a higher proportion of incidents are reported to the authorities, leading to a better
understanding of the size and scale of the threat;
cyber incidents are managed more effectively, efficiently and comprehensively, as a
result of the creation of the CIRT-SL as a centralized incident reporting and response
mechanism; and
we will address the root causes of attacks at a national level, reducing the occurrence of
repeated exploitation across multiple victims and sectors.
4.2 DETER
The National Security Strategy states that defense and protection start with deterrence. This is as
true in cyberspace as any other sphere. To realize our vision of a nation that is secure and
resilient to cyber threats, and prosperous and confident in the digital world, we have to dissuade
and deter those who would intend to harm us and our interests. To achieve this, we all need to
continue to raise levels of cyber security so that attacking us in cyberspace – whether to steal
from us or harm us – is neither cheap nor easy. Our adversaries must know that they cannot act
with impunity: that we can and will identify them, and that we can act against them, using the
most appropriate response from amongst all the tools at our disposal. We will continue to build
global alliances and promote the application of international law in cyberspace. We will also
more actively disrupt the activity of all those who threaten us in cyberspace and the
infrastructure on which they rely. Delivering this ambition requires world-class sovereign
capabilities.
4.2.1 CYBER’S ROLE IN DETERRENCE
Cyberspace is only one sphere in which we must defend our interests and sovereignty. Just as our
actions in the physical sphere are relevant to our cyber security and deterrence, so our actions
and posture in cyberspace must contribute to our wider national security.
The principles of deterrence are as applicable in cyberspace as they are in the physical sphere.
CIRT-SL makes clear that the full spectrum of our capabilities will be used to deter adversaries
and to deny them opportunities to attack us. However, we recognize that cyber security and
resilience are in themselves a means of deterring attacks that rely on the exploitation of
vulnerabilities.