ACTIONS OUTCOMES WHO?* ACTION 1 • Agencies, businesses and individuals have clarity about where to report cyber incidents. NCPO/CERT • Efficient triaging of cyber incidents to relevant agencies. Police • The impact of cyber incidents is contained – harm and reoccurrence is reduced. NZSIS SET UP A NATIONAL CERT • There is trusted two-way sharing of information on cyber threats. • Actionable and timely advice provided to agencies, businesses and individuals • An internationally recognised contact point for dealing with cyber security incidents. ACTION 2 VIGOROUSLY PROTECT NEW ZEALAND’S MOST IMPORTANT INFORMATION INFRASTRUCTURES • The protection of New Zealand’s most important information infrastructures is prioritised and reflects our evolving national interests. • Increased number of organisations receiving CORTEX malware protection services. • Increased number of instances of malware detected and disrupted. • Potential for additional support to Internet Service Providers (ISPs) is explored. ACTION 3 USE CYBER TOOLS TO FURTHER NEW ZEALAND’S NATIONAL SECURITY INTERESTS ACTION 4 PREPARE FOR MAJOR CYBER INCIDENTS NCSC/GCSB DIA/GCIO Private sector Connect Smart partners - NetSafe - NZITF NCSC/GCSB NCPO ISPs Government agencies and private sector entities of high national interest. • NZDF’s information systems and platforms are resilient to adversary exploitation. NZDF • Threats to New Zealand’s security interests are detected and averted. MoD • Cyber tools are used in accordance with the law and subject to relevant oversight mechanisms. GCSB NZSIS • Twice yearly inter-agency exercises, including the private sector and international partners. NCPO/CERT • Readiness and capability to deal with a major cyber incident, including coordinated technical, law enforcement, policy and communications responses. Police • Trusted relationships established with international partners. MFAT NCSC/GCSB DIA/GCIO NZSIS Connect Smart partners - NetSafe - NZITF * DIA: Department of Internal Affairs; GCIO: Government Chief Information Officer; GCPO: Government Chief Privacy Officer; GCSB: Government Communications Security Bureau; IITP: Institute of IT Professionals; ISP: Internet Service Provider; MBIE: Ministry of Business, Innovation and Employment; MFAT: Ministry of Foreign Affairs and Trade; MoD: Ministry of Defence; MoE: Ministry of Education; MoJ: Ministry of Justice; NCPO: National Cyber Policy Office; NCSC: National Cyber Security Centre; NGO: Non-Governmental Organisation NZDF: New Zealand Defence Force; NZITF: New Zealand Internet Task Force; NZQA: New Zealand Qualifications Authority; NZSIS: New Zealand Security Intelligence Service; NZTE: New Zealand Trade and Enterprise; TEC: Tertiary Education Commission. 4 New Zealand’s Cyber Security Strategy Action Plan 2015

Select target paragraph3