infrastructure. Reports are to be sent to CERT.GOV.GE, which also receives and responds
to voluntary reports and requests for assistance from public and private sector
organisations not designated as critical. CERT gained a high professional reputation and
trust from public and private stakeholders and it is the primary guardian of Georgian
cyberspace from different types of cyber threats, incidents and attacks. Within the scope
of its authority, CERT.GOV.GE performs preventive and protective measures, it is not
involved in offensive and disruptive activities. CERT.GOV.GE never uses its powers
against other nations’ CERT/CSIRT community or critical information infrastructures;
6) Responsible disclosure on threats and incidents to authorized state agencies
(CERT/CSIRT, law-enforcement) is a key area of current work and future development
for Georgian Government. CERT.GOV.GE monitors the cyberspace of Georgia and shares
information about incidents and threats with the relevant stakeholders. Additionally, it
has a central repository for incident-monitoring, which includes information from
international threat-intelligence data providers as well as public reporting.
CERT.GOV.GE also has an information feed available for both public and private
organizations, based on which all the relevant stakeholders are duly notified of emerging
threats. Georgia puts a lot of emphasis on stimulating responsible disclosure from the side
of the private sector, creating cyber threats and incident sharing platforms and elaborating
relevant procedures and rules for reporting or responding to national-level incidents not
only in critical infrastructures or government, but also within nation-wide scope. Formal
national incident coordinating architecture will be elaborated and consolidated list of
national level incidents will be created that can be used to identify trends and common
causal themes;
7) The cyber-ecosystem in Georgia has already gained a good speed of evolvement across
government, the private sector, and also in the information society, in general. ICT
security awareness and capacity-building, identification and engagement of young talents,
building-up cyber education in each and every academic stage are the top strategic
priorities for the country. After a comprehensive and systematic awareness raising
campaigns initiated by the government in the last couple of years, there are clear signs
that the general public begins to develop a more detailed cybersecurity mind-set, gains in
awareness appear within different target groups across Georgia (pupils, teachers,
municipal civil servants, media representatives, civil servants, SMSs, etc.,). There is an
increasing trend in the concerns of surveyed population about the security or privacy
aspect of using Internet services. Cybersecurity awareness and cyber-consciousness are
mostly present in the mind-set of employees in the government sector. In the coming
years Georgia will put more and more resources and efforts in developing cyber security
human capital within its information society;
8) Cyber- and information security professionals in Georgia form a close-knit and
collaborative public-private community that runs on common values, trust and respect.
Multi-stakeholderism is the key guiding principle for resolving cybersecurity challenges
3