QATAR NATIONAL CYBER SECURITY STRATEGY
2.2 Challenges
The adoption of new technologies such as cloud computing and mobile applications, the implementation of smart-grid technology, and the substantial increase in technology users present
key opportunities for development and innovation. These opportunities, however, exist in an
increasingly fast-paced and evolving environment that will continue to impact Qatar’s ability to
innovate and compete in the global economy. The challenges in this environment include:
§§Cyber Security Skills and Services Deficits. Globally, and in Qatar, there is a shortage
of workers with the requisite knowledge, skills, and abilities to effectively understand
the complexity of ICT and address cyber security issues. In addition, few local providers
offer robust and reliable cyber security services. As ICT products and services increase in
complexity, these deficits have the potential to grow, and if not adequately addressed, further
impact the country’s ability to protect critical information infrastructure (CII).
§§Global Supply Chain Risks. The global cyber ecosystem is a system of interconnected
systems that often include multiple components from various sources around the world. It is
increasingly difficult to determine the origin and integrity of the components of ICT products.
A global supply chain introduces weaknesses that malicious actors may exploit to launch
attacks.
§§ICS Connectivity. ICSs are increasingly connected to business networks and the Internet.
While this connectivity provides efficiencies that enable the remote monitoring of the
mechanical processes used for oil and natural gas production, electricity generation, and
water purification, it also increases the vulnerability of ICSs to cyber threats.
§§Information Sharing Constraints. Information owners or providers may be reluctant to
share information about vulnerabilities, incidents, and best practices for fear of revealing
weaknesses. In addition, individual organizations do not always understand that information
they possess about cyber threats, vulnerabilities, and effective best practices can be of value
to others.
§§Executive Leadership Awareness. While information technology (IT) managers, chief
information officers, chief technology officers, and chief information security officers typically
address cyber security for their organizations, cyber security affects more than the smooth
operation of an organization—it affects an organization’s overall mission and its bottom line.
Unfortunately, when communication between executive leadership and IT professionals is
limited, the senior-most levels of the organization can lack awareness of the real risks or the
resources necessary to implement security requirements, coordinate incident response, and
mitigate those risks.
§§Changing Privacy Expectations. Due to the increased use of personal information within
government organizations and throughout international business, countries continue to enact
and update privacy laws to protect individuals and their data. Many of these countries require
“adequate levels of protection” before allowing international organizations to transfer data
to destinations outside their borders.12 When personal information is not properly protected,
organizations face potential risks: for a government organization, this could mean loss of trust
in its online services; businesses risk losing customers to global competitors.
5