3/4/22, 1:38 PM Managing a digital revolution: cyber security capacity building in Myanmar - Routledge Companion to Global Cyber-Security Strategy ministries of agencies and taking in very little input from private companies or critical infrastructure owners. As a consequence, questions can be raised regarding the applicability' of the strategy when it comes into force. The noninclusion of the very companies that will be tasked with providing cyber security in developing the strategy can be seen as troubling. The lack of an overarching strategy in turn fragments the approach by various ministries and agencies, as a cross-sectorial issue is met by isolated initiatives. As ministries and agencies operate within their respective silos when it comes to detecting and responding to various risks and threats. As Myanmar has rapidly digitalized, the frequency of cyber incidents is growing rapidly and the fragmented approach is hampering the ability to manage it sufficiently. This is further complicated by the byzantine bureaucratic processes and structures that define much of the governmental work. For the issue of cyber security providing meaningful legislation and regulations is for instance dependent on the cooperation between the Ministry of Transport and Communication and the Ministry of Planning and Finance, a cooperation which so far has been limited and strained. Providing a clear overarching direction for these various approaches and conflicts of interests necessitates a cyber strategy tailored to the situation in Myanmar, providing clear incentives, benchmarks, and divisions of responsibility. The lack of top-down political leadership is further reflected in the absence of awareness about critical infrastructures and their importance for modern societies. The very concept of critical infrastructures is not widely established, and subsequently neither is the cyber security of said infrastructures. The lacking mapping, categorization, and understanding of different infrastructures and the role they play in society limits the ability to secure them in a sufficient manner. As there does not exist any legal definition of what a critical infrastructure is, the framework for mapping and categorizing them is non-existent. As a first step creating a legal framework for what is considered critical infrastructure, as well as giving the responsibility of protecting said infrastructures to an institution, would be a starting point to improve critical infrastructure protection in Myanmar. The i i b f b i id t t ti i tit ti di f https://ebrary.net/173520/political_science/managing_digital_revolution_cyber_security_capacity_building_myanmar#aftercont t t th t 9/19

Select target paragraph3