NATIONAL CYBER SECURITY STRATEGY GREEN PAPER 4 PROPOSED STRATEGY • Maximisation of cyber security related financial and human resources • Imparting effective awareness and knowledge that is commensurate to the target audience and to the medium used19 • A measure of the extent of national awareness and understanding of cyber security over time. Most measures highlighted within Goals 4 and 5 of this strategy as well as any established national way of sharing related knowledge, experience and insight as referred to in Measure 3.12O may potentially serve as key sources for the establishment and maintenance of such a concerted strategic campaign. Ultimately, the key factor in any training and awareness programmes on cyber security is: • Finding the right way to raise awareness • Establishing training programmes that effectively increase security level of an organisation and maintaining such increased level of security in the long term • Ensuring motivation of users to learn and pay particular attention to various signals of fake communications on a day to day basis (particularly to counter social engineering threats). Prior and post assessment of such programmes is one way of ensuring their effectiveness. However, consideration should also be taken that such programmes may not necessarily focus only on traditional modes of education and awareness but also on experimentation of innovative ways of their conduct21. 5.5 ENCOURAGE ‘CYBER HYGIENE’ AND PERSONAL RESPONSIBILITY Ultimately, citizens are expected to apply at least some form of basic ‘cyber hygiene’ in using ICT, such as through careful disposition and use of personal information on-line, installing software updates, using basic security controls such as passwords and anti-virus software. The national awareness campaign as highlighted earlier should help in reaching this objective. In particular, a responsible disclosure policy that enables well-intentioned citizens to safely inform Government, businesses or institutions about detected vulnerabilities in their ICT systems or services may also be considered22. 24 MALTA | NATIONAL CYBER SECURITY STRATEGY GREEN PAPER

Select target paragraph3