency plan that fits on two pages and everyone actually knows about. Sounds simple, and it is, which is exactly why so few bother…
Conclusion
CI Fortify is an American programme aimed primarily at geopolitical threats, but the underlying idea is universal: if you know your dependencies, have tested your recovery and understand how to keep operating in an emergency, you will be in a far stronger position after an incident. Whether that incident is ransomware, a cloud outage or a flood stops mattering at that point.
Whether someone thought about it beforehand, that is the question that actually matters…
We help Swiss SMEs build pragmatic emergency plans and test in our assessments how robust your IT infrastructure really is. Get in touch if you would like to know where you stand.
Sources: CISA CI Fortify Announcement, The Record: CISA Initiative, Swiss Information Security Act