QATAR NATIONAL CYBER SECURITY STRATEGY 2.2 Challenges The adoption of new technologies such as cloud computing and mobile applications, the implementation of smart-grid technology, and the substantial increase in technology users present key opportunities for development and innovation. These opportunities, however, exist in an increasingly fast-paced and evolving environment that will continue to impact Qatar’s ability to innovate and compete in the global economy. The challenges in this environment include: §§Cyber Security Skills and Services Deficits. Globally, and in Qatar, there is a shortage of workers with the requisite knowledge, skills, and abilities to effectively understand the complexity of ICT and address cyber security issues. In addition, few local providers offer robust and reliable cyber security services. As ICT products and services increase in complexity, these deficits have the potential to grow, and if not adequately addressed, further impact the country’s ability to protect critical information infrastructure (CII). §§Global Supply Chain Risks. The global cyber ecosystem is a system of interconnected systems that often include multiple components from various sources around the world. It is increasingly difficult to determine the origin and integrity of the components of ICT products. A global supply chain introduces weaknesses that malicious actors may exploit to launch attacks. §§ICS Connectivity. ICSs are increasingly connected to business networks and the Internet. While this connectivity provides efficiencies that enable the remote monitoring of the mechanical processes used for oil and natural gas production, electricity generation, and water purification, it also increases the vulnerability of ICSs to cyber threats. §§Information Sharing Constraints. Information owners or providers may be reluctant to share information about vulnerabilities, incidents, and best practices for fear of revealing weaknesses. In addition, individual organizations do not always understand that information they possess about cyber threats, vulnerabilities, and effective best practices can be of value to others. §§Executive Leadership Awareness. While information technology (IT) managers, chief information officers, chief technology officers, and chief information security officers typically address cyber security for their organizations, cyber security affects more than the smooth operation of an organization—it affects an organization’s overall mission and its bottom line. Unfortunately, when communication between executive leadership and IT professionals is limited, the senior-most levels of the organization can lack awareness of the real risks or the resources necessary to implement security requirements, coordinate incident response, and mitigate those risks. §§Changing Privacy Expectations. Due to the increased use of personal information within government organizations and throughout international business, countries continue to enact and update privacy laws to protect individuals and their data. Many of these countries require “adequate levels of protection” before allowing international organizations to transfer data to destinations outside their borders.12 When personal information is not properly protected, organizations face potential risks: for a government organization, this could mean loss of trust in its online services; businesses risk losing customers to global competitors. 5

Select target paragraph3