6. CRITICAL SUCCESS FACTORS (CSFS) The CMM that was used to assess cybersecurity posture of Malawi revealed a number of critical success factors that will lead to successful achievement of cybersecurity goals of Malawi. These factors include: 6.1. Political Will ● Enhancing Malawi’s cybersecurity posture needs to be a top priority for the Government. ● Cybersecurity requires adequate organizational and political support. ● At the national level, cybersecurity has to be driven from the highest office to provide a unified agenda that will guide all relevant national stakeholders. ● At organization level, the success of cybersecurity efforts depend mainly on the commitment and support of top management to get stakeholders support and secure budget for cybersecurity. ● security governance should be led by competent security managers 6.2. Funding and Resources ● The successful implementation of Malawi’s NCS will depend on adequate funds and resources. Considering that ICTs and Cyberspace spur socio-economic growth, the National Cybersecurity Strategy implementation logical frameworks have identified possible lead organization and funding sources for various measures proposed in the NCS. 6.3. Effective coordination of efforts ● Cybersecurity is a shared responsibility among different players with different responsibilities and abilities requiring unified coordination across a wide spectrum of stakeholders. ● Successful implementation of the NCS will therefore, require developing a comprehensive national structure that will facilitate national cohesion at all levels and meaningful participation by all stakeholders, working together toward a common goal of securing Malawi’s cyberspace. 6.4. Awareness, education and training ● The success of cybersecurity depends on availability of the requisite knowledge, awareness, trust to use information systems and reduced exposure to risks. ● It is important to inform, educate and raise awareness of public and private organizations, owners of critical infrastructures and the civil society of their security responsibilities. ● Security awareness among ICT professionals and users can prevent them from becoming easy and soft target for cyber criminals. It is also important for the nation to provide qualified human resources with enhanced technological capabilities of dealing with 24

Select target paragraph3