Cybersecurity guide for developing countries This is a major security risk. States must beware of becoming dependent for the strategic, tactical and operational management of their security on external entities that are beyond their control. Governments have a role to play in imposing the following: – build in security capability (security by default) that is user friendly, intuitive, transparent and verifiable; – keep individuals and organizations from putting themselves into dangerous situations (avoid lax configuration, risky behaviour, over-dependence, etc.); – compliance with security standards; – mitigation of vulnerabilities in technologies and security solutions. I.2.7 The economic dimension The point of security is not to make money, but to avoid losing it. While it may appear relatively straightforward to estimate what security costs (associated budgets, cost of security products, training, etc.), assessing the profitability of security is more difficult. Taking a subjective approach, one might suppose that security measures intrinsically possess a “passive” form of effectiveness that prevents certain potential losses. Nonetheless, it is difficult to weigh the cost of security and the costs associated with losses due to accidents, errors or malicious acts. The cost of security is a function of the needs of the organization, and depends on the assets to be protected and the cost of damage resulting from insufficient security. There is thus no ready answer to the following questions: – How can the organization’s risk exposure be evaluated, especially the serial risks that are due to the interconnection of infrastructures between organizations? – How can the indirect costs of a lack of security be estimated, such as those associated with damage to image or espionage? – What can security yield for the organization that implements it? – What is the economic value of security? – What is the return on investment of security? The economic value of security must be conceived in the broadest social sense, taking into account the impact of new technologies on individuals, organizations and nations. It cannot be reduced to the costs of installation and maintenance. I.2.8 The social dimension It is important to make all participants in the internet aware of the importance of getting security right, and what the basic steps are that will strengthen the level of security if they are clearly formulated, defined and implemented intelligently. Information campaigns and civic education for a responsible information society, covering the challenges, the risks and the preventive and deterrent security measures, are needed in order to educate all cybercitizens to buy into the security process. The emphasis should be on the duty of security, individual responsibility and deterrent measures, as well as the potential implications under criminal law of a failure to respect security obligations. More generally, it is also necessary to provide education and training in information and communication technologies, and not merely security and deterrent measures. The awareness of security issues should not be limited to the promotion of a certain security culture. The security culture must be embedded 16 Cybersecurity

Select target paragraph3