Executive Summary
Traditionally, the concept that “security is everyone’s business” has been an essential part of any
normal security best practices, education and awareness campaigns against phishing and, or other
cyber-related attacks. Technically, these cyber-attacks are often the very first step for cybercriminals
to work their way to their ultimate target. For instance, the first cyber-attack, ‘Morris worm’ or the
infamous ‘ILOVEYOU’ worm which 20 years ago contributed to revolutionizing the way cyber-attacks
are deliberately executed. These cyber-attacks brought about new knowledge on how countries
and organizations respond to cyber-threats. ‘Lesson learnt’ shows that awareness and diligence are
important at all levels and often referred by security experts as one of the best ways to combat
cybercrime. Moreover, the implementation of national cyber security frameworks including polices,
strategies and standard operating procedures, are key guides and plans to enhance cyber security
efforts in any country.
As more traditional services such as sending of handwritten mails or norms of doing business
transactions are transforming into online or e-services, there are increasing cyber risks associated with
the way technology is evolving. Moreover, the current COVID-19 pandemic reaffirms cyber security as
a top concern for governments and businesses around the world.
The prioritization and enforcement of cyber security is a challenge and does not come easy or cheap
for an organization, and even for someone whose job does not involve sensitive data, systems or
Vanuatu as a whole. That cyber security mindset must change or evolve over time when employees
or Internet users realize they do hold the missing piece that enable attackers to infiltrate key systems.
Therefore, cyber security education and awareness are essential steps in creating a ‘security-literate’
and a ‘security-aware’ society that ensures employees and Internet users understand that any data
or credentials they expose, regardless of how insignificant they seem, can become a foothold for
attackers to pivot toward bigger cyber-attacks or prizes of much greater value. Being security-literate
and security-aware can help organizations and users develop concrete Incident Response (IR) plans
which clearly define all stages:
Preparation;
Detection & Analysis;
Containment, Eradication & Recovery; and
Post-Incident Activities.
This National Cyber Security Strategy delivers six national priorities to strengthen National Security
and address cyber-threats and issues in Vanuatu. The Strategy priorities include:
Cyber Resilience;
Cyber Security Awareness;
Cyber Capability and Literacy;
Addressing Cybercrime;
International Engagement; and
Cyber Security Standards and Legal Frameworks.
It is also important to address these national priorities with critical national responses to ensure the
Government, Businesses and Internet users are secured and protected from cyber-attacks. These
responses are classified under a multi-stakeholder approach which are categorized into three groups:
Government Responses;
Private Sector Responses; and
Civil Society Responses.
Furthermore, the strategy emphasises on the importance of ‘Cyber Security Education’ and the urgent
need to unify efforts through the multi-stakeholder framework. It is a cornerstone for building effective
unified cyber security awareness campaigns. Organizations and cyber security stakeholders must
develop and contribute in helping employees and other Internet users learn how to identify security
risks and threats such as phishing attacks. Hence, awareness has to reach a more personal level to
be truly effective for everyone who utilize the Internet and technology on a daily basis. Once at the
personal level, the sense of ‘trust’ and ‘ownership’ evolves therefore Internet users to make better
choices and decisions while being online.
3
| Vanuatu’s Cyber Security Strategy 2030