held on 15 January 2015, was attended by about 60 people. The views voiced at these meetings were
taken into consideration in drawing up the strategy.
Connection with other strategies and parliamentary resolutions
Direct and indirect links exist between the strategy on cyber security and many other official
strategies and resolutions, e.g. the national strategy on civil protection and public security, law
enforcement, telecommunications, the planned strategy on national security and the
Icelandic State and Municipal Policy on the Information Society 2013-2016: “e-Power Expansion: create, connect, participate“
Strategy and action in Iceland: Taking the initiative on security
The threats and challenges outlined above call for responses. As a whole, the situation presents an
important opportunity to forge ahead and make Iceland’s IT environment more secure and more
competitive in the international context. Generally, prioritising security straight away at the initial
planning stage means that expensive situations can be avoided later on. Integrating security
considerations in the initial plan makes it possible to design reliable computer systems, just as sound
foundations make it possible to build a skyscraper: without them, the project remains a ‘castle in the
air’. Priority must be given to security by design and privacy by design, i.e. the inclusion of security
and privacy considerations from the outset in the design process. Cyber security must form a part of
computer-related studies at all levels of the educational system. Moreover, such studies at university
level must be upgraded, with closer collaboration with universities abroad to enable students
graduating from Icelandic universities to undertake postgraduate studies in cyber security.
It is likely that ever more stringent security requirements will be made on the market for software
and software-related services. Many states intend to make use of this opportunity to create for
themselves a competitive advantage over others and offer an IT environment supporting the needs
of commerce, industry and private individuals. This could involve both a more secure environment
for e-commerce and also being in the forefront of cyber security and making it into a valuable export
product. Defence against industrial espionage is also an important aspect of this, since such
espionage constitutes a large part of the economic damage caused by cyber security threats.
Consultancies are starting to use nations’ cyber security status as a factor in their advice on choice of
location for enterprises which intend to set up data centres or other computer-related services.
The legal environment in Iceland must also support software-related development and provide
protection against cybercrime in order to deter criminal organisations from seeing the country as a
suitable venue for their activities because of low level of cyber security. At any given time, steps must
be taken to evaluate how Iceland’s legislation stands in comparison with that of the other Nordic
countries. Furthermore, the police must have the powers to enforce this legislation. Particular
attention must be given to the protection of personal data: technical developments and standards
can change very rapidly and it is important that the level of protection in Iceland is not lower than in
other Nordic countries.
Considerable results can also be achieved through simple awareness-raising. By employing relatively
simple precautionary measures, it is believed that hazards both to private individuals and enterprises
can be reduced significantly. A great deal is at stake when it comes to combating cybercrime.
Defences must be raised around important elements in the infrastructure in Iceland. This is a manyfaceted task. It is important to have a high-capacity cyber security team capable of analysing and
evaluating cyber-attacks of various types and providing assistance in the case of attacks.
5