Stakeholders and structures Initial situation A country’s specific approach to cyber security is linked very closely to its existing stakeholders and structures. The term “cyber security” refers to organisations, institutions or persons with a vested interest in cyber security, or particularly severely affected by it. An insight into the present quality of cyber security in Austria was obtained by examining a total of 200 stakeholders and structures and analysing the 80 currently most important ones. By sectors. Actions related to cyber security in Austria focus on the public sector, notably institutions at federal level and publicly financed institutions. The public administration set up specialised institutions with different responsibilities and target groups in several ministries. These institutions have been optimised for their respective sphere of activity and make a substantial contribution to cyber security in Austria. The Länder (federal provinces), cities and municipalities operate on a smaller scale, and have only very few overarching structures. The private sector usually has good cyber structures at corporate level. The larger the enterprise, the greater the possibilities to take preventive and protective measures. Private-sector cyber security interest representations are only now emerging on a broader basis. There are only very few interest representations exclusively geared towards the needs of the citizens, who must resort to the institutions of the public administration. By areas of activity. Stakeholders and structures acting on a trans-sectoral basis are distributed quite evenly over the following areas of activity: sensitisation, research, prevention, emergency and crisis management. The highly specialised areas of public information services and criminal prosecution fall exclusively within the purview of the ministries responsible. 6 However, education sector takes only very little action in the field of cyber security; there are hardly any stakeholders offering cyber security programmes. However, this would be of vital importance for the qualitative (further) development of human resources familiar with cyber security issues—both in enterprises and public authorities. The education sector has huge a potential for the future. By level of customer orientation. The government and business sectors receive an almost equal level of support as the clients of Austrian stakeholders. It must be emphasised that there are only very few citizens’ interest representations (lacking visibility). Another striking fact is that cyber stakeholders show little customer orientation towards the citizens. Cyberspace is an area in which many Austrian structures and stakeholders are active separately and highly independently. Several trans-sectoral organisations exclusively specialised in cyber security are already playing an important role in Austria, e.g. the well-established CERTs (Computer Emergency Response Teams). However, processes suitable for the control of cyber incidents are implemented predominantly at local level. Overarching cyber security procedures have not been harmonised or defined in detail. While other areas benefit from institutionalised and process-controlled mechanisms to tackle incidents, cyber incident management in Austria relies predominantly on a personal network of contacts. It is remarkable that two essential elements are either lacking completely or are insufficiently developed in the Austrian structures: •• a central Situation Centre for Austria; the responsibilities of such a centre are currently exercised by CERTs; •• the sector of public administration affected by cyber security; this includes public stakeholders, their specialised institutions and above all processes of cooperation in the framework of a

Select target paragraph3