whether cyber risk is being managed in their sectors to the level demanded by the national
interest.
The Government shall also ensure that the right regulatory framework for cyber security is in
place, one that:
ensure industry acts to protect itself from the threat;
is outcome focused and sufficiently flexible so that it will not fall behind the threat, or
lead to compliance rather than sound risk management;
is agile enough to foster growth and innovation, rather than lead it;
is harmonized with regimes in other jurisdictions so that companies do not suffer from a
fragmented and burdensome approach; and
delivers, when combined with effective support from the Government, a competitive
advantage for CIRT-SL.
Many of our industry sectors are already regulated for cyber security. Nonetheless, we must
ensure the right steps are taken across the whole economy, including the CNI, to manage cyber
security risks.
The Government will measure its success in protecting our CNI and other priority sectors by
assessing progress towards the following outcomes:
we understand the level of cyber security across the CNI, and have measures in place to
intervene, where necessary, to drive improvements in the national interest; and
our most important companies and organizations understand the level of threat and
implement proportionate cyber security practices.
4.1.5 CHANGING PUBLIC AND BUSINESS BEHAVIOURS
A successful digital economy relies upon the confidence of businesses and the public in online
services. The Government is working with industry and other parts of the public sector to
increase awareness and understanding of the threat. The Government is also providing the public
and business with access to some of the tools that they need to protect themselves. While there
are many organizations that are doing an excellent job of protecting themselves, and in providing
services to others online, the majority of businesses and individuals are still not properly
managing cyber risk.