The majority of online products and services coming into use become ‘secure by default’ by
2022. Consumers will be empowered to choose products and services that have built-in security
as a default setting. Individuals can switch off these settings if they choose to do so but those
consumers who wish to engage in cyberspace in the most secure way will be automatically
protected.
We will pursue the following actions:
the Government shall lead by example by running secure services on the Internet that do
not rely on the Internet itself being secure;
the Government shall explore options for collaboration with industry to develop cuttingedge ways to make hardware and software more ‘secure by default’; and
We shall adopt challenging new cyber security technologies in government, encouraging
administrations to do likewise, in order to reduce perceived risks of adoption. This will
provide proof of concept and demonstrate the security benefits of new technologies and
approaches.
It will also put security at the heart of new product development, eliminate opportunities for
criminal exploitation and thereby protect the end user.
To do this we shall:
Continue to encourage procuring bodies to purchase hardware and software products with
security settings activated as default, requiring the user to actively disable these settings
to make them insecure. Some vendors are already doing this, but some are not yet taking
these necessary steps;
continue to develop an Internet Protocol (IP) reputation service to protect government
digital services (this would allow online services to get information about an IP address
connecting to them, helping the service make more informed risk management decisions
in real time);
seek to install products on government networks that will provide assurance that software
is running correctly, and not being maliciously interfered with;
look to expand beyond the CIRT. GOV.SL domain into other digital services measures
that notify users who are running out-of-date browsers; and