This paper follows ongoing research and previously published articles on the development of a Critical Infrastructure Cyber Governance Maturity Model (CICGM ${ }^{\mathbf{2}})$. The aim of the CICGM2 is to assess and improve the cybersecurity posture of critical infrastructures - specifically in developing countries. The research suggests that there are gaps in terms of cybersecurity governance development at critical infrastructures in developing countries. The CICGM ${ }^{\mathbf{2}}$ addresses this gap by enabling role players responsible for the safeguarding critical infrastructure systems in developing countries with a cybersecurity governance maturity tool to determine their current cybersecurity governance capacity posture whilst also providing guidelines on how they can improve on this. The article presents the methodology that is suggested to deploy and implement the CICGM2 at critical infrastructure facilities in developing countries. The deployment methodology of the CICGM2 is based on the widely recognized focus group methodology of the Cybersecurity Capacity Maturity Model for Nations (CMM) developed by the University of Oxford's Global Cyber Security Capacity Centre.
Without critical infrastructures such as electricity, drinking water or health services, society as we know it will come to a standstill. Infrastructure protection in developing countries is a serious challenge. The cybersecurity threat to critical infrastructures in developing countries is far greater than for developed countries and cybersecurity challenges in developing countries are often beyond the scope of the people managing such facilities. An explorative literature review indicated that although there are norms and standards for critical infrastructures in developing countries very little research has been done on the cybersecurity governance aspect of critical infrastructures. Similarly, there is limited research on maturity models to evaluate the maturity of cybersecurity governance of critical infrastructures in developing countries. The development of a functional cybersecurity governance maturity model will capacitate role players responsible for the safeguarding of critical infrastructure systems in developing countries. The purpose of the article is to present research aimed at creating a Critical Infrastructure Cyber Governance Maturity Model (CICGM(2)) focused on the cybersecurity governance of critical infrastructure systems in developing countries. The outcome of the CICGM(2) will contain a tailor-made cybersecurity governance assessment tool to improve the management of critical infrastructures in developing countries. The CICGM(2) will be developed by integrating recognized cybersecurity governance frameworks with established cybersecurity maturity models.
As the utilization of cyber systems in the management and operation of critical infrastructures have grown, the cybersecurity threats to critical infrastructure sectors such as energy, healthcare, transportation and water simultaneously increased exponentially. Critical infrastructures in developing countries are particularly vulnerable to growing cybersecurity threats due to limited resources, inadequate cybersecurity policies and a general shortage of skilled cybersecurity specialists. Addressing these vulnerabilities is essential for developing countries to ensure the operational continuity, data protection and public safety associated with functioning critical infrastructures. An explorative literature review identified a number of aspects that can be used to counter the increasing cybersecurity threats to critical infrastructures in developing countries. Literature suggests that although there are defined norms and standards for critical infrastructures in developing countries, there is room for improvement in terms of the contribution that enhanced cybersecurity awareness can accomplish. A good cybersecurity awareness program must include sufficient training that is aligned with an organization’s objectives, focus on raising cybersecurity awareness while performing normal duties whilst creating an interactive cybersecurity communication culture between all stakeholders. This paper presents research that is in progress to develop a functional cybersecurity governance maturity model aimed at capacitating role players responsible for the safeguarding of critical infrastructure systems in developing countries. The primary aim of the evolving Critical Infrastructure Cyber Governance Maturity Model (CICGM²) is to improve the cybersecurity governance of critical infrastructure systems in developing countries. The purpose of the article is to specifically describe how the CICGM² can be used to assess and determine the level of maturity of cybersecurity awareness programs at critical infrastructures in developing countries. The integration of recognized cybersecurity governance frameworks and established cybersecurity maturity models into the CICGM² presents unique opportunities to establish, measure and manage cybersecurity awareness initiatives at critical infrastructure systems in developing countries. This article contributes to the field of cybersecurity governance by offering a non-technical, scalable and adaptable CICGM² for key stakeholders at critical infrastructures in developing countries that can be used to determine the level of the cybersecurity awareness initiatives for the facilities that they are responsible for.
At the beginning of 2020, the world came to a stand‐still when governments across the globe decided to enter states of ‘emergency’ or ‘disaster’ over the breakout of the COVID‐19 pandemic. The responses to the pandemic included stringent movement restrictions and hygiene advice preventing face‐to‐face interactions. As a result, many activities, including schooling, working, and shopping were moved online, drastically increasing exposure to cyber threats and risks. It is unclear if and how the rapid increase in internet use corresponded to an improvement in cybersecurity mindset development in countries of the Southern African Development Community (SADC). This paper explores the effect of the increase in digital technology usage due to the COVID‐19 pandemic restrictions on the relationship between cybersecurity awareness‐raising initiatives and the development of higher levels of cybersecurity mindset in Botswana, Lesotho, and Malawi. These three countries have a similar cybersecurity footprint and an average cybersecurity capacity level for the region. The research applies a comparative multiple case study approach relying on a thematic review of the literature and related documents, supported by in‐depth interviews with purposefully selected key informants from the three selected SADC countries. Findings suggest that since the start of the COVID‐19 pandemic, awareness‐raising programs have gained some momentum in our selected countries, but the cybersecurity mindset has not improved. That was attributed to low frequency and poor quality of campaigns added to the lack of training, education and lived experience. The paper highlights the need to increase the frequency and improve the quality of programmes, for greater impact on the development of local cybersecurity mindsets.
The Internet of Medical Things (IoMTs), which is basically a subset of the wider Internet of Things (IoTs), has become a core component of modern healthcare. All indications are that it will expand at great speed providing more sophisticated and interconnected health support to patients. However, it is well documented that there are big cybersecurity risks in the IoMTs. Managing this cybersecurity risks within this growing IoMTs in hospitals and other institutions, is of growing concern, and is causing serious worries. Cybersecurity Governance is the responsibility of the Board of Governors (Directors) of an Institution, and relates to the accountability, responsibility and oversight role the Board has, as part of good Corporate Governance, to ensure that the Institution is and stays resilient against cyberattacks and cybercrime. This paper motivates and the emphasises the general Cybersecurity Governance responsibilities of Boards of Governors in the IoMTs, provide some guidelines for such Governors and specifically investigates the question whether Cybersecurity Governance in the IoMTs adds any extra aspects which are maybe not present or not so apparent in Cybersecurity Governance in other areas.
Cybercrime has become one of the biggest forms of crime in the world today – if not the biggest form. Everybody is seeking ways to address this growing cyber risk. Cybersecurity awareness of end users is an important component of helping to prevent cybercrime. However, research indicates that traditional cybersecurity awareness programs are not very successful. Budgets for cyber protection programs keep increasing, but there is no evidence that the levels of cybercrime are decreasing. Companies (across the globe) are searching for new ways and approaches to make their end users more cyber aware. What has become clear from many efforts and approaches in making end users cyber aware, is that an approach emphasizing the technical aspects alone does not work. A complementary human oriented approach is also needed. This paper advances 3 new possible approaches which can be considered in the challenge to create more cyber aware end users. The first approach, called the ‘Fighter’ approach, is taken from the area of firefighting, where employees are trained to fight a fire in an emergency. The second approach, called the ‘Ownership’ approach, is from the operational technology (OT) area where machine operators are trained to take ownership of their machines and safely operate their machines. The third approach, called the ‘Workplace’ approach, is taken from the area of workplace training where being cyber-awareness is seen as a part of a secure workplace. All three these approaches are based on primarily on letting the end user realise that cybersecurity awareness is actually part of their daily job environment.
This chapter gives managers and decision makers guidance in prioritizing limited resources as they face the challenge of protecting stakeholders from growing online threats. Based on a comparative study of 80 nations, we have found a clear impact of cybersecurity education, awareness raising, and training (CEAT) on the vitality of internet use and services at the national level. CEAT encompasses one of five dimensions of a larger cybersecurity capacity-building model (the Cybersecurity Capacity Maturity Model for Nations or CMM) developed by the Global Cybersecurity Capacity Centre. This chapter briefly describes the education, awareness, and training indicators that compose this dimension of capacity building within the CMM and our cross-national analysis of the outcomes of CEAT on internet use. Controlling for contextual variables, such as the wealth of the nations and scale of internet use, the quantitative analysis shows a positive and statistically significant impact of CEAT on the vitality of internet use and services but also a distribution of CEAT scores that indicates key issues for low-income and developing nations. A qualitative analysis of responses from a sample of these nations is used to identify key reasons for their maturity levels in this area. Recognizing the lack of maturity in cybersecurity education, awareness raising, and training in most nations studied, the chapter offers suggestions for policy and practice to meet the need for more effective programs.
This paper assesses the impact of cybersecurity education, awareness raising, and training (CEAT) on the vitality of internet use and services at the national level. CEAT encompasses one of five dimensions of a larger cybersecurity capacity building model (CMM) that was developed by the Global Cybersecurity Capacity Centre. The paper describes this dimension of capacity building within the CMM, and its indicators of education, awareness, and training in cybersecurity capacity. The paper then presents a cross-national analysis of the outcomes of CEAT on internet use based on comparative data from 80 nations. Controlling for contextual variables, such as the wealth of the nations and scale of internet use, the analysis shows a positive and statistically significant impact of CEAT on the vitality of internet use and services, as well as a distribution of CEAT scores that indicates key issues for low-income and developing nations. A qualitative analysis of responses from these nations is used to identify key reasons for their levels of maturity in this area. While recognising key limitations of these findings, it offers suggestions for policy and practice to meet the need for effective programs for education, awareness raising, and training. In addition, the research suggests the need for more detailed indicators of CEAT initiatives in more nations and over time to assess the validity of the findings and the recommendations for policy and practice in this area of capacity building offered in this paper.
The South African economy is not only the second largest in Africa, but it is also the most diversified, industrialized and technologically advanced on the continent. This technological advance is evidenced by its citizenry’s comparatively high-level of digital connectivity and interconnectedness. On the reverse side, South Africa (SA) has the third highest number of cybercrime victims internationally. Maintaining and expanding its competitive technological advantage requires of South Africa to have a robust national cybersecurity endeavour. This needs to include an innovative, high-impact cybersecurity awareness campaign that effectively reaches a diverse population. This paper’s primary aim is to propose such a high-impact drive, namely a broad-based national cybersecurity awareness campaign that levers the South African minibus taxi industry. The paper’s three objectives pertain to the ‘why’ and ‘how’ of such a campaign. The paper’s first objective is to substantiate the need for a broad-based cybersecurity awareness campaign (in short: why is it needed?). The second objective is to substantiate why the taxi industry constitutes an optimal platform for a game changing campaign. Thirdly, the paper advances a proposition on a Taxi Industry Cybersecurity Awareness Campaign (TICAC) (i.e. how can the taxi industry be a game changer?). We qualify the TICAC as a tentative, high-level conceptual proposition subject to much further research on the theoretical/academic and practical levels. It is hoped that the paper would be of value to also other countries – developed and developing – in utilising private and/or public transport industries as platforms for cybersecurity awareness initiatives.
The popularity of wearable devices is growing exponentially, with consumers using these for a variety of services. Fitness devices are currently offering new services such as shopping or buying train tickets using contactless payment. In addition, fitness devices are collecting a number of personal information such as body temperature, pulse rate, food habits and body weight, steps-distance travelled, calories burned and sleep stage. Although these devices can offer convenience to consumers, more and more reports are warning of the cybersecurity risks of such devices, and the possibilities for such devices to be hacked and used as springboards to other systems. Due to their wireless transmissions, these devices can potentially be vulnerable to a malicious attack allowing the data collected to be exposed. The vulnerabilities of these devices stem from lack of authentication, disadvantages of Bluetooth connections, location tracking as well as third party vulnerabilities. Guidelines do exist for securing such devices, but most of such guidance is directed towards device manufacturers or IoT providers, while consumers are often unaware of potential risks. The aim of this paper is to provide cybersecurity guidelines for users in order to take measures to avoid risks when using fitness devices.
Critical infrastructure in South Africa remains highly vulnerable to cybercrime threats due to a poor cyber-crime fighting capacity and a lack of a strong cybersecurity policy. South Africa appears to have fallen behind in securing and protecting cyberspace, considering the country's dependability as well as the interconnectedness to the internet. Globally, the water and wastewater sector were ranked number four in the global security incidents. This study presents the findings of a systematic literature review conducted to assess the cybersecurity knowledge necessary for a general employee in the water sector. The study proposes a framework for determining the minimum knowledge that a general employee in the water sector should have. The frameworks start by defining the eight different types of cybersecurity challenges, then move on to mitigation strategies for dealing with such attacks. Several approaches and strategies were provided for mitigating various cybersecurity challenges. To deal with such risks, mitigations such as cybersecurity knowledge and skills, cybersecurity awareness, and cybersecurity training were proposed. The strategies for developing knowledge to deal with various sorts of dangers were provided at both the individual and organizational levels.
Cybersecurity is high on the agenda of national and international security policy discussions – mostly lead by diplomats. The practise of diplomacy has evolved since the Internet has become the backbone of society as we know it. Technological evolution has resulted in a significantly bigger and more accessible cyberspace, but the ability of governments and institutions to respond to and function in an expanding cyberspace seems to be lagging behind. The practice of diplomacy has similarly changed fundamentally and created a cyber-diplomacy environment where there is an increased utilization of inter alia social media platforms to achieve foreign policy goals. There is not enough attention given to practical processes to guide the new breed of diplomats in the evolving world of cyber-diplomacy and there is a need to improve the cybersecurity awareness of diplomats in all countries, but this article will focus primarily on developing countries. To mitigate potential cyber threats to diplomacy, diplomats need to be subjected to cyber-diplomacy orientation as well as functional cyber awareness training. Preliminary research conducted suggests that there is a gap between the existing and required cyber-diplomacy and cybersecurity awareness levels of diplomats from developing countries. The purpose of the article is to present a cyber-diplomacy and cybersecurity awareness framework (CDAF) that can be used by developing countries to equip their diplomats to play a more constructive role within the international cyber-diplomacy domain. The CDAF comprises of two distinct components, namely cyber-diplomacy and cybersecurity awareness, but this article will focus primarily on the cyber-diplomacy capacity building aspect of the CDAF. The CDAF was developed by following a design science research approach where a real-world problem was identified followed by an in-depth literature review to identify objectives and possible solutions to the problem. The subsequent outcomes were used to design and development of the CDAF. The article concludes with a critical evaluation of the proposed framework as well as how it can be incorporated into the developing cybersecurity knowledge modules of the Global Forum on Cyber Expertise (GFCE).
Download This Paper Open PDF in Browser Add Paper to My Library Share: Permalink Using these links will ensure access to this page indefinitely Copy URL Copy DOI
Users have lost control and ownership of their personal information in Cyberspace. A user’s personal information is scattered across many (company) databases in Cyberspace, which introduces many security risks. The user usually has no idea where his/her personal data is stored in Cyberspace, and has very little, if any, control over consolidating or deleting such data. The purpose of the research presented in this paper is to explore an alternative approach to return the ownership and control of their data to the real owners. This will allow for the secured ownership and control of personal information by the real owner. This new approach will use the Blockchain technology, together with Smart Contracts, to put the owner in charge of his/her personal data, and ensure the control and secure access to such data. In this paper, we will present a model, called the “SUUS CHAIN” model, to manage the ownership of personal data.
Nowadays, many cyber users do not understand how to protect themselves and their information within cyber space. One reason is that cyber users are unaware of possible cyber risks and threats that may occur within cyber space. The second reason is that citizens, businesses and users within the public sector may be aware of relevant cyber risks but do not really understand the seriousness of such risks and the consequences if they do realise. Therefore, cybersecurity awareness campaigns are an integral part of improving cybersecurity awareness. Based on in-country reviews conducted as part of the Global Cybersecurity Capacity Centre (GCSCC) programme, we observed that the campaigns to raise cybersecurity awareness throughout the country are often led by different ‘owners’ without co-ordination and adequate resources therefore creating fragmentation in the national cybersecurity awareness raising programme. This paper suggests that the development of a coordinated and coherent national cybersecurity awareness program is critical for building a basic level of aware-ness at the national level. We will examine the requirements needed to develop a coordinated national awareness raising programme by reviewing the existing literature, best practice approaches and the role of different stakeholders such as the government, private sector and civil society. We will draw conclusions on the main obstacles to ensure overall coherence between the actions of stakeholders and the efforts countries should prioritise in order to increase awareness of cyber risks at the national level.
PurposeThe purpose of this paper is to position the preservation and protection of intellectual capital as a cyber security concern. The paper outlines the security requirements of intellectual capital to help boards of directors (BoDs) and executive management teams to understand their responsibilities and accountabilities in this respect.Design/methodology/approachThe research methodology is desk research. In other words, we gathered facts and existing research publications that helped us to define key terms, to formulate arguments to convince BoDs of the need to secure their intellectual capital and to outline actions to be taken by BoDs to do so.FindingsIntellectual capital, as a valuable business resource, is related to information, knowledge and cyber security. Hence, preservation thereof is also related to cyber security governance and merits attention from BoDs.Research limitations/implicationsThis paper clarifies BoDs intellectual capital governance responsibilities, which encompass information, knowledge and cyber security governance.Practical implicationsThe authors hope that BoDs will benefit from the clarifications, and especially from the positioning of intellectual capital in cyber space.Social implicationsIf BoDs know how to embrace their intellectual capital governance responsibilities, this will help to ensure that such intellectual capital is preserved and secured.Originality/valueThis paper extends a previous paper published by Von Solms and Von Solms, which clarified the key terms of information and cyber security, and the governance thereof. The originality and value is the focus on the securing of intellectual capital, a topic that has not yet received a great deal of attention from security researchers.
This book reflects academically on important and relevant natural scientific disciplines, important technologies and related media to determine and communicate the moral issues and challenges within those specific fields of study, and how to deal with them morally and from a multidimensional South African context. It aims to add scientific, technological and ethical value, locally and globally, by reflecting mainly from the viewpoint of a specific scholars, writing about the most pressing moral issues or challenges raised by problems within their specific field of study. It is written mainly from a qualitative methodological perspective, including autobiographical and participatory views. The co-authors present in respective chapters their research systematically and intersectionally, based on profound theoretical analysis and reasoning. Current research in the basic and implied sciences and technologies requires sound ethical practice based on a defensible moral stance. Moral norms, in our view, are deeply grounded and evolved convictions about justice and injustice, right and wrong, good and bad. It is not about rules. This scholarly book combines the insights and expertise of established South African scholars from different disciplines and backgrounds. The contributors are all deeply committed to the value and validity of science and ethical practice across the moral spectrum. Open and responsible discussions around this topic can lead to the introduction of moral guidelines and regulations to protect the rights of individuals, animals and the environment, while simultaneously facilitating the growth of scientific practice. This collected work, with its very specific and carefully selected grouping of academic fields, aims to innovatively assist in alleviating the shortage of academic publications reflecting on the moral issues in these specific fields.
This article advances a conceptual framework for cyber counterintelligence (FCCI) as a theoretical construct, hopefully useful not only to this field's academic development, but also to sound practice. It is submitted within the context of the sharp increasing targeting of state and non-state actors by adversarial intelligence actors (such other nation states, crime syndicates and competitors). The signature role of cyber counterintelligence (CCI) is precisely the engagement, exploitation and neutralisation of such adversarial actors. CCI has been practised by nation states for well over a decade and has recently also been gaining traction in corporate board rooms and as an academic field. Sound theory is critical to not only CCI's academic evolvement but also to sound practice. The proposed FCCI comprises of eight notional building blocks essential to explaining what CCI is and how it works.
With participatory action and engagement of end users (urban dwellers) playing an important role in the success of smart city initiatives, and the smart city model as a whole [1], free, public Wi-Fi hotspots are a viable option that may be employed to advance this endeavor. As end users become more reliant on the availability of these hotspots for various aspects of their everyday life, however, security becomes a prominent concern as hotspots may not only attract the attention of the end user, but also that of the abuser (cybercriminals). With various stakeholders typically involved in the delivery of smart city Wi-Fi initiatives, the question of who should be held responsible in the event of a cybercrime incurring losses to an end user while making use of the free Wi-Fi becomes of particular interest. As a result, in this chapter, various security aspects relating to smart city Wi-Fi offerings are discussed, striving to provide initial remedial recommendations from both the perspectives of the end user as well as the smart city. Further insight is also provided through a comparative analysis of the approaches taken to deliver free, public Wi-Fi in the cities of Barcelona (Spain), and Geneva (Switzerland).