 citizens use government online services with confidence: and trust that their sensitive information is safe and, in turn, understand their responsibility to submit their sensitive information online in a secure manner;  the Government shall set and adhere to the most appropriate cyber security standards, to ensure that all branches of government understand and meet their obligations to secure their networks, data and services; and  The Government’s critical assets, including those at the highest classification, are protected from cyber-attacks. The Government shall continue to move more of its services online so that the state can become truly ‘digital by default’. The Government’s ministry of information stakeholders and CIRT-SL shall ensure that all new digital services built or procured by government are also ‘secure by default’. The Government’s networks are highly complex and in many cases still incorporate legacy systems, as well as some commercially available software which is no longer supported by the vendor. We will ensure that there are no unmanaged risks from legacy systems and unsupported software. We will improve government and wider public sector resilience to cyber-attack. This means ensuring an accurate and up to date knowledge of all systems, data, and those who have access to them. The likelihood and impact of a cyber-incident will be minimized by implementing best practice as set out by the CIRT-SL. The Government will also ensure that it is able to respond effectively to cyber incidents through a programme of incident exercises and regular testing of government networks. We will invite Entrusted Administrations and local authorities to participate in these exercises, as appropriate Cyber security is not just about technology. Almost all successful cyber-attacks have a contributing human factor. We will therefore continue to invest in our people, to ensure that everyone who works in government has a sound awareness of cyber risk. We will develop specific cyber expertise in areas where the risks are heightened and ensure that we have the right processes in place to manage these risks effectively. The CIRT-SL will develop/assemble world- leading cyber security guidance which will keep pace with the threat and development of new technologies. We will take steps to make sure

Select target paragraph3