GOAL TWO:
Cyber Capability
NEW ZEALANDERS, BUSINESSES AND GOVERNMENT AGENCIES
UNDERSTAND CYBER THREATS AND HAVE THE CAPABILITY TO
PROTECT THEMSELVES ONLINE
The Cyber Capability goal goes beyond promoting awareness, to focus on building cyber security
capability among individuals, businesses, government agencies and organisations. Achieving this
goal means that New Zealanders at all levels will have the skills and tools to protect themselves
online, making it harder for malicious cyber actors to steal private data, identity information or
cause damage to information systems.
Connect Smart is an on-going cyber security awareness and capability campaign. The aim is
to spread the cyber security message as broadly as possible, including using Connect Smart public
and private partners to build the cyber security skills of their staff, customers and supply chains.
Connect Smart partners are cyber security champions working collectively to improve
New Zealand’s cyber security.
Small and medium enterprises (SMEs) play a huge role in New Zealand’s economic growth; it is
important that they are equipped to protect their business information. Targeted and accessible
cyber security advice will be made available for SMEs through the Connect Smart website and
activities, including an online questionnaire to complement the “SME Cyber Security Toolkit”.
A new “cyber credentials” scheme is proposed for SMEs. The scheme will promote to the SME
audience the core actions that, if implemented properly, can make a big difference to their cyber
security. SMEs can use their “cyber credentials” to demonstrate publicly to their customers and
business supply chain that they have in place the key cyber security practices. The scheme will
involve self-assessment and independent verification. Ultimately, if there is sufficient interest from
SMEs, it could also involve a system of independent certification to ensure objective testing of
cyber security practices. Carrying out these core actions provides a pathway towards more detailed
cyber security standards that are already available (e.g. ISO 27000 series).
Investing in cyber security is fundamental for competitive commercial performance. A guide
for business executives is available on the Connect Smart website to ensure cyber security is
“on the agenda before it becomes the agenda”.2 Voluntary standards have been developed
for industrial control systems, based on work led by the electricity sector.3 These materials
will be updated and expanded.
Improving and maintaining the cyber security capability of government agencies is important.
The head of each government agency is responsible for the implementation of the government’s
Protective Security Requirements. These requirements include measures to protect information
security such as policies relating to IT procurement, supply chain, cloud services, user access
privileges, mobile devices, websites and on-line services.4
New Zealand’s cyber security expertise needs to grow so that businesses and organisations can
source the technical staff required to carry out ICT security. At the same time, the education and
training system should produce ICT users at all levels with the skills to put in place basic cyber
hygiene practices.
National Cyber Security Centre, Cyber Security and Risk Management – an Executive Level Responsibility, 2013.
http://www.connectsmart.govt.nz/businesses/boards-and-executive/ or http://www.ncsc.govt.nz/assets/cyber-security-riskmanagement-Executive.pdf
2
National Cyber Security Standards, Voluntary Cyber Security Standards for Industrial Control Systems, March 2014.
http://www.ncsc.govt.nz/newsroom/ncsc-voluntary-cyber-security-standards-for-infrastructure-operators/
3
Protective Security Requirements, Information Security Management Protocol, December 2014. http://protectivesecurity.govt.
nz/home/information-security-management-protocol/
4
New Zealand’s Cyber Security Strategy Action Plan 2015
5