GOAL ONE: Cyber Resilience NEW ZEALAND’S INFORMATION INFRASTRUCTURES CAN RESIST CYBER THREATS AND WE HAVE THE CYBER TOOLS TO PROTECT OUR NATIONAL INTERESTS Cyber Resilience involves detection, protection and recovery from cyber incidents. Government agencies and businesses need to have timely, actionable cyber security information and advice and be able to deal with a trusted agency when they have a cyber security incident. It is proposed that a national CERT1 be established. This institution would act as a central reporting mechanism for the full range of cyber incidents, triaging incident response to the relevant separate organisation and ensuring technical advice gets to the organisations that need it – in real-time. A national CERT would bring together representatives and functions from a range of government agencies, non-government organisations and the private sector that currently deal with cyber incidents. It would be an internationally recognised point of contact – an important factor given the extent to which cyber incidents are perpetrated from off-shore and the need for international cooperation to manage these incidents. The CERT would incorporate a threat analysis and information sharing platform. This would improve understanding of the likelihood and impact of cyber risks facing the country. The platform would examine existing threat patterns and techniques (i.e. the signatures or cyber “fingerprints” of malicious actors), and look out for brand new threats, including those arising from technological innovations. Information about cyber threats can come from a variety of sources: classified intelligence, other national CERTs, the private sector, multinational ICT companies, non-government organisations and individuals. The government should review regularly those government and private sector information infrastructure systems that are most vulnerable to threats and, if compromised, would have the most consequence for New Zealand’s national interests. This ensures that New Zealand’s most significant assets are protected. Project CORTEX counters foreign-sourced, technically sophisticated or persistent cyber threats against a limited number of government and consenting private sector organisations of national significance. The detection and disruption capabilities are operated by the National Cyber Security Centre within the Government Communications Security Bureau (GCSB). As a matter of national security, the government must ensure that the New Zealand Defence Force’s (NZDF) networked information systems, including for command and control, logistics and operation of major platforms, are adequately protected, particularly in offshore situations. New Zealand’s intelligence agencies may also use cyber tools to gather intelligence and information for the protection of New Zealand’s interests. Regular cyber security exercises involving public, private and international partners, are necessary to ensure preparedness for major cyber incidents. This will test the effectiveness of the national Cyber Security Emergency Response Plan, involving a detailed escalation process, and seamless coordination of technical, law enforcement, policy, communications and private sector responses. CERT was once an acronym for ‘computer emergency response team’. Since 1997, CERT has been a registered trademark owned by Carnegie Mellon University and is no longer used as an acronym. New Zealand is requesting permission to use the CERT trademark. 1 New Zealand’s Cyber Security Strategy Action Plan 2015 3

Select target paragraph3