stakeholders view Myanmar’s lack of existing infrastructure as an opportunity, allowing Myanmar to “leapfrog” legacy technology and implement cutting edge infrastructure. For many Myanmar businesses, a desire to deploy modern technology has overshadowed the importance of cyber-security and data protection policies. B. Field Assessment Findings See also field research findings in Chapter 4.3 on Privacy, which are also relevant for cybersecurity issues. Cyber Security Human Rights Implicated: Right to privacy     Low awareness of cybersecurity risk by business: The majority of companies did not have policies in place to test their systems against threats. Only one company interviewed carried out ongoing penetration and vulnerability tests to mitigate risk. Lack of awareness of cybersecurity risks among users: Users on social media were observed sharing sensitive personal data including bank statements and checks for donations. Users also reported being unaware of how to configure privacy settings in their social media accounts. Use of pirated applications in mobile shops: Many users also download pirated applications on their mobile phones at phone shops, unaware of the specific application permissions the software required or that an application could contain malware. Lack of identified Personally Identifiable Information: An independent cybersecurity professional noted that companies in Myanmar have not defined what constitutes Personally Identifiable Information (PII) (information that can used to “distinguish or trace” an individual’s identity), or who has the ability to access this information internally. 434 C. Cybersecurity: Recommendations for ICT Companies    Raise awareness of users about protecting themselves online: Users in Myanmar generally have a very low level of awareness around cybersecurity, including the use of passwords or keeping personal information safe. Both government and business should address the need to raise cybersecurity awareness among users. Employ the maximum security for user communication: At a minimum, companies that provide online communications and transactions, such as email, social networking and shopping, should use industry standard encryption such as ‘https’, which encrypts traffic between a web browser and the server of the service being accessed, strengthening the privacy of communications and transactions online. 435 Be prepared for a cyber-attack by developing a response plan. As noted above, there are currently no laws on cybersecurity, data protection and little in the way of support from overstretched government resources in terms of supporting smaller or newer businesses in developing their cybersecurity approach. This could be an important area of collective action by the larger multinational ICT companies to 434 National Institute of Standards and Technology, “Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)” (2010). 435 Mike Shema, “Web Security: Why You Should Always Use HTTPS“ Mashable (31 May 2011). CHAPTER 4.5: CYBER-SECURITY 187 4 4.5

Select target paragraph3