stakeholders view Myanmar’s lack of existing infrastructure as an opportunity, allowing
Myanmar to “leapfrog” legacy technology and implement cutting edge infrastructure. For
many Myanmar businesses, a desire to deploy modern technology has overshadowed the
importance of cyber-security and data protection policies.
B. Field Assessment Findings
See also field research findings in Chapter 4.3 on Privacy, which are also relevant for
cybersecurity issues.
Cyber Security
Human Rights Implicated: Right to privacy
Low awareness of cybersecurity risk by business: The majority of companies
did not have policies in place to test their systems against threats. Only one
company interviewed carried out ongoing penetration and vulnerability tests to
mitigate risk.
Lack of awareness of cybersecurity risks among users: Users on social media
were observed sharing sensitive personal data including bank statements and
checks for donations. Users also reported being unaware of how to configure
privacy settings in their social media accounts.
Use of pirated applications in mobile shops: Many users also download pirated
applications on their mobile phones at phone shops, unaware of the specific
application permissions the software required or that an application could contain
malware.
Lack of identified Personally Identifiable Information: An independent cybersecurity professional noted that companies in Myanmar have not defined what
constitutes Personally Identifiable Information (PII) (information that can used to
“distinguish or trace” an individual’s identity), or who has the ability to access this
information internally. 434
C. Cybersecurity: Recommendations for ICT Companies
Raise awareness of users about protecting themselves online: Users in Myanmar
generally have a very low level of awareness around cybersecurity, including the use
of passwords or keeping personal information safe. Both government and business
should address the need to raise cybersecurity awareness among users.
Employ the maximum security for user communication: At a minimum, companies
that provide online communications and transactions, such as email, social networking
and shopping, should use industry standard encryption such as ‘https’, which encrypts
traffic between a web browser and the server of the service being accessed,
strengthening the privacy of communications and transactions online. 435
Be prepared for a cyber-attack by developing a response plan. As noted above,
there are currently no laws on cybersecurity, data protection and little in the way of
support from overstretched government resources in terms of supporting smaller or
newer businesses in developing their cybersecurity approach. This could be an
important area of collective action by the larger multinational ICT companies to
434
National Institute of Standards and Technology, “Guide to Protecting the Confidentiality of Personally
Identifiable Information (PII)” (2010).
435 Mike Shema, “Web Security: Why You Should Always Use HTTPS“ Mashable (31 May 2011).
CHAPTER 4.5: CYBER-SECURITY
187
4
4.5