Stakeholders and structures
Initial situation
A country’s specific approach to cyber
security is linked very closely to its existing
stakeholders and structures. The term
“cyber security” refers to organisations,
institutions or persons with a vested interest
in cyber security, or particularly severely
affected by it.
An insight into the present quality of
cyber security in Austria was obtained by
examining a total of 200 stakeholders and
structures and analysing the 80 currently
most important ones.
By sectors. Actions related to cyber
security in Austria focus on the public
sector, notably institutions at federal level
and publicly financed institutions. The
public administration set up specialised
institutions with different responsibilities
and target groups in several ministries.
These institutions have been optimised for
their respective sphere of activity and make
a substantial contribution to cyber security
in Austria.
The Länder (federal provinces), cities
and municipalities operate on a smaller
scale, and have only very few overarching
structures. The private sector usually has
good cyber structures at corporate level.
The larger the enterprise, the greater
the possibilities to take preventive and
protective measures. Private-sector cyber
security interest representations are only
now emerging on a broader basis. There
are only very few interest representations
exclusively geared towards the needs of the
citizens, who must resort to the institutions
of the public administration.
By areas of activity. Stakeholders and
structures acting on a trans-sectoral basis
are distributed quite evenly over the
following areas of activity: sensitisation,
research, prevention, emergency and
crisis management. The highly specialised
areas of public information services and
criminal prosecution fall exclusively within
the purview of the ministries responsible.
6
However, education sector takes only very
little action in the field of cyber security;
there are hardly any stakeholders offering
cyber security programmes. However,
this would be of vital importance for the
qualitative (further) development of human
resources familiar with cyber security
issues—both in enterprises and public
authorities. The education sector has huge a
potential for the future.
By level of customer orientation. The
government and business sectors receive
an almost equal level of support as the
clients of Austrian stakeholders. It must
be emphasised that there are only very few
citizens’ interest representations (lacking
visibility). Another striking fact is that
cyber stakeholders show little customer
orientation towards the citizens.
Cyberspace is an area in which many
Austrian structures and stakeholders are
active separately and highly independently.
Several trans-sectoral organisations
exclusively specialised in cyber security
are already playing an important role in
Austria, e.g. the well-established CERTs
(Computer Emergency Response Teams).
However, processes suitable for the
control of cyber incidents are implemented
predominantly at local level. Overarching
cyber security procedures have not been
harmonised or defined in detail. While other
areas benefit from institutionalised and
process-controlled mechanisms to tackle
incidents, cyber incident management in
Austria relies predominantly on a personal
network of contacts.
It is remarkable that two essential
elements are either lacking completely or
are insufficiently developed in the Austrian
structures:
•• a central Situation Centre for Austria;
the responsibilities of such a centre are
currently exercised by CERTs;
•• the sector of public administration
affected by cyber security; this includes
public stakeholders, their specialised
institutions and above all processes of
cooperation in the framework of a