MITA
Protecting ourselves from potential cyber threats
The Maltese Government is launching its first National Cyber Security Strategy which will provide a framework for protecting systems, networks, information on the internet and also the users of cyber space. MITA's consultant on ICT Policy & Cyber Strategy, Dr Keith Cilia Debono gives us an overview about MITA's role in the formulation of this strategy and explains the principles upon which it is based.
What is Cyber Security?
Let us start by first explaining what we mean by cyber space. At first instance, the following items come to mind - the Internet, the underlying ICT infrastructure, the interconnected systems, the information that is flowing or else being processed or stored. All these form an integral part of what we mean with cyber space. However, let us not forget the underlying processes, the usage of such ICTs - and of course, the people using them. In simpler terms, we are referring to services which are either rendered or received like for example on-line shopping, Internet banking or on-line chatting with friends.
Unfortunately, the world of cyber space is far from being perfect. Its users may not necessarily use it appropriately - they may be negligent or they may have malicious intent; exploiting vulnerabilities in cyber space so as to steal information that often translates into big money, or else to tarnish the reputation of individuals, or possibly to sabotage commercial or national interests. This may have serious consequences considering the extensive use of interconnected ICT in our day to day lives. We need to ensure the confidentiality, integrity and availability of cyber space at all times - hence the need to address cyber security. We need to protect our national interests, businesses, our families and ourselves. We need to be prepared - aware of the potential cyber threats lurking in our own homes, businesses - irrespective of size - and to our national economy as a whole.
Therefore, as we can see, cyber security is not all simply addressing the technical aspect - that would be a myopic vision. Cyber security essentially calls for ways to address human resource aspects - behavioural, procedural, governance aspects, among others.
Why is it important that a country has a strategy of its own about Cyber Security?
In essence, cyber space touches all aspects of a nation's society and the economy. Its security is not a one off consideration. The evolvements - technical and behavioural - within the cyberspace are rapid and tend to outpace the ways of ensuring its security. For example, within a time span of a few years, we have seen huge developments in mobile technology and social media, amongst others and in their use. Smart technology and 'Internet of Things' by which we can even digitally control our household appliances remotely shall increasingly feature in our day to day lives.
It therefore calls for an ongoing and systemic approach that essentially requires cooperation and coordination from multiple multi-disciplinary stakeholders.
Additionally, cyber space knows no national territory. It is mostly so from a security aspect. The security challenges vary from being very sophisticated to involving various perpetrators who are often skilled and experts not just in technical matters, but also in psychology, amongst other disciplines. For example, how many times have people received a phone call fraudulently asking for access to their computer, logins or personal details and in some unfortunate cases lured into doing so? Hence there is the need to plan ahead and coordinate with other countries to ensure effective cyber security.
Ultimately, addressing cyber security involves resources - human, technical and financial - both within the short to medium term as well as in the future. Hence, there is the need to plan for such factors, within a mind-set of cyber security as an investment rather than as a cost.
All such factors call for the need for a country to have a strategy focussing on addressing cyber security.
It is for such reasons that Malta, along with other countries within the European Union and across the globe, is having its own National Cyber Security Strategy.
Is this the first strategy for our country? If yes, how did we manage to operate until now?
Yes, this shall be the first issue of a National Cyber Security Strategy. It however does not imply that nothing has been done to date. There have already been initiatives and actions taken to date in areas such as those related to cyber crime, cyber awareness, protection of critical infrastructure, legal aspects, among others. However, there is now the need for a concerted approach, rather than a piecemeal approach as ultimately addressing cyber security effectively calls for multi-stakeholder involvement and participation.
On what principles is the strategy being based upon?
The key principles aim to reflect the various facets of cyber security and of course the essential underlying complex nature of cyber space.
Primarily, whilst proposing ways of bolstering security, the Strategy aims to ensure respect to the fundamental rights, freedoms, and of course obligations, of the individual as enshrined within our Constitution and also within the ambit of the legal framework within the European Union of which Malta forms part.
Another key principle is that of cooperation and coordination across multiple stakeholders, even from varied disciplines and countries, considering the horizontal, boundary-less nature of cyber security.
One must also not discount the fact that it is in everyone's interest to ensure cyber security, given the interconnectedness of cyber space and that the weakest link within the chain may lead to undesirable consequences in other parts of the chain. Hence, whilst Government takes a leading role, responsibility for cyber security cannot simply be vested within Government but also within the private sector and ultimately, the individual user.
Essentially, given the dynamic nature of cyber space and the ensuing cyber security challenges which are also continuously evolving, one cannot be 100% foolproof from any potential vulnerability. Additionally, the nature and extent of the threats and hence the risks involved may vary. To top it all, addressing cyber security does involve a degree of cost and potentially effort. Hence, there is also the need for a risk culture - that is one where there is the need to assess risks involved and apportion the cost and effort accordingly.
Which are the key factors to consider in a national cyber security strategy?
Let us start with the key notion that cyber security is here to stay. It calls for permanence. Hence, it fundamentally calls for the necessary governance; that is, the Strategy itself and its implementation, related roles, responsibilities, processes, policies that do not necessarily just involve the public sector but also the private sector.
Cyber crime is a major headache. The latest Eurobarometer report focusing on Cyber security reveals that EU citizens have become increasingly concerned about becoming a victim of
Cyber crime. This includes concern on theft of personal digital identity (68%), discovery of malicious software on devices used (66%), online banking fraud or bank card fraud (63%), social media or email account hacking (60%). Indeed the two most common scenarios experienced were those of malicious software on device or fraudulent phone calls.
This calls for the need to have the necessary mechanisms and measures - technical, human resource, legal and to strengthen them wherever and whenever necessary. Addressing cyber crime also essentially calls for close cooperation with other countries; considering that perpetrators, more often than not, operate on international network basis.
Cyber security also increasingly plays a crucial role in national security. A nation's integrity may be compromised through cyber related attacks, which may potentially be instigated by other nation-states. Hence, there is the need to invest accordingly in a nation's cyber defence, also taking into account aspects such as cyber diplomacy which is increasingly taking a higher profile on an EU and on an international level.
A nation's long term preparedness in cyber security also entails ensuring the relevant legislation and where applicable the necessary updated regulations within various sectors. However, one has to keep in mind that legislation and regulation may not necessarily be a solution to all various business scenarios. Voluntary self-commitment particularly in small and/or resource constrained enterprises, potentially enabled by incentives, should therefore be encouraged.
Ultimately, an ongoing, sustained awareness campaign to ensure preparedness by all strata of Malta's economy and society is needed. This is not lacking at this stage; but definitely it needs to be intensified further so as to ensure an all inclusive message for effective cyber security.
Talking about preparedness, this also calls for the availability of the right skills set, for which the educational sector needs to cater for so as to meet the medium to long term related requirements of the nation. Indeed, awareness and education are seen as key effective tools in addressing the cyber security challenge.
All factors mentioned above cannot be accomplished without commitment and mutual cooperation by the various parties involved. A battle cannot be won with no coherent strategic direction and coordinated effort among an army itself! The same applies for cyber security.
How was the National Cyber strategy devised?
Digital Malta - the national digital strategy for Malta for the years 2014-2020 called for a National Cyber Security Strategy as one of its action items. The task was assigned to MITA and in February 2015, MITA earnestly conducted the necessary research locally and internationally. The wheel was not re-invented. Reference has been made to EU guidelines, as well as national cyber security strategies within and outside the European Union. Yet, special consideration was given to ensure relevance to the local context. Strategic direction was provided by a Ministerial multi-disciplinary steering committee.
The research led to the issue of a Green paper for a National Cyber Security Strategy, outlining the principles, and proposed goals and measures to address cyber security on a national scale. The Green paper was subject to national consultation and feedback - on-line, as well as through a series of sectoral consultation sessions - essentially involving economy and finance, education and awareness, justice and legislation, infrastructure and health, national security, foreign policy and the public.
In this regard, the Strategy has taken a robust approach in its articulation, leading to an early awareness for its need and for its implementation, in the process.
The National Cyber Security Strategy is going to be launched tomorrow by the Minister for Competitiveness, and Digital, Maritime and Services Economy.
What is the way forward upon launch of the Strategy?
The Strategy shall essentially call for action from various multiple players, within the public sector as well as within the private sector. As in all cultural paradigm changes, it is no easy feat. Whilst some areas may be fully conscious of the need to address cyber security and in a coordinated manner, it may still need to be further understood in other areas.
On the other hand, a strategy is not cast in stone. It shall need to evolve along with its implementation and changing overall scenario. The same applies to the National Cyber Security Strategy. Hence the Strategy shall need to reflect the changing realities within cyber space itself on the local scene so as to ensure its adaptability and ongoing relevance. Cyber security is a never ending story, and this is what the strategy shall need to reflect.