Executive Summary Traditionally, the concept that “security is everyone’s business” has been an essential part of any normal security best practices, education and awareness campaigns against phishing and, or other cyber-related attacks. Technically, these cyber-attacks are often the very first step for cybercriminals to work their way to their ultimate target. For instance, the first cyber-attack, ‘Morris worm’ or the infamous ‘ILOVEYOU’ worm which 20 years ago contributed to revolutionizing the way cyber-attacks are deliberately executed. These cyber-attacks brought about new knowledge on how countries and organizations respond to cyber-threats. ‘Lesson learnt’ shows that awareness and diligence are important at all levels and often referred by security experts as one of the best ways to combat cybercrime. Moreover, the implementation of national cyber security frameworks including polices, strategies and standard operating procedures, are key guides and plans to enhance cyber security efforts in any country. As more traditional services such as sending of handwritten mails or norms of doing business transactions are transforming into online or e-services, there are increasing cyber risks associated with the way technology is evolving. Moreover, the current COVID-19 pandemic reaffirms cyber security as a top concern for governments and businesses around the world. The prioritization and enforcement of cyber security is a challenge and does not come easy or cheap for an organization, and even for someone whose job does not involve sensitive data, systems or Vanuatu as a whole. That cyber security mindset must change or evolve over time when employees or Internet users realize they do hold the missing piece that enable attackers to infiltrate key systems. Therefore, cyber security education and awareness are essential steps in creating a ‘security-literate’ and a ‘security-aware’ society that ensures employees and Internet users understand that any data or credentials they expose, regardless of how insignificant they seem, can become a foothold for attackers to pivot toward bigger cyber-attacks or prizes of much greater value. Being security-literate and security-aware can help organizations and users develop concrete Incident Response (IR) plans which clearly define all stages:     Preparation; Detection & Analysis; Containment, Eradication & Recovery; and Post-Incident Activities. This National Cyber Security Strategy delivers six national priorities to strengthen National Security and address cyber-threats and issues in Vanuatu. The Strategy priorities include:       Cyber Resilience; Cyber Security Awareness; Cyber Capability and Literacy; Addressing Cybercrime; International Engagement; and Cyber Security Standards and Legal Frameworks. It is also important to address these national priorities with critical national responses to ensure the Government, Businesses and Internet users are secured and protected from cyber-attacks. These responses are classified under a multi-stakeholder approach which are categorized into three groups:  Government Responses;  Private Sector Responses; and  Civil Society Responses. Furthermore, the strategy emphasises on the importance of ‘Cyber Security Education’ and the urgent need to unify efforts through the multi-stakeholder framework. It is a cornerstone for building effective unified cyber security awareness campaigns. Organizations and cyber security stakeholders must develop and contribute in helping employees and other Internet users learn how to identify security risks and threats such as phishing attacks. Hence, awareness has to reach a more personal level to be truly effective for everyone who utilize the Internet and technology on a daily basis. Once at the personal level, the sense of ‘trust’ and ‘ownership’ evolves therefore Internet users to make better choices and decisions while being online. 3 | Vanuatu’s Cyber Security Strategy 2030

Select target paragraph3