CyOne Security AG
Zug
Secure Use of Standard Components
- 07 August 2026
- 100%
- Permanent position
- Zug
About the job
Government organisations often rely on standard components for cost and efficiency reasons. To ensure cyber security is not compromised, customised additions with specific security functions are required. Learn more about "customised" standard components in the blog post.
More and more people are working remotely, whether on the train or from home. This flexibility meets the needs of employees. This is also shown by the FlexWork Trend Study 2025 from the University of Applied Sciences Northwestern Switzerland: mobile working has become firmly established in Switzerland. The details of its implementation are often still a topic. To compete with companies for skilled workers, administrations and public institutions must continue to invest in more flexible working models.
Investments in reorganising IT processes come with specific challenges: high cost pressure and limited resources. Therefore, authorities often rely on standard components, known as "commercial off-the-shelf" products (COTS). This affects cyber security because the infrastructure with numerous peripheral devices such as notebooks or mobile phones is often inadequately protected. This is not only because these devices are usually not hardened. The low prioritisation of device management also plays a role, as well as insufficient attention to security settings and necessary updates.
Risks in the Supply Chain
Further dangers lurk in the supply chain. It is difficult to control and fully trace today's international supply chains. This increases the risk of supply chain attacks. Hardware, software, and updates can already be compromised at the factory. For authorities, this means: if they rely on standard components, there is a risk that systems and infrastructure will be attacked, classified information will leak, and fall into the wrong hands.
Security with Standard Components
Authorities are thus in a dilemma: they want to protect sensitive data against cyber-attacks while efficiently fulfilling their tasks within budget constraints. This is also possible with standard components – if they are "customised" and adapted to the specific requirements of Swiss authorities.
CyOne Security supports authorities in designing and implementing an agile security architecture. The hardware of standard components is supplemented and hardened with additional configurable security functions, security hardware, and firmware elements. These include, for example, Hardware Security Anchors that encrypt both stored and "in transit" data. This, in turn, allows a secure connection of mobile devices to the central IT infrastructure. This way, authorities consistently achieve a top security level right to the periphery.
Choosing secure and hardened standard components is an important step. Equally crucial, however, is to keep the risks along the entire supply chain in view.
Would you like to deepen your knowledge of supply chain security and learn more about the key measures for a secure supply chain? Our whitepaper "Supply Chain Security: Ensuring Suppliers and Partners Do Not Become a Threat" provides valuable insights and all you need to know about supply chain security.