Webinar: National Cybersecurity Strategies – Implementation and Monitoring

Webinar: National Cybersecurity Strategies – Implementation and Monitoring

Opening Remarks and Introduction

Welcome and Introduction of Doreen Bogdan

  • The session begins with a greeting from the host, thanking attendees for joining from various parts of the world.
  • Doreen Bogdan, Director of BDT, is introduced to provide opening remarks.

Importance of Cybersecurity

Doreen Bogdan's Key Points

  • Doreen emphasizes that cybersecurity is crucial for digital strategies as cyber incidents affect institutions and individuals alike.
  • She highlights the collective responsibility to enhance cyberspace security and user confidence in online resources.

Digital Transformation and Cyber Risks

Challenges in Connectivity

  • As efforts are made to connect 3.6 billion unconnected people, attention must also be given to cybersecurity challenges that hinder effective web use.
  • COVID-19 has accelerated digital transformation but has also exposed vulnerabilities in ICT infrastructure due to evolving cyber risks.

Financial Impact of Cybercrime

Economic Consequences

  • Projected damages from cybercrime are expected to exceed $6 trillion in 2021, affecting various sectors including finance, healthcare, and government agencies.
  • Investment in cybersecurity infrastructure is critical for protecting businesses and customer data amidst rising threats.

National Cybersecurity Strategies

Importance of Comprehensive Strategies

  • Comprehensive national cybersecurity strategies are essential for managing cyber risks through coordinated actions among stakeholders.
  • ITU engages with countries on ongoing projects aimed at raising awareness and building necessary skills for effective cybersecurity governance.

Capacity Building Initiatives

Examples of ITU Activities

  • ITU conducts annual cyber drill exercises to improve incident response capabilities in developing countries while promoting child online protection initiatives.
  • A new guide for developing national cybersecurity strategies was launched with input from international partners to address contemporary challenges post-COVID pandemic.

Growth in National Strategies

Global Trends

  • The number of countries with national cybersecurity strategies has increased significantly from 76 in 2018 to 120 currently under development or already implemented.

Multi-Stakeholder Collaboration

Call for Partnerships

  • Doreen invites collaboration across sectors as multi-stakeholder partnerships are fundamental to ensuring a safe online environment for users today and future generations .

Closing Remarks by Doreen

Final Thoughts

  • Emphasizing the need for actionable solutions, she concludes her remarks by wishing participants a successful webinar .

Transitioning to Nick Espinosa

Introduction by Nick Espinosa

  • Nick introduces himself as Chief Security Fanatic at Security Fanatics and spokesperson for the COVID-19 Cyber Threat Coalition . He stresses the importance of adopting national cybersecurity strategies amid increasing criminal hacking activities .

Housekeeping Items

Panel Discussion Preparation

  • Nick outlines housekeeping rules including muting microphones during discussions , using chat only for relevant questions , and avoiding political topics during the session .

Mural Platform Usage

Collaborative Workspace

  • Participants will utilize Mural as an online collaborative workspace where recommendations will be gathered throughout the discussion . A link will be shared via chat shortly .

Recording Notice

Session Documentation

  • The session will be recorded , with recordings potentially used for ITU reports or materials related to empowering women in cybersecurity . Participants are reminded about this recording policy .

Panel Introductions Begin

Andrea Rigoni's Introduction

  • Andrea introduces himself after joining late , sharing his extensive experience in cybersecurity both on advisory sides and within government roles focused on international cooperation initiatives .

Additional Panelist Introductions:

Sam Visner (881)

  • Sam shares his background as director at MITRE’s National Cybersecurity Federally Funded Research Center along with his academic role at Georgetown University . He expresses gratitude towards ITU for hosting him today .

Chris Gibson (964)

  • Chris introduces himself as executive director at FIRST , highlighting his experience building CERT UK while emphasizing collaboration among incident response teams globally .

Agvile Ginotiene (1012)

  • Agvile discusses her role at UN Office Counter-Terrorism focusing on developing national strategies based on her previous consulting work across multiple regions .

Irfan Hemani (1082)

  • Irfan describes his current position drafting new UK government strategy alongside international work within digital culture ministry after starting out in private sector information security roles .

Pratima Pradhan (1180)

  • Pratima presents herself as senior ICT officer at Bhutan CERT having recently transitioned into this role following completion of her master’s degree last year .

Discussion Highlights:

Strategy Development Insights (1356)

  • Discussions emphasize growing popularity around formalized national strategies driven by global initiatives urging governments towards transparency regarding their approaches toward cyber security .

Distinction Between Policy & Strategy (1387)

  • A clear distinction between 'policy' which defines intentions versus 'strategy' which outlines execution methods is highlighted stressing importance behind coherent frameworks guiding implementation efforts effectively.

Gaps In International Governance (1689):

  • Sam identifies gaps existing within international governance structures advocating establishment common planning frameworks facilitating better understanding amongst nations leading towards improved cooperation overall.

The Need for International Transparency in Cybersecurity

Importance of International Mechanisms

  • Emphasizes the necessity for better international transparency to hold countries and criminal groups accountable for developing offensive cyber capabilities.
  • Cites the Comprehensive Test Ban Treaty Organization as a successful model for international monitoring of nuclear weapons testing, suggesting similar frameworks could be applied to cybersecurity.

Shared Understanding of Cyber Activities

  • Advocates for a collaborative approach to detect illicit cyber activities and hold cyber criminals accountable.
  • Acknowledges progress made but urges more attention towards establishing shared detection mechanisms.

The Global Challenge of Cybercrime

Collaborative International Coalition

  • Highlights the need for an international coalition to tackle global cybercrime effectively, recognizing it as a significant issue affecting all nations.

Existing Channels for Law Enforcement Collaboration

  • Questions the effectiveness of current national law enforcement structures in pursuing cybercriminals, despite organizations like Interpol being available.
  • Calls for exploration of existing regional channels that can unite law enforcement, private industry, and academia to combat cyber threats.

National Engagement in International Collaboration

Minimum Requirements for Countries

  • Discusses how national policies define engagement in international collaboration against cybercrime.
  • Mentions Interpol and Europol as key channels for information exchange regarding cybercrime activities.

Initiatives Supporting Private Sector Involvement

  • Describes initiatives like the Global Forum on Counterterrorism that bring together industry stakeholders to address online terrorist activities.

Challenges in Information Exchange

Practical Guides and Resources

  • Introduces a joint publication by UNODC aimed at helping member states request electronic evidence from internet service providers across jurisdictions.

Effectiveness of Current Efforts

  • Acknowledges ongoing efforts in incident response team collaborations but stresses that more work is needed to enhance these partnerships.

Disparities in Cybersecurity Regulations

Privacy Issues Across Regions

  • Points out disparities between regions such as Europe’s GDPR compared to the United States' lack of similar regulations impacting cybersecurity laws.

Introduction to Martin Koyabi

Role within Commonwealth Telecommunication Organization

  • Martin Koyabi introduces himself and outlines his role focusing on technical support across Commonwealth nations concerning cybersecurity issues.

National Cybersecurity Strategies

Unique Challenges Faced by Commonwealth Countries

  • Discusses challenges faced by Commonwealth countries in implementing effective national cybersecurity strategies due to varying levels of support from governments.

Strategy Implementation Challenges

  • Identifies prioritization as a critical challenge when moving from strategy formulation to implementation.
  • Stresses importance of identifying gaps using models like CMM (Capability Maturity Model).

Funding Issues in Cybersecurity Strategies

Financial Sustainability Concerns

  • Highlights funding challenges often overlooked during strategy formulation stages.
  • Notes emerging trends where donor agencies are collaborating with countries before providing assistance.

Legal and Regulatory Framework Gaps

  • Addresses legal policy challenges that hinder effective cybersecurity implementations across developing nations.

Monitoring and Evaluation Needs

Importance of Effective Monitoring

  • Emphasizes the need for robust monitoring systems alongside financial sustainability measures within national strategies.

Addressing Skills Gap in Cybersecurity

Confidence Levels Among Managers

  • Reports only 34% confidence among managers regarding their teams’ abilities to respond effectively to cyber threats due largely to skill shortages globally.

Role of National CIRTs

  • Explores how national Computer Incident Response Teams (CIRTs), can bridge skills gaps through training programs tailored toward essential knowledge areas required within this field.

Organizational Structures Needed For Effective Implementation

Accountability Within National Strategies

  • Stresses accountability as crucial; strategies should clearly outline responsibilities, resources needed, timelines, and metrics necessary for success.

Workforce Development Initiatives

  • Suggestion that workforce development must align with national policies while ensuring individuals possess relevant skills suited towards evolving technological landscapes such as cloud computing or IoT advancements.

Stakeholder Engagement in National Cybersecurity Strategies

Importance of Recognizing Stakeholders

  • Emphasizes the need to recognize various stakeholders as relevant participants in national cybersecurity strategies.
  • Suggests that metrics for evaluating cybersecurity effectiveness should be based on real evidence rather than tactical measures, akin to measuring cholesterol without understanding its implications.

Merging Old and New Approaches

  • Advocates for a common framework that combines traditional compliance-based metrics with modern data-driven approaches, including artificial intelligence.
  • Highlights the necessity of international collaboration to create secure environments that respect freedom of speech while enhancing government capabilities.

Common Objectives Among Governments

  • Notes that despite different strategies, 95% of objectives across governments are similar, suggesting potential for collaborative efforts on shared goals.
  • Uses an analogy of musicians working together to illustrate the importance of collective effort in achieving cybersecurity objectives.

Challenges in Developing National Cybersecurity Strategies

Initial Stages and Core Factors

  • Discusses how a country's stage in cybersecurity development influences its strategy formulation, emphasizing foundational legal and regulatory frameworks.
  • Points out that priorities must align with available data and risk assessments related to national infrastructure protection.

Bhutan's Cybersecurity Journey

  • Introduces Bhutan's context as a small nation transitioning from least developed status, highlighting significant advancements in ICT adoption over two decades.
  • Describes the establishment of BT CERT (Bhutan Computer Incident Response Team), which began operations following an ITU readiness assessment.

Implementation Challenges and Strategies

Importance of Education and Stakeholder Buy-in

  • Identifies challenges such as educating non-tech-savvy leaders about cybersecurity's significance and securing stakeholder support for comprehensive strategies.
  • Mentions limited local expertise as a barrier to effective strategy implementation due to a shortage of qualified cybersecurity professionals.

Strategic Planning and Budgeting

  • Outlines plans for implementing Bhutan’s National Cybersecurity Strategy (NCS), including forming high-level committees chaired by the Prime Minister.
  • Discusses budget allocation aimed at identifying critical information infrastructure and enhancing public awareness regarding cybersecurity.

Engagement Strategies for Stakeholders

Fostering Collaboration Across Sectors

  • Explores methods for encouraging stakeholder engagement across government, private sector, academia, and civil society within national security frameworks.

Regulatory Approaches to Encourage Compliance

  • Reflecting on past experiences where regulation was avoided; discusses how GDPR introduced accountability through penalties for non-compliance.

Metrics and Accountability in Cybersecurity

The Role of Metrics in Engagement

  • Stresses the importance of good education on individual responsibilities towards cybersecurity practices at all levels—enterprise, government, corporate, and personal.

Establishing Governance Mechanisms

  • Highlights the need for clear governance structures within countries to ensure accountability regarding national cybersecurity strategy implementations.

The Importance of Supply Chain Security in Cybersecurity

Overview of Supply Chain Concerns

  • Discussion on the increasing focus on supply chain security within the cybersecurity community, highlighting its relevance to both critical national infrastructure and businesses.
  • Audience question regarding the significance of integrating national cybersecurity principles related to supply chain controls for developing countries.

Diverse Perspectives on Supply Chain Security

  • Acknowledgment that different countries have varying approaches to supply chain security, indicating a lack of consensus on best practices.
  • Emphasis on understanding vulnerabilities and trusted suppliers as essential components in managing supply chain risks.

Risk Management Strategies

  • Recognition that a comprehensive cybersecurity strategy should not solely depend on supply chain management but also include recovery from cyber threats.
  • Importance of having domestic skills and industrial capabilities to rebuild after cyber incidents, stressing that protocols alone do not eliminate risk.

Balancing Growth and Security

  • Discussion about the trade-offs between encouraging technological growth post-COVID and ensuring robust cybersecurity measures are in place.
  • Noting that while technology has shown resilience during crises, it is crucial to prioritize risk management effectively.

Contingency Planning in Supply Chains

Need for Awareness in Contingency Planning

  • Highlighting gaps in contingency planning related to supply chains, suggesting a need for increased awareness among stakeholders.

Defining Cybersecurity Strategy for ICT

Challenges in ICT Policy Development

  • Transitioning discussion towards information and communication technology (ICT), focusing on how governments can create effective cybersecurity strategies benefiting various sectors.

Global Nature of Technology

  • Stressing that there are no national boundaries when it comes to ICT; global cooperation is necessary due to interconnected markets.

Engaging Multiple Stakeholders

Complexity of International Cooperation

  • Governments must recognize multiple dimensions affecting technology regulation beyond just technical sovereignty, including international standards and collaboration with other nations.

Communication During Cyber Incidents

Improving Crisis Communication

  • Addressing the importance of effective communication during cyber crises involving various stakeholders such as operators, civil society, and government agencies.

Coordination Among Stakeholders

  • Discusses challenges faced by organizations like CERT UK in managing crisis communications effectively across public-private sectors.

Monitoring National Cybersecurity Strategies

Challenges Faced by Governments

  • Identifying obstacles preventing effective monitoring and evaluation within national cybersecurity strategies, particularly concerning reliable information sharing among industries.

Information Sharing Mechanisms

  • The role of industry-specific information sharing centers is highlighted as beneficial for improving collaboration between private sectors and government entities.

Recommendations for Developing Countries

Building Effective Cyber Ecosystems

  • Urging developing countries to consider governance structures early when establishing new IT infrastructures or smart cities to avoid future gaps in their cybersecurity frameworks.

Enhancing Law Enforcement Collaboration with CSIRTs

Importance of Information Sharing

  • Emphasizing the necessity for incident response teams (CSIRTs), law enforcement agencies, and other bodies to share information effectively during cyber incidents.

Legal Considerations

  • Discusses how legal frameworks impact evidence sharing between nations while addressing concerns over data protection regulations like GDPR.

Trust Between Organizations

  • Concludes with the assertion that trust is fundamental for successful cooperation between law enforcement agencies and CSIRTs in combating cybercrime effectively.

Contact Information and Networking Opportunities

Introduction to Panelists' Contact Details

  • Chris mentions his email (chris@first.org) but acknowledges the complexity of the information shared.
  • Agvile shares that she is active on LinkedIn and will be moving to New York, offering her contact through permanent missions for capacity building assistance related to counterterrorism.

Engagement with Participants

  • Pratima expresses humility about her presence and offers her LinkedIn profile and email for further connections, despite a typo in her email.
  • Martin indicates he is also active on LinkedIn, plans to share his email in the chat, and discusses his work within the Commonwealth and ITU.

Closing Remarks from Panelists

Final Thoughts on Collaboration

  • Nick wraps up by sharing his Twitter handle (@Nick A E S P), LinkedIn profile (Nick Espinosa), and encourages participants to reach out via email.

Appreciation for Participation

  • Nick thanks the ITU for organizing the discussion on national cybersecurity strategy, emphasizing its global importance.
  • He concludes by expressing gratitude towards all participants and wishing everyone a great day.
Video description

The International Telecommunication Union (ITU) organized an online discussion on the lifecycle development and implementation of a National Cybersecurity Strategy. Cybersecurity experts with different backgrounds and from different sectors shared their experiences and knowledge on the importance of national cybersecurity strategy related actions to build greater cybersecurity resilience and readiness. Additionally, they also elaborated the approaches and opportunities for better collaboration amongst different national and international stakeholders. Further building on continued international cooperation and knowledge sharing in the cybersecurity domain is especially important in the current COVID-19 crisis.​