Abstract
In 2014, Denmark launched its first national strategy for cyber resilience of critical infrastructure (CI). The ‘National Cyber and Information Security Strategy’ and its two subsequent successors from 2018 and 2022 follow the Sector Responsibility Principle (SRP). According to the principle, the state distributes the task of achieving and maintaining societal resilience to individual sectors, for example, health, energy supply, or finance, while maintaining central oversight and responsibility for implementation. Denmark is not alone in taking this approach: in fact, all the Nordic countries
have applied some version of SRP. Danish governments have over the last decade taken significant steps to implement and facilitate societal cyber resilience through development of institutions, strategies, legal measures, and public-private partnerships (PPP). That said, Danish governments have gone less far than, for example, Finland’s to take measures to achieve efficacy, and significant weaknesses are still left to be addressed. The article outlines the principles behind SRP and, using mainly Danish examples, demonstrates why implementation of SRP is both legally, organisationally, and echnically difficult but also politically ‘unpleasant’. Resilience is desirable but also a tedious chore. An inherent risk with SRP at both strategic, political level and individual private or public entity level are incentives to strive for legal compliance, rather than operational efficacy and act more according to a ‘sector responsibility avoidance principle’. In that light, the article outlines how the SRP has been implemented in Denmark so far, along with examples of both what drives the effort and challenges to successful SRP implementation.
Publisher
NASK National Research Institute
Reference55 articles.
1. Cyberresiliens, sektorprincip og ansvarsplacering – nordiske erfaringer
2. National strategi for cyber-og informationssikkerhed – Øget professionalisering og mere viden;Regeringen,2014
3. Finansministeriet. (2018). National strategi for cyber-og informationssikkerhed, Finansministeriet. [Online]. Available: http://www.fmn.dk/nyheder/Documents/National-strategi-for-cyber-og-informationssikkerhed-2018.pdf. [Accessed: Aug. 19, 2020].
4. Regeringen. (Dec. 2021). The Danish National Strategy for Cyber and Information Security, Regeringen. [Online]. Available: https://www.cfcs.dk/globalassets/cfcs/dokumenter/2022/ncis_2022-2024_en.pdf. [Accessed: Jan. 8, 2023].
5. North Atlantic Treaty Organization (NATO). (2020). NATO Defence Planning Capability Review 2019/2020 Denmark C-M (2020) 0026 (DK-Overview), NATO. [Online]. Available: https://www.fmn.dk/globalassets/fmn/dokumenter/aarsrapporter/nato/-nato-defence-planning-capability-review-2019-2020-.pdf. [Accessed: Feb. 6, 2023].