from vulnerabilities that attackers look for and have the tools to exploit. An additional issue is
the use by some organizations of unsupported software, for which patching regimes do not exist.
According to CISCO’s 2016 annual security report, 106,000 devices out of 115,000 analyzed,
had vulnerabilities in the software they are running on.
2.2.5 Access to hacking resources
The readily available hacking information and user-friendly hacking tools on the Internet is
enabling those who want to develop a hacking capability to do so. The information hackers need
in order to compromise victims successfully is often openly accessible and can be reaped
quickly. Everyone needs to be aware of the extent of exposure of their personal details and
systems on the Internet, and the degree to which that could leave them vulnerable to malicious
cyber exploitation.
2.3 CONCLUSIONS
We have adopted a national cyber security and data protection policy and established
institution(s) that will enhanced our resilience and mitigate some of the threats we face in
cyberspace. However, we are not yet ahead of the threats. The types of malicious cyber actors we
must contend with, and their motivations, have largely endured, even as the volume of malware
and the numbers of such malicious actors has grown rapidly. Our collective challenge is to
ensure our defenses are evolved, reinforced and responsive enough to counter such threats, to
reduce the ability of malicious actors to attack us and to address the root causes of the
vulnerabilities outlined above.
3.0 NATIONAL RESPONSE
To mitigate the multiple threats we face and safeguard our interests in cyberspace, we need a
strategic approach that underpins all our collective and individual actions in the digital domain
over the next five years. This section sets our strategic approach.
3.1 PRINCIPLES
In working towards these objectives, the Government will apply the following principles:
our policies shall be driven by the need to both protect our people and enhance our
prosperity;