infrastructure. Reports are to be sent to CERT.GOV.GE, which also receives and responds to voluntary reports and requests for assistance from public and private sector organisations not designated as critical. CERT gained a high professional reputation and trust from public and private stakeholders and it is the primary guardian of Georgian cyberspace from different types of cyber threats, incidents and attacks. Within the scope of its authority, CERT.GOV.GE performs preventive and protective measures, it is not involved in offensive and disruptive activities. CERT.GOV.GE never uses its powers against other nations’ CERT/CSIRT community or critical information infrastructures; 6) Responsible disclosure on threats and incidents to authorized state agencies (CERT/CSIRT, law-enforcement) is a key area of current work and future development for Georgian Government. CERT.GOV.GE monitors the cyberspace of Georgia and shares information about incidents and threats with the relevant stakeholders. Additionally, it has a central repository for incident-monitoring, which includes information from international threat-intelligence data providers as well as public reporting. CERT.GOV.GE also has an information feed available for both public and private organizations, based on which all the relevant stakeholders are duly notified of emerging threats. Georgia puts a lot of emphasis on stimulating responsible disclosure from the side of the private sector, creating cyber threats and incident sharing platforms and elaborating relevant procedures and rules for reporting or responding to national-level incidents not only in critical infrastructures or government, but also within nation-wide scope. Formal national incident coordinating architecture will be elaborated and consolidated list of national level incidents will be created that can be used to identify trends and common causal themes; 7) The cyber-ecosystem in Georgia has already gained a good speed of evolvement across government, the private sector, and also in the information society, in general. ICT security awareness and capacity-building, identification and engagement of young talents, building-up cyber education in each and every academic stage are the top strategic priorities for the country. After a comprehensive and systematic awareness raising campaigns initiated by the government in the last couple of years, there are clear signs that the general public begins to develop a more detailed cybersecurity mind-set, gains in awareness appear within different target groups across Georgia (pupils, teachers, municipal civil servants, media representatives, civil servants, SMSs, etc.,). There is an increasing trend in the concerns of surveyed population about the security or privacy aspect of using Internet services. Cybersecurity awareness and cyber-consciousness are mostly present in the mind-set of employees in the government sector. In the coming years Georgia will put more and more resources and efforts in developing cyber security human capital within its information society; 8) Cyber- and information security professionals in Georgia form a close-knit and collaborative public-private community that runs on common values, trust and respect. Multi-stakeholderism is the key guiding principle for resolving cybersecurity challenges 3

Select target paragraph3