whether cyber risk is being managed in their sectors to the level demanded by the national interest. The Government shall also ensure that the right regulatory framework for cyber security is in place, one that:  ensure industry acts to protect itself from the threat;  is outcome focused and sufficiently flexible so that it will not fall behind the threat, or lead to compliance rather than sound risk management;  is agile enough to foster growth and innovation, rather than lead it;  is harmonized with regimes in other jurisdictions so that companies do not suffer from a fragmented and burdensome approach; and  delivers, when combined with effective support from the Government, a competitive advantage for CIRT-SL. Many of our industry sectors are already regulated for cyber security. Nonetheless, we must ensure the right steps are taken across the whole economy, including the CNI, to manage cyber security risks. The Government will measure its success in protecting our CNI and other priority sectors by assessing progress towards the following outcomes:  we understand the level of cyber security across the CNI, and have measures in place to intervene, where necessary, to drive improvements in the national interest; and  our most important companies and organizations understand the level of threat and implement proportionate cyber security practices. 4.1.5 CHANGING PUBLIC AND BUSINESS BEHAVIOURS A successful digital economy relies upon the confidence of businesses and the public in online services. The Government is working with industry and other parts of the public sector to increase awareness and understanding of the threat. The Government is also providing the public and business with access to some of the tools that they need to protect themselves. While there are many organizations that are doing an excellent job of protecting themselves, and in providing services to others online, the majority of businesses and individuals are still not properly managing cyber risk.

Select target paragraph3