26.06.2026 - The National Cyber Security Centre (NCSC) has developed a standardised tool for assessing cyber resilience and tested it under real-world conditions for the first time in the canton of Aargau. The results show that basic protective IT measures have been put in place, but many organisations still lack a holistic, process-oriented resilience strategy.
The ability to maintain essential services following cyberattacks and IT disruptions is becoming increasingly important to organisations. In practice, however, they often lack a structured framework for assessing their own cyber resilience level and comparing it with that of other stakeholders. The NCSC has therefore developed the Cyber Resilience Assessment , which is based on its Cybersecurity and Resilience Method (CSRM). Cyber Resilience Assessment enables organisations to carry out a self-assessment covering six resilience objectives and forms the basis for benchmarking. Unlike many established approaches to IT security, such as NIST CSF and ISO 27001, Cyber Resilience Assessment deliberately focuses on business-critical processes within an organisation and their dependencies on IT and OT systems.
Pilot project in the canton of Aargau
To test the tool in practice, a pilot project was run in the canton of Aargau from mid-February to the end of March. A total of 25 organisations took part, including 14 communes and 11 other organisations from the service, industry, IT and telecommunications, electricity supply and construction sectors. The organisations carried out the self-assessment independently, and completing the assessment catalogue took up to one day’s work, depending on the organisation. The pilot was designed not only to gain initial insights into content, but also to test the digital survey tool. Feedback on the user interface and the clarity of individual questions will be incorporated directly into the further development of the tool.
Key findings from the pilot project
The assessment reveals a consistent picture across the various sectors: many organisations have implemented basic protective IT measures, such as data backup, access controls and IT system protection. By contrast, they demonstrate significant weaknesses in integrating these measures into their own business processes. The shortcomings are particularly evident in three areas: firstly, in structured mapping of IT and OT dependencies across business processes; secondly, in contingency and recovery planning, where clear prioritisation and regular training exercises are often lacking; and thirdly, in managing dependencies on external IT service providers – a pattern of vulnerability that can be seen across all sectors. In summary, it can be said that cyber resilience in many organisations is still based on individual measures, rather than a holistic, process-oriented strategy. While basic IT security measures often exist, a comprehensive approach to cyber resilience is not yet sufficiently established in many organisations.
Added value for organisations, cantons and the federal government
Cyber Resilience Assessment provides participating organisations with a structured assessment of their current cyber resilience levels. It highlights strengths, identifies blind spots and allows measures to be prioritised. In addition, benchmarking enables comparison with similar organisations, making it a useful tool for communicating transparently with managers about the need for action. For cantons and the federal government, widespread use of Cyber Resilience Assessment provides an aggregated overview of resilience levels across entire sectors, laying the foundation for targeted support, awareness-raising measures and evidence-based management. This is particularly relevant to supplier management and process-oriented IT and OT security management, which have been identified as action areas. The benefits of the tool increase significantly as the breadth of the data set grows.
For cantons, associations and the federal government, this provides an aggregated overview of resilience levels across entire sectors.
Current situation and outlook
Cyber Resilience Assessment is currently at the prototype stage. The pilot in the canton of Aargau was the first practical test under real-world conditions. Based on the insights obtained, the digital assessment tool is now being further developed with the aim of making it available to a wider user base. This includes improving the user interface, phrasing individual questions more clearly and reducing the time required to complete the assessment. In future, shared IT systems, applications and data will not need to be recorded separately for each process; instead, it will be possible to assign them to multiple business-critical processes. In the medium term, the plan is to consolidate the assessment into a single catalogue in order to make the results more comparable. As the data set grows, Cyber Resilience Assessment has the potential to become a key tool for evidence-based management of cyber resilience, both regionally and nationally.