3/4/22, 1:38 PM Managing a digital revolution: cyber security capacity building in Myanmar - Routledge Companion to Global Cyber-Security Strategy websites that residents want to access. Up until very recently Myanmar was served by a single submarine cable, creating both large vulnerabilities in the infrastructure and a slow connection (Telegeography, 2020). In general Myanmar’s cyber security “maturity” is at the start-up level, very few actions, other than some initial discussions on this topic, have been taken. There are however some indications on clear progress towards a more formative level in the education sector, the legal and regulatory framework, and on establishing better standards. Nevertheless, Myanmar remains among the countries in the Asia-Pacific region with the least attention to cyber security. Reports have pointed to large issues and gaps in the approach to the issue. Beyond the military aspect of cyber security Myanmar is among the lowest scoring countries in all categories in a comparison between Asian countries, highlighting a long list of issues that needs to be addressed (ASPI, 2017). A shortage in skilled labor is one of the main issues, as the 1CT sector is regulated and run by a small group of public employees tasked with managing the rapid transition. The digital transformation, coupled with the democratic transition, is dependent on the development of a long list of technical standards and regulation, as well as reinventing the educational system to meet new demands. On top of this, the interconnected nature of the ICT sector, and the fact that Myanmar has already become entangled with foreign actors after years of isolation, points to the scope of the challenge Myanmar is facing to make the transition run smoothly (Myanmar Centre for Responsible Business, 2015). Moreover, while the government drafted a master plan for telecommunications in 2015 its implementation has been severely postponed and uneven, undermining the efforts at creating a sound political environment. This is mirrored in the regulatory sector wherein the existing rules and regulations are aimed at control and censorship, and not on cybercrime and related issues (ASPI, 2017). A subdivision of the political and regulatory capacity is a country’s participation in international foras and programs. This is an area of particular importance in cyberspace, where the government challenges are often global in nature. One of the main ways for countries with less-developed cyber security maturity is to i ti b t C t E R https://ebrary.net/173520/political_science/managing_digital_revolution_cyber_security_capacity_building_myanmar#aftercont T (CERT ) 14/19

Select target paragraph3