Introduction The cyber threat is a constant concern for Danish public authorities and private companies. In short, it is a matter of when, not if an organization falls victim to a cyberattack. ”Effective cyber defence” is a guide that contains six steps that organizations can take to establish basic cyber defences. By following these steps, organizations can prevent many of the cyberattacks they encounter on a daily basis, and effectively mitigate successful attacks. 6 steps for an effective cyber defence 1) The management’s toolbox 2) Helpful technical measures 3) Conduct is key 4) Detect your enemy 5) Be prepared! 6) Find the gaps in your cyber defence Cyber security vigilance at the executive level is the cornerstone of an effective cyber defence. The top management has to govern cyber and information security by continuously supporting, prioritizing and following up on security objectives and strategies with the same vigilance, as applied to other business matters, for example financial and HR matters. An effective cyber defence is not a project, but rather a continuous process that requires constant evaluation and optimization. This applies to all six steps in this guide. Consequently, the top management has to ensure continuous follow-ups and improvement. We recommend that Danish organizations use international standards and best practices as a starting point. In Denmark, the following cyber security frameworks are often used: ISO 27001, NIST Cybersecurity Framework, SANS and CIS 20. Compliance with standards and best practices creates a foundation for establishing set and repeatable processes that improve cyber and information security within organizations. Target audience ”Effective cyber defence” is intended for all public authorities and private companies with complex IT systems, and may also be useful to anyone interested in good cyber and information security practices. This guide is directed primarily to top management and cyber and information security staff. Public authorities and private companies may be obligated to comply with specific cyber and information security requirements. Such requirements may entail following a particular standard, for example ISO 27001, or implementing specific technical measures such as ”The technical minimum requirements for government authorities”. ”Effective cyber defence” does not replace such requirements and this guide should be read in the context of these requirements. 3

Select target paragraph3