GOAL TWO: Cyber Capability NEW ZEALANDERS, BUSINESSES AND GOVERNMENT AGENCIES UNDERSTAND CYBER THREATS AND HAVE THE CAPABILITY TO PROTECT THEMSELVES ONLINE The Cyber Capability goal goes beyond promoting awareness, to focus on building cyber security capability among individuals, businesses, government agencies and organisations. Achieving this goal means that New Zealanders at all levels will have the skills and tools to protect themselves online, making it harder for malicious cyber actors to steal private data, identity information or cause damage to information systems. Connect Smart is an on-going cyber security awareness and capability campaign. The aim is to spread the cyber security message as broadly as possible, including using Connect Smart public and private partners to build the cyber security skills of their staff, customers and supply chains. Connect Smart partners are cyber security champions working collectively to improve New Zealand’s cyber security. Small and medium enterprises (SMEs) play a huge role in New Zealand’s economic growth; it is important that they are equipped to protect their business information. Targeted and accessible cyber security advice will be made available for SMEs through the Connect Smart website and activities, including an online questionnaire to complement the “SME Cyber Security Toolkit”. A new “cyber credentials” scheme is proposed for SMEs. The scheme will promote to the SME audience the core actions that, if implemented properly, can make a big difference to their cyber security. SMEs can use their “cyber credentials” to demonstrate publicly to their customers and business supply chain that they have in place the key cyber security practices. The scheme will involve self-assessment and independent verification. Ultimately, if there is sufficient interest from SMEs, it could also involve a system of independent certification to ensure objective testing of cyber security practices. Carrying out these core actions provides a pathway towards more detailed cyber security standards that are already available (e.g. ISO 27000 series). Investing in cyber security is fundamental for competitive commercial performance. A guide for business executives is available on the Connect Smart website to ensure cyber security is “on the agenda before it becomes the agenda”.2 Voluntary standards have been developed for industrial control systems, based on work led by the electricity sector.3 These materials will be updated and expanded. Improving and maintaining the cyber security capability of government agencies is important. The head of each government agency is responsible for the implementation of the government’s Protective Security Requirements. These requirements include measures to protect information security such as policies relating to IT procurement, supply chain, cloud services, user access privileges, mobile devices, websites and on-line services.4 New Zealand’s cyber security expertise needs to grow so that businesses and organisations can source the technical staff required to carry out ICT security. At the same time, the education and training system should produce ICT users at all levels with the skills to put in place basic cyber hygiene practices. National Cyber Security Centre, Cyber Security and Risk Management – an Executive Level Responsibility, 2013. http://www.connectsmart.govt.nz/businesses/boards-and-executive/ or http://www.ncsc.govt.nz/assets/cyber-security-riskmanagement-Executive.pdf 2 National Cyber Security Standards, Voluntary Cyber Security Standards for Industrial Control Systems, March 2014. http://www.ncsc.govt.nz/newsroom/ncsc-voluntary-cyber-security-standards-for-infrastructure-operators/ 3 Protective Security Requirements, Information Security Management Protocol, December 2014. http://protectivesecurity.govt. nz/home/information-security-management-protocol/ 4 New Zealand’s Cyber Security Strategy Action Plan 2015 5

Select target paragraph3