Part Three The Strategy national and EU research projects and initiatives on cyber security. Essentially, it entails participation not only from Government but also from the private sector and the academia. • Ingraining a culture of cyber security awareness on the potential misuse, vulnerabilities and risks potentially arising from the ICTs and concepts applied (particularly those emerging); whilst embracing the opportunities arising from their use v. A Strategic, target-oriented national awareness and advice campaign • Imparting the key message that it is ultimately in everyone’s interest and responsibility to take the necessary relevant cyber security safeguards; keeping in view of the inherent interconnectedness of individuals and organisations alike in cyber-space. It is highly recommended that a concerted, ongoing strategic approach is undertaken, potentially through a nationwide Communications strategy for cyber security53; aimed at addressing the various strata of society, business and public sector along with their corresponding needs, expectations, and potential ICTs and concepts applied54. Most measures highlighted within Goals 4 and 5 of this strategy as well as any established national way of sharing related knowledge, experience and insight as referred to in Measure 3 (i)56 may potentially serve as key sources for the establishment and maintenance of such a concerted strategic campaign. Such an approach may ensure: • Avoiding piecemeal, potentially approaches to awareness campaigns one-off • No duplication of effort • Maximisation of cyber security related financial and human resources vi. Encourage ‘cyber hygiene’ and personal responsibility • Identification and engagement of all potential sources of dissemination of the awareness campaigns Ultimately, citizens are expected to apply at least some form of basic ‘cyber hygiene’ in using ICT, such as through careful disposition and use of personal information on-line, installing software updates and anti-virus software, using basic security controls such as strong passwords and, as much as possible, seeking to be more wary of any suspicious activity related to their personal on-line accounts. The national awareness campaign, as highlighted in Measure 5 (v), should help in reaching this objective. • Imparting effective awareness and knowledge on cyber security patterns and measures that is commensurate to the specific target audience and to the medium used55 • A measure of the extent of national awareness and understanding of cyber security over time • That cyber security is not simply a concern of ICT professionals. Furthermore, the possibility of a national responsible disclosure policy framework that enables wellintentioned system users to safely inform Government, businesses or institutions about detected vulnerabilities in their ICT systems or services may also be explored. The framework would need to establish the right parameters and conditions so as to ensure its effectiveness57. Ultimately, the key factors that need to be borne in mind in the establishment of such campaign is: • Finding the right way to raise awareness, keeping in view of the target audience • Ensuring motivation to learn and pay particular attention to various signals of fake communications on a day to day basis (particularly to counter social engineering threats) 26 MALTA CYBER SECURITY STRATEGY 2016

Select target paragraph3