Information about you
Contact details and publishing consent:
Please select one item
Radio button:
Radio button:
Organisation/Group name*
East Ayrshire Council
Organisation/Group address**
Council HQ
London Road
London Road
Organisation/Group postcode**
Please select one item
Radio button:
Community organisation
Radio button:
Third sector / equality organisation
Radio button:
Private sector organisation
Radio button:
Representative body for professionals
Radio button:
Local government
Radio button:
Community Planning Partnership
Radio button:
Public Body, including Executive Agencies, NDPBs, NHS etc
Radio button:
Academic or Research Institute
Radio button:
Other – please state…
Please select one item
Radio button:
Publish this response
Radio button:
Do not publish this response
Radio button:
Your name along with your response
Radio button:
Just your response (anonymous)
Radio button:
Please do not publish my response at all
Consultation Questions
1. Are the guiding principles right for this strategy?
Please select one item
Radio button:
Radio button:
Are there any other principles that should be considered when continuing to develop this strategy?
The principles support vision of shared responsibility, from national leadership through to shared responsibility and the principle of all users of technology working together to improve on a safer on-line environment.
It is important that “education” remains at the forefront of these principles: leaders; managers; educators; students; our young people; and citizens who use and engage with technology must be fully aware of the risks - and their responsibilities – when connected to the cyber world.
Without education and understanding of the risks in a personal and business environment, it may be difficult for the strategy to succeed.
It is important that “education” remains at the forefront of these principles: leaders; managers; educators; students; our young people; and citizens who use and engage with technology must be fully aware of the risks - and their responsibilities – when connected to the cyber world.
Without education and understanding of the risks in a personal and business environment, it may be difficult for the strategy to succeed.
2. Do you agree with the vision?
Please select one item
Radio button:
Radio button:
I would agree with the vision however it could be seen as very business-orientated and therefore may not resonate with citizens, their personal use of the internet, and the responsibility they have to use the internet safely and securely whilst protecting their own data from being compromised.
3. Do you agree with the three strategic outcomes?
Please select one item
Radio button:
Radio button:
Are there additional outcomes that should be considered? If yes, what are they and why?
The strategic outcomes address the use of on-line technologies in both a personal and business environment; the strategic outcomes should be delivered through a comprehensive education programme.
4. Do you think these are the right objectives to focus on?
Please select one item
Radio button:
Radio button:
Are there additional objectives that should be considered?
The objectives stated are adequate however I would question the view that “none of these objectives is more important than the other” – the second objective is key … raising awareness and communication, being more aware of the potential risks and becoming more cyber aware, will be delivered through an effective education programme.
Raising awareness of cybercrime should ultimately support a reduction in such instances occurring and therefore will be become less of a burden to business; public bodies would also benefit through a reduction in fines for data breaches.
The strategy should be developed to raise awareness of cyber security and best practice methodologies. The strategy should not be overly prescriptive or designed as a “one solution to fit all”; high level controls can either compel organisations to spend large amounts of money unnecessarily (particularly in the current financial climate) or to undertake technical works that have a detrimental effect on service delivery.
Raising awareness of cybercrime should ultimately support a reduction in such instances occurring and therefore will be become less of a burden to business; public bodies would also benefit through a reduction in fines for data breaches.
The strategy should be developed to raise awareness of cyber security and best practice methodologies. The strategy should not be overly prescriptive or designed as a “one solution to fit all”; high level controls can either compel organisations to spend large amounts of money unnecessarily (particularly in the current financial climate) or to undertake technical works that have a detrimental effect on service delivery.
5. Do you agree with the main areas of focus for effective leadership and promoting collaboration?
Please select one item
Radio button:
Radio button:
Are there any other areas that should be considered?
Public bodies are already very aware of the need for information and data security, and are compelled to protect personal sensitive data to meet the obligations of the Data Protection Act. The notion that the Scottish Government will “hold public bodies to account” (particularly without legislation) could be seen as another level of bureaucracy that adds very little to the need for cyber resilience.
The Scottish Government can have a very important role in terms of raising the profile of, and leading the promotion on, the need for enhanced cyber resilience across on-line services; however it should do this as a practitioner where cyber resilience is demonstrated as being core to the evolution of on-line service delivery, and as a facilitator to ensure best practice methodologies are available to all public bodies.
The Scottish Government can have a very important role in terms of raising the profile of, and leading the promotion on, the need for enhanced cyber resilience across on-line services; however it should do this as a practitioner where cyber resilience is demonstrated as being core to the evolution of on-line service delivery, and as a facilitator to ensure best practice methodologies are available to all public bodies.
6. Do you agree with the main areas of focus for raising awareness and ensuring effective communication?
Please select one item
Radio button:
Radio button:
Are there any other areas that should be considered?
Educating businesses and citizens on the need for cyber safety is absolutely key, therefore any, every, and all methods to support cyber awareness should be encouraged across organisations and within citizens’ personal environment.
Most businesses will be aware of where to obtain information and support in relation to cyber security and perhaps therefore there is a great need to make information more generally available for the wider community; citizens need to be more aware of their personal risks and responsibilities to protect themselves from, for example, fraud or identity theft.
Most businesses will be aware of where to obtain information and support in relation to cyber security and perhaps therefore there is a great need to make information more generally available for the wider community; citizens need to be more aware of their personal risks and responsibilities to protect themselves from, for example, fraud or identity theft.
7. Do you agree with the main areas of focus for developing education and skills in cyber resilience?
Please select one item
Radio button:
Radio button:
Are there any other areas that should be considered?
Our young learners are already an on-line population, using the internet to communicate with friends and family, for research as part of their studies, and to participate in gaming sessions. Educating our young learners in how to use an on-line environment safely and securely is key, and ultimately will lead to a population who are more digitally connected to meet the need for technical expertise in to the future.
8. Do you agree with the main areas of focus for strengthening research and innovation?
Please select one item
Radio button:
Radio button:
Are there any other areas that should be considered?
Whilst it is important to quantify the cost of cybercrime, the focus should equally be on increasing education awareness and the need for cyber resilience; through time this should reduce cost associated with cybercrime – both directly as a result of criminality, and indirectly as a result of fines imposed on public bodies by the Information Commissioners Office in relation to data breaches.
9. Are there actions that will help us achieve making Scotland and its people more cyber resilient?
Do you have suggestions of any actions that will help us to make Scotland more cyber resilient?
Education is key to raising the profile of cyber awareness. It is important that citizens and businesses are encouraged to maximise the benefits of technology and on-line services, therefore the strategy should be implemented with a measured, balanced, and common sense approach, where it is considered an enabler to better safety and security rather than a barrier to the digital agenda.
10. Do you think the monitoring and evaluating arrangements are sufficient?
Please select one item
Radio button:
Radio button:
If not, what arrangements would you like to see?
Action plans and milestones need to be measured and realistic, otherwise they will be ineffectual and public bodies may not be keen to support a national implementation. It is important to remember that technology changes are rapid and therefore a positive outcome of annual evaluation should be to ensure learning and effective good practice is shared.
11. Have you ever experienced cyber crime ?
Please select one item
Radio button:
Radio button:
12. Would you be willing to share your experiences with us?
Please select one item
Radio button:
Radio button: