held on 15 January 2015, was attended by about 60 people. The views voiced at these meetings were taken into consideration in drawing up the strategy. Connection with other strategies and parliamentary resolutions Direct and indirect links exist between the strategy on cyber security and many other official strategies and resolutions, e.g. the national strategy on civil protection and public security, law enforcement, telecommunications, the planned strategy on national security and the Icelandic State and Municipal Policy on the Information Society 2013-2016: “e-Power Expansion: create, connect, participate“ Strategy and action in Iceland: Taking the initiative on security The threats and challenges outlined above call for responses. As a whole, the situation presents an important opportunity to forge ahead and make Iceland’s IT environment more secure and more competitive in the international context. Generally, prioritising security straight away at the initial planning stage means that expensive situations can be avoided later on. Integrating security considerations in the initial plan makes it possible to design reliable computer systems, just as sound foundations make it possible to build a skyscraper: without them, the project remains a ‘castle in the air’. Priority must be given to security by design and privacy by design, i.e. the inclusion of security and privacy considerations from the outset in the design process. Cyber security must form a part of computer-related studies at all levels of the educational system. Moreover, such studies at university level must be upgraded, with closer collaboration with universities abroad to enable students graduating from Icelandic universities to undertake postgraduate studies in cyber security. It is likely that ever more stringent security requirements will be made on the market for software and software-related services. Many states intend to make use of this opportunity to create for themselves a competitive advantage over others and offer an IT environment supporting the needs of commerce, industry and private individuals. This could involve both a more secure environment for e-commerce and also being in the forefront of cyber security and making it into a valuable export product. Defence against industrial espionage is also an important aspect of this, since such espionage constitutes a large part of the economic damage caused by cyber security threats. Consultancies are starting to use nations’ cyber security status as a factor in their advice on choice of location for enterprises which intend to set up data centres or other computer-related services. The legal environment in Iceland must also support software-related development and provide protection against cybercrime in order to deter criminal organisations from seeing the country as a suitable venue for their activities because of low level of cyber security. At any given time, steps must be taken to evaluate how Iceland’s legislation stands in comparison with that of the other Nordic countries. Furthermore, the police must have the powers to enforce this legislation. Particular attention must be given to the protection of personal data: technical developments and standards can change very rapidly and it is important that the level of protection in Iceland is not lower than in other Nordic countries. Considerable results can also be achieved through simple awareness-raising. By employing relatively simple precautionary measures, it is believed that hazards both to private individuals and enterprises can be reduced significantly. A great deal is at stake when it comes to combating cybercrime. Defences must be raised around important elements in the infrastructure in Iceland. This is a manyfaceted task. It is important to have a high-capacity cyber security team capable of analysing and evaluating cyber-attacks of various types and providing assistance in the case of attacks. 5

Select target paragraph3