1 INTRODUCTION
1 Introduction
1.1 Challenges
Technology will give rise to far-reaching changes over
the coming years. Robotisation, sensor technology, 3D
printing, big data and artificial intelligence are all examples
of technological advances that are likely to change society.
We will have access to digital services we can barely
imagine – services that will be available 24/7, wherever we
may be. Our everyday life will become increasingly digital,
primarily to the benefit of private individuals, companies
and the authorities.
The digitalisation carries with it a range of challenges.
Our society is becoming increasingly vulnerable to cyber
threats, and thorough understanding of society’s digital
dependencies is becoming ever-more important. Digital
infrastructures and systems are growing more complex,
global and integrated. All kinds of devices are being
connected to the internet and use of cloud solutions is on
the rise. The need to reduce costs and increase access to
competence is resulting in more and more digital services
being outsourced to third parties, particularly in lowcost countries. Compound (hybrid) threats are blurring
the traditional dividing line between peace and armed
conflict, and challenging the conventional placement of
responsibility between the civilian and military sectors.
The sheer speed of technological evolution makes it
extremely difficult to forecast which threats will come to
dominate the threat landscape of the future. Regardless, it
is likely that specific types of threats such as ransomware,
industrial espionage, sabotage, blackmail, cyber-bullying
and identity theft will remain prominent over the coming
years. These are threats that can be targeted at private
individuals and companies alike, with severe consequences
for those affected.
The Norwegian National Security Authority (NSM)
publishes an annual report entitled the “Comprehensive
Cyber Security Risk Assessment” (Helhetlig IKT-risikobilde).
The report is built on a comprehensive portfolio of risk
and vulnerability reports from authorities, the business
community, academia and other stakeholders. The
assessment for 2018 suggests that the digitalisation of
society is changing the value of both new and existing
digital solutions. Every time services are digitalised or
automated, the level of digital dependency in society
increases. When services are made available on digital
platforms, the associated values are exposed to threat
6 | National Cyber Security Strategy for Norway
agents operating in the domain. This naturally generates
new security challenges and alters the threat landscape.
The threat landscape is characterised by the continuation
of trends from previous years, combined with a
reinforcement of some developments. Foreign intelligence
activity targeted at public and private companies, along
with cyber crime, constitute the predominant cyber threats
to Norwegian society in 2018.
1.2 Strategy
The Norwegian Ministry of Justice and Public Security is
responsible for coordinating public security in the civilian
sector. The Ministry holds a special responsibility for
national cyber security in the civilian sector, and will outline
the Government’s policy for cyber security, including
national cyber security requirements and recommendations
for public and private companies.1 The Norwegian Ministry
of Defence holds responsibility for cyber security in the
defence sector. In order to address these responsibilities,
the authorities have access to a broad range of tools:
development of regulations and knowledge, supervisory
activities as well as counselling and guidance.
However, the authorities will not be able to solve all
challenges in cyberspace by themselves. Critical societal
functions and other Norwegian interests are dependent
on digital infrastructures that continue to increase in both
scope and complexity. Long and less transparent digital
value chains, which span multiple sectors and borders, are
a core challenge in assessing digital vulnerability.
The cyber security challenges must therefore be
resolved by placing a strong emphasis on collaboration
and partnerships among relevant stakeholders at both
national and international level. Challenges need to be
addressed through joint input and across traditional
sectoral boundaries, such that the security needs of all
stakeholders are appropriately accommodated. Particular
emphasis must be put on cooperations and partnerships
within the prioritised areas of the strategy. These are
described in detail in Chapter 3.
1 Cyber security has to do with protecting “everything” that is vulnerable
because it is connected to or otherwise dependent on information and
communication technology. The term is used synonymously with the terms
“ICT security” and “digital security”.