1 INTRODUCTION 1 Introduction 1.1 Challenges Technology will give rise to far-reaching changes over the coming years. Robotisation, sensor technology, 3D printing, big data and artificial intelligence are all examples of technological advances that are likely to change society. We will have access to digital services we can barely imagine – services that will be available 24/7, wherever we may be. Our everyday life will become increasingly digital, primarily to the benefit of private individuals, companies and the authorities. The digitalisation carries with it a range of challenges. Our society is becoming increasingly vulnerable to cyber threats, and thorough understanding of society’s digital dependencies is becoming ever-more important. Digital infrastructures and systems are growing more complex, global and integrated. All kinds of devices are being connected to the internet and use of cloud solutions is on the rise. The need to reduce costs and increase access to competence is resulting in more and more digital services being outsourced to third parties, particularly in lowcost countries. Compound (hybrid) threats are blurring the traditional dividing line between peace and armed conflict, and challenging the conventional placement of responsibility between the civilian and military sectors. The sheer speed of technological evolution makes it extremely difficult to forecast which threats will come to dominate the threat landscape of the future. Regardless, it is likely that specific types of threats such as ransomware, industrial espionage, sabotage, blackmail, cyber-bullying and identity theft will remain prominent over the coming years. These are threats that can be targeted at private individuals and companies alike, with severe consequences for those affected. The Norwegian National Security Authority (NSM) publishes an annual report entitled the “Comprehensive Cyber Security Risk Assessment” (Helhetlig IKT-risikobilde). The report is built on a comprehensive portfolio of risk and vulnerability reports from authorities, the business community, academia and other stakeholders. The assessment for 2018 suggests that the digitalisation of society is changing the value of both new and existing digital solutions. Every time services are digitalised or automated, the level of digital dependency in society increases. When services are made available on digital platforms, the associated values are exposed to threat 6 | National Cyber Security Strategy for Norway agents operating in the domain. This naturally generates new security challenges and alters the threat landscape. The threat landscape is characterised by the continuation of trends from previous years, combined with a reinforcement of some developments. Foreign intelligence activity targeted at public and private companies, along with cyber crime, constitute the predominant cyber threats to Norwegian society in 2018. 1.2 Strategy The Norwegian Ministry of Justice and Public Security is responsible for coordinating public security in the civilian sector. The Ministry holds a special responsibility for national cyber security in the civilian sector, and will outline the Government’s policy for cyber security, including national cyber security requirements and recommendations for public and private companies.1 The Norwegian Ministry of Defence holds responsibility for cyber security in the defence sector. In order to address these responsibilities, the authorities have access to a broad range of tools: development of regulations and knowledge, supervisory activities as well as counselling and guidance. However, the authorities will not be able to solve all challenges in cyberspace by themselves. Critical societal functions and other Norwegian interests are dependent on digital infrastructures that continue to increase in both scope and complexity. Long and less transparent digital value chains, which span multiple sectors and borders, are a core challenge in assessing digital vulnerability. The cyber security challenges must therefore be resolved by placing a strong emphasis on collaboration and partnerships among relevant stakeholders at both national and international level. Challenges need to be addressed through joint input and across traditional sectoral boundaries, such that the security needs of all stakeholders are appropriately accommodated. Particular emphasis must be put on cooperations and partnerships within the prioritised areas of the strategy. These are described in detail in Chapter 3. 1 Cyber security has to do with protecting “everything” that is vulnerable because it is connected to or otherwise dependent on information and communication technology. The term is used synonymously with the terms “ICT security” and “digital security”.

Select target paragraph3