lagen.nu
Be Aware, Be Secure. Synthesis of the results of the first European Cyber Security Month

Be Aware, Be Secure. Synthesis of the results of the first European Cyber Security Month

Utgivare
Europeiska unionens cybersäkerhetsbyrå
Antagen
2012-12-17
Språk
engelska
Källa
www.enisa.europa.eu
Endast på engelskaEuropeiska unionens cybersäkerhetsbyrå har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens cybersäkerhetsbyrå.

SyntheSiS of the reSultS of the firSt EuropEan CybEr SECurity Month

Acknowledgements

eniSA wishes to acknowledge and thank all Member States and the european Commission Directorate-General for Communications networks, Content and technology, which contributed to this document with informal reviews, valuable insights, observations and suggestions. the content would be incomplete and incorrect without their help.

Author of the report: isabella Santa (eniSA)

About eniSA

the european network and information

Contact details

Security Agency (eniSA) is a centre of network and information security expertise for contacting eniSA or for general enquiries for the eu, its member states, the private on Awareness raising activities please use the sector and europe’s citizens. eniSA works following details: with these groups to develop advice and e-mail: opsec@enisa.europa.eu recommendations on good practice in internet: http://www.enisa.europa.eu information security. it assists eu member states in implementing relevant eu legislation for questions related to the european Cyber and works to improve the resilience of Security Month, please use the following europe’s critical information infrastructure details: and networks. eniSA seeks to enhance e-mail: awareness@enisa.europa.eu existing expertise in eu member states by supporting the development of cross-border communities committed to improving network and information security throughout the eu. More information about eniSA and its work can be found at www.enisa.europa.eu.

LegaL notiCe notice must be taken that this publication represents the views and interpretations of the authors and editors, unless stated otherwise. this publication should not be construed to be a legal action of eniSA or the eniSA bodies unless adopted pursuant to the eniSA regulation (eC) no 460/2004 as lastly amended by regulation (eu) no 580/2011. this publication does not necessarily represent state-of the-art and eniSA may update it from time to time.

third-party sources are quoted as appropriate. eniSA is not responsible for the content of the external sources including external websites referenced in this publication.

this publication is intended for information purposes only. it must be accessible free of charge. neither eniSA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication.

reproduction is authorised provided the source is acknowledged. All images © eniSA, except cover image © David Malan/Getty images; and page 5 image © iStockphoto.com/Andreas Kermann

© european network and information Security Agency (eniSA), 2012

1 executive summary

for the first time, last october, a european the report is structured into four main parts: Cyber Security Month took place as a pilot the overview of the security-related weeks project across europe. this was as foreseen organised at national level across europe; in the eu–uSA Summit final report and in the roadmap produced by the awareness-raising ‣ the organisational insights of delivering sub-group of the eu–uSA Working Group on eCSM initiatives and related achievements; Cyber-security and Cyber-crime in December ‣ the role played by eniSA; 2011. this project was supported by eniSA ‣ the lessons learned. and the european Commission. the first part of the report is a global view of in this first pilot project, the Czech Republic, the eCSM pilot project. the main findings are: Luxembourg, norway, Portugal, Romania, Slovenia, Spain and the United Kingdom ‣ the majority of the Member States hold a participated in various activities and events security week or weeks; throughout october, to raise awareness of ‣ the proportion of campaigns encompassing cyber security. general users versus those targeting business users is almost the same; latvia, together with the Council of the ‣ a wide variety of key messages are european union, officially supported the promoted across the different european project. countries; ‣ the largest number of events were the objectives of the european Cyber Security organised in the fourth week of october; Month (eCSM) were to promote cyber security ‣ all supporting material and communications awareness among citizens, to modify their were produced in the official language of the perception of cyber threats and to provide countries concerned; updated security information through ‣ printed materials (38 %) and physical events education, good practices and competitions. A (25 %) featured in many cases; diverse range of activities and events targeting ‣ all Member States used a variety of different audiences was held throughout techniques that were fun, exciting and europe. these included: tV and daily radio motivating; advertisements; social media campaigns ‣ the private sector was involved in six pilot and quizzes with prizes; news articles; countries; conferences; student fairs; roadshows; and ‣ the wide variety of delivery channels round tables. used suggests the potential value of a multifaceted approach that could match each pilot country decided upon the scope different messages to different media and number of activities and events to be and opportunities across all sectors and organised. eniSA provided guidance and countries; expertise on how to organise information ‣ websites are the most prominent channels security campaigns, together with tips and of communication used, together with the advice on how to be safe online. Moreover, distribution of giveaways (seven out of eight the Agency provided promotional material to pilot countries); the participating countries to help promote ‣ the Member States adopted different awareness. this report provides an overview methods to assess the effectiveness of of the activities organised by each country and eCSM activities — generally, the data presents a synthesis of findings on the basis of gathered can be used to identify very similar evaluation and performance information either key performance indicators. provided by the pilot countries or gathered by eniSA itself. An overview is provided by the second part provides detailed information aggregating data at european level. Data is on the activities and events organised by also displayed at national level. each country. Quantitative and qualitative information that was captured by the participating countries while measuring the achievements of the eCSM initiatives is reported. A summary table is included for each country to help the reader to view the achievements at national level.

‣ Better define the specific audience that is targeted by the awareness initiative in order to tailor the message content to the target group’s knowledge or technical aptitude using the most effective communication channels. ‣ Produce all relevant material in at least all the official languages of participating countries. ‣ Make press releases available in at least all the official languages of participating countries. ‣ Produce video clips in different formats in order to allow their use for tV adverts. ‣ Make sure there are enough staff available during events. Particular attention should be paid to the number of staff available during weekends compared to weekdays. ‣ Produce giveaways according to the season of distribution (i.e. t-shirts distributed in cold weather did not appear to be a good idea). ‣ involve an increased number of private the third part describes the role played by companies to increase impact. eniSA as coordinator. the Agency was the ‣ Deal with changes in plans and keep hub for all pilot countries, not only supporting interested parties informed. the eCSM, together with the european ‣ ensure media coverage by planning possible Commission, but also providing subject matter interviews in advance. Be prepared for lastexpertise and material which helped to get the minute cancellations. message out. the analysis carried out in the report lead to the fourth part shows the lessons learned the conclusion that the first european Cyber to enable readers to identify key challenges, Security Month pilot project was successful, issues and solutions, making any future eCSM especially because of the engagement, activity more effective. the main findings are existing good practices and experience of the as follows. participating countries.

2 introduction

Citizens are increasingly relying on the ‣ conferences and workshops in norway, internet in their everyday lives for banking, Portugal and Spain; shopping, education and a number of other ‣ media and social media campaigns in services. it is, therefore, important that they norway and Slovenia; are able to use the internet in a secure and ‣ non-governmental organization (nGo) round confident manner. tables in the Czech republic; ‣ competitions and quizzes in luxembourg, Making the internet a better place for all norway and Slovenia; citizens is a shared responsibility, at both roadshows in the united Kingdom. ‣ european and global level. the eu Cyber Security Strategy, due out in the near future, each country built on its own existing activities will set out just how important this is, with and experience for maximum impact. concrete proposals to improve digital security. Moreover, the european union has been working with the uSA, and at last year’s eu– 2.1 Purpose

uSA Summit, several steps were agreed to help make the online world secure, on both the purpose of this document is to consolidate sides of the Atlantic. the evaluations of the eCSM activities completed by the pilot countries in addition the european Cyber Security Month is an to providing an analysis of the achievements effective instrument for raising awareness of the initiatives organised at national level about network and information Security (niS). across europe.

the main objectives of the european Cyber Aiming to provide an integrated perspective Security Month are: across all types of evaluations, the report highlights the results and impact of the eCSM ‣ to generate general awareness about activities, discusses the lessons learned and network and information Security; draws attention to related issues with a view ‣ to promote safer use of the internet for all to further enhancing the eCSM’s development users; effectiveness. ‣ to build a strong track record to raise awareness through the eCSM; ‣ to involve relevant stakeholders; ‣ to increase national media interest through the european and international dimension of the project; ‣ to enhance attention and interest with regard to information security through political and media coordination.

this year, eight countries participated in the first european Cyber Security Month: the Czech republic, luxembourg, norway, Portugal, romania, Slovenia, Spain and the united Kingdom. these countries replied positively either to a call for expressions of interest to organise ‘Security week’ pilot projects sent to all members of the awareness-raising sub-group of the eu–uSA Working Group on Cyber-security and Cybercrime, or to a communication campaign on the project initiated by eniSA.

over the course of the month of october, a range of local activities and events were held across europe to raise the security awareness of specific target groups. these included, among others:

in addition, the report concentrates on the in the context of the CiiP action plan, the

learning issues which emerge repeatedly european Forum for Member States

in the countries’ evaluations as areas that discussed and developed european principles

merit further attention. Among other aims, and guidelines for the resilience and stability

the report is intended to provide a basis of the internet (‘the principles’) ( ). in

for discussion by the Member States, the particular, the principles state that:

european Commission and eniSA on how Public authorities, with the support of other

the eCSM can best be organised in the years stakeholders, as appropriate, should strive

to come. All countries are having to face up to educate and raise awareness on the risks

to a similar challenge, to a greater or lesser associated with Internet-related activities.

extent, namely how to engage citizens and

change their information security behaviour. It is recognised that certain categories of

stakeholders are not always in a position to properly understand the risks — both for

2.2 Rationale and policy context

themselves and for the stability and resilience of the Internet as a whole — associated with their

this section provides selected information and Internet-related activities. facts that motivate and explain the decision

to organise the first european Cyber Security

Without prejudice to the competences of

Month. the main aims of this month include:

Member States in the area of culture and education, and taking in the utmost account the

‣ generating general awareness about

principle of subsidiarity, a shared EU approach

network and information Security;

to such activities, with a view to achieve a global

‣ promoting safer use of the internet for all approach, should be sought. users;

‣ building a strong track record to raise

The private sector has an important role to play

awareness through the eCSM;

in supporting public authorities and in providing

‣ involving relevant stakeholders;

clear information to all stakeholders, concerning

‣ increasing national media interest through

the potential risks of their behaviours for the

the european and international dimension of stability and resilience of the Internet, e.g. the project; unwillingly propagating virus and other malware, ‣ enhancing attention and interest with regard having their computers enrolled in a Botnet, etc. to information security through political and

media coordination.

Strengthening education efforts in this area

1 will also have the benefit of producing skilled Since 2005, the Commission ( ) has highlighted

experts in the needed ICT fields. Education and

the urgent need to coordinate efforts to build

awareness-raising will also strengthen the

the trust and confidence of stakeholders in

preventive abilities of stakeholders, which in turn

electronic communications and services. to

will help to avoid recourse to ex post or overly

this end a strategy for a secure information 6 2 invasive security measures. ( ) society ( ) was adopted in 2006.

on these lines, the Digital Agenda for europe on 30 March 2009, the Commission adopted 7 (DAe) ( ), adopted in May 2010, and the a communication on Critical information 8 related Council conclusions ( ) highlighted the infrastructure Protection (CiiP) — ‘Protecting shared understanding that trust and security europe from large-scale cyber attacks are fundamental preconditions for the wide and disruptions: enhancing preparedness, 3 uptake of iCt and therefore for achieving the security and resilience’ ( ), setting out a plan objectives of the ‘smart growth’ dimension (the ‘CiiP action plan’) to strengthen the 9 of the europe 2020 strategy ( ). the DAe security and resilience of vital information emphasises the need for all stakeholders to and communication technology (iCt) join forces in a holistic effort to ensure the infrastructures. the aim was to stimulate security and resilience of iCt infrastructures and support the development of a high level by focusing on prevention, preparedness and of preparedness, security and resilience

capabilities at both national and european

awareness, as well as to develop effective

2.5 Methodology

and coordinated mechanisms to respond to new and increasingly sophisticated forms of eniSA gathered information with regard to cyber attacks and cyber crime. this approach Member States’ eCSM pilot organisations and ensures that both the preventive and the achievements in two different stages: in the reactive dimensions of the challenge are duly planning phase during Q1–Q2 2012; and in the taken into account. evaluation phase after 31 october 2012.

these documents provide the rationale and eniSA developed templates that focused upon policy context for discussion and cooperation gathering details about security-related weeks with the Member States and international organised at national level across europe. organisations and, where appropriate, with 10 eight Member States were targeted ( ) and all private sector organisations with the objective of them responded. of assessing the feasibility of organising a security month in europe, possibly in the inventory form aimed at extracting coordination with the united States. pertinent information first on the activities and events planned and then on the results finally, the suggested guidelines foresee the obtained. eniSA participated in three eCSM full use of eniSA, as well as other bodies pilot projects gathering supplementary (e.g. the Member States, the Commission information. and/or industry), to map the principles into concrete and operational activities such as the All information was compiled and then organisation of the eCSM. quality checked with the relevant ministries and governmental agencies involved in the 2.3 Scope organisation of the eCSM pilot. in some cases they were supplemented by additional the scope of this report is for eniSA to: material, interviews and research carried out centrally by eniSA. ‣ provide an overview of the activities organised by each pilot country; Data has been aggregated by combining ‣ present a synthesis of findings on the basis data elements from different sources to of evaluation and performance information; provide insights and identify patterns in the ‣ highlight the results and impact of the organisation of security events across europe eCSM activities; and the behaviour of the general public. ‣ present the lessons learned; ‣ draw attention to issues with a view to further enhancing the eCSM’s development effectiveness.

2.4 target audience

this document is intended for organisations, either public or private, which supported the eCSM or intend to do so in the future, as well as it security managers, professionals and (10) the inventory worksheet template was sent to the eCSM any other target group who attended events participating countries: the Czech republic, luxembourg, and conferences organised across europe norway, Portugal, romania, Slovenia, Spain and the united during the month of october 2012. Kingdom.

3 the european overview

following this call, six countries responded

3.1 eCSM pilot projects

positively: luxembourg, norway, Portugal,

Slovenia, Spain and the united Kingdom. the All eCSM pilot countries were asked to provide Czech republic and romania joined at a later evaluation and performance information stage following a communication campaign on regarding any event or activity organised at the project, initiated by the Agency. national level to raise citizens’ information security awareness during the month of these eight countries can be divided between october 2012. geographical zones as follows: 25 % in northern europe, 50 % in central europe and

3.2 Synthesis of findings 25 % in southern europe.

this year a total of eight countries participated eniSA required either a government/ in the first ever european Cyber Security public body of a country or a public–private Month (figure 1). partnership to organise activities and events to last for at least 1 week. FigURe 1: eURoPean oveRview

each country decided upon the scope and number of activities and events to be organised by building on its own existing activities and experience for maximum Pilot countries Non - pilot countries impact. the experience in organising such 73 % 27 % events as well as the ‘digital divide’ between people in different countries varied from one pilot project to another. the majority of the countries had organised security awareness events in the past. overall, 37.5 % of the

participating countries had run security awareness initiatives before 2008.

overall, 37.5 % of the participating countries organised activities for the entire month, 25 %

for more than 1 week and the others (37.5 %) held events for 1 week.

over the course of the month of october, a range of local activities and events were held on 20 January 2012 a call for expressions across the eight participating countries: 27 of interest to organise ‘Security week’ pilot conferences and workshops, two fair stands, projects in the context of the eCSM was sent seven lectures in schools and five roadshows. to all members of the awareness-raising the majority of countries (62.5 %) organised sub-group of the eu–uSA Working Group on social media and online campaigns including Cyber-security and Cyber-crime, as well as to competitions. the representative of the eeA countries. the countries were asked to organise events to eniSA provided guidance and expertise raise citizens’ information security awareness on how to organise information security at national level and eventually to be deployed campaigns, together with tips and advice regionally. on how to be safe online. Moreover, the Agency provided promotional material to the participating countries to help promote awareness.

the participation of people and the media coverage in all countries was very high.

3.2.1 Participating countries one further country and an organisation ( ) officially supported the eCSM by reaching the following countries participated in the and educating citizens, employees and eCSM: communities through events, activities and/or other campaign distribution methods: ‣ Czech republic ‣ luxembourg ‣ latvia ‣ norway ‣ Council of the european union. ‣ Portugal ‣ romania no data was collected and/or analysed in ‣ Slovenia reference to any of the initiatives organised by ‣ Spain the eCSM champions. ‣ united Kingdom. (11) hereafter ‘champions’.

3.2.2 2012 events calendar

Private sector Country Event type Target group Dates involved (Y/N)

Czech Republic Round table Professionals; NGOs; politicians; 22–26 October N public administration; media; industry

Online and media campaign General public

Luxembourg Fair stand General public 13–21 October Y

Norway Conference; seminars; radio Citizens; SMEs All month Y advert; online and social media campaign

Portugal Conference; workshop Professionals 1–4 October Y

Romania Conference Professionals; government All month Y institutions

Online and social media General public campaign

Slovenia TV advert; social media General public 17–31 October N campaign

Fair stand Students

Spain Conference Professionals All month Y

Lecture Children; parents; teachers; schools; adults; teenagers

Social media campaign General public

United Kingdom Roadshow; lecture; online General public 22–26 October Y campaign

3.2.3 goals and objectives of the pilot presented here are those provided by the pilot projects countries, so the groups are not distinctive):

All over the eu, security events were ‣ adults organised aimed at informing citizens about ‣ children the importance of information security and ‣ citizens highlighting the simple steps people can ‣ government institutions take to protect their data, whether personal, ‣ industry stakeholders financial or professional. the main goals and ‣ internet hotlines objectives reported were raising awareness, ‣ it civil servants changing behaviour and providing resources ‣ it professionals (e.g. it managers, chief to all citizens regarding how to protect information officers, security engineers) themselves online. ‣ media ‣ non-governmental organisations (nGos) ‣ parents

3.2.4 target audience(s)

‣ politicians ‣ public administrations All countries, with the exception of ‣ schools Portugal, reported events organised for ‘all’, ‘individuals’, ‘citizens’ or ‘the general public’. ‣ small and medium enterprises (SMes) ‣ students only a few reported having run a campaign for ‣ teachers a very specific target group, such as children, ‣ teenagers. teachers, parents, SMes etc.

examples of groups that were targeted by Given the clear overlap between some of the reported groups, it is useful to group similar information security events across europe are 12 audiences into three broader categories — listed below ( ) (note that the specific names general users, young people and business 12 users — as shown in table 2. ( ) the information is listed in alphabetical order.

Main category Target group

General users Adults

Citizens

Parents

Schools

Teachers

Young people Children

Students

Teenagers

Business users Government institutions

industry stakeholders

Internet hotlines

IT civil servants

IT professionals

Media

NGOs

Politicians

Public administrations

SMEs

the proportion of campaigns encompassing that citizens had with regard to specific general users versus those targeting business activities. Creating a meaningful and possibly users is almost the same. this is due to the inspiring phrase was shown to be good numerous events targeting SMes and it practice across europe. professionals. By contrast, the number of security events specifically for young people is 3.2.7 Pilot projects’ timeframe about half the number dedicated to general users. Graph 1 provides an overview of the spread of security pilot projects throughout october, as it is worthwhile emphasising the need to organised across europe. better define the specific audience that is targeted by the awareness initiative in order graph 1: Weeks When eCsM seCuriTy evenTs to tailor the message content to the target Were organised group’s knowledge or technical aptitude using the most effective communication channels. this will maximise the appeal of the message and persuade the audience to take action, especially if the message fits with the target 8 group’s interests and needs. 7

3.2.5 Subject matter

6 the analysis carried out by eniSA reported 5 that the security topics most often addressed by the national security events across europe 4 were: 3 Number of countries ‣ internet safety and security 2 ‣ identity theft ‣ data protection/privacy 1 ‣ passwords 0 ‣ online fraud (scams, phishing) Week 1 Week 2 Week 3 Week 4 Week 5 ‣ cyber crime ‣ cyber bullying Czech Republic Portugal Slovenia ‣ social networks ‣ wireless access Luxembourg Romania United Kingdom ‣ online child protection Norway Spain ‣ cyber security ‣ information security ‣ cyber threats ‣ cloud security.

Data available does not allow drawing Graph 1 shows that the largest number of conclusions with respect to the prioritisation eCSM activities were organised in the fourth of the above mentioned security topics. week of october, followed by the third week, however, it appears that some of these and then an equal number of activities were topics were more dominant than others, e.g. organised in the remaining weeks. this data internet safety and security, cyber security, explains that the pick in media coverage online fraud, cyber crime and cyber bullying. occurred in the third and fourth week of it is clear that most of the themes identified october. had potential relevance to eu citizens in the context of their business and personal lives. it should be noted that in order to successfully attract the constant attention of the media and the general public, it is important to

3.2.6 type of messages used

spread future eCSM activities evenly across the chosen month in order to have awareness it has not been possible to categorise the activities running continuously for a full messages used in the european countries, month across europe. this approach would mainly because of the variety of styles and facilitate as well the role played by eniSA as languages used. coordinator of the organisation of the eCSM, especially in light of the participation of an Data showed that slogans had been created increased number of Member States, which to better promote security events in some appears to be a growing trend. countries and increase the level of recognition

3.2.8 Languages ‣ newsletters

‣ roadshows to create the greatest impact on citizens, ‣ e-learning. materials were available in the official language(s) of the countries concerned. to the wide variety of delivery channels this end, eniSA produced guidance material, demonstrates that the participating countries as well as the eCSM logo, in all 23 official choose to deploy multiple channels. it also languages to properly engage stakeholders suggests the potential value of a multifaceted and citizens. approach that could match different messages to different media and opportunities. Moreover, only two pilot countries used english as well: data from luxembourg, Slovenia, Spain Portugal and romania. and the united Kingdom demonstrates that whenever competitions and draws were 3.2.9 Delivery channels organised or giveaways were distributed, citizens were more incline to participate in eniSA identified 16 delivery channels that any eCSM activity and instinctively felt more 13 comfortable to receive practical advice on were used to some degree across europe ( ): anything from how updating antivirus software ‣ websites to what parental control is. ‣ giveaways (e.g. key-chains, pens, t-shirts, carrier bags, leD torches and folding flying Different colour codes have been used to discs) group the different delivery channels into ‣ conferences, seminars, workshops, broader categories, based upon the type of lectures, round tables message involved: physical events (yellow), ‣ magazines, brochures, booklets and other electronic messages (light green), printed printed material materials (light blue), display materials (pink) ‣ stickers and media and multimedia products (green). ‣ flyers, leaflets ‣ posters figure 2 shows the broad percentages for ‣ social networks the delivery categories that were identified. ‣ video clips Printed materials (38 %) and physical events ‣ newspaper articles, media campaigns (25 %) feature in many cases. ‣ competitions, draws, tests, quizzes ‣ exhibitions, expos According to the analysis carried out by eniSA, ‣ tV, radio six countries reported using just four delivery methods and two countries used five. (13) the information is listed in order of popularity.

Media and multimedia products Display materials 19 % 6 % Printed materials Physical events 38 % 25 %

Electronic messages 12 %

the analysis carried out by eniSA reported gRaPh 2: DeLiveRy ChanneLS

that, of the delivery channels used to make

citizens aware of security issues, websites,

giveaways and conferences/seminars/

workshops, etc. were the most common, as

illustrated in Graph 2. 8

in particular, the majority of the pilot countries 7

(seven) used a website as the main channel 6 of communication with their target group.

the website is the backbone of ongoing 5 communications and is useful for getting

feedback, following which adjustments can be 4

made to the various approaches. Moreover, 3 a website can present content for multiple Number of countries

audiences, is easy to update and maintain, 2 can be easily linked to other information and

can be integrated with more than one delivery 1

channel, for example social media, webcasts 0 and e-mail. ys s s s ers ws wa ork xpos adio ea Stick Poster TV/r Websites, as a communication vehicle, scored Websites Giv wsletter E-learning ound tables ers/leaflets Video clips Ne Roadsho the same as the distribution of giveaways. this es/r Fly s/tests/quizzes Social netw aw Exhibitions/e is a very effective way to attract and interest

people. shops/lectur ork Competition/dr finally, the organisation of events comes s/w wpaper articles/media campaigns Ne very close. usually, conferences, seminars es/booklets and other printed material

and meetings create high impact and can ochur

reach a very wide range of audiences by the erences/seminar careful selection of venues and topics. the Conf experience of luxembourg, Spain and the Magazines/br

united Kingdom, for example, demonstrates

how successful and effective physical events

could be due to the interactive element of the

channel.

3.2.11 Costs 3.2.10 techniques

eniSA did not gather any information on either in general, all Member States used a variety the fixed or variable costs connected to the of techniques which were fun, exciting and organisation of national awareness initiatives motivating in order to catch the attention and across europe. this is because data either stimulate the public they were aimed to. Ways was not available or not for public distribution. used to make information security events

interesting included: in any case, it should be considered that costs

could vary greatly from one country to another ‣ the use of easy-to-understand terms; depending on the number of events organised, ‣ the use of different messages and activities material produced, availability of resources, to ensure awareness was always fresh; previous projects, etc. Considering all these ‣ the use of practical messages; variables and, in particular, the complexity of ‣ the organisation of memorable activities. the campaign organised and its duration, it

would be difficult to interpret the calculated for example, Slovenia officially launched average total budget request for an eCSM pilot its eCSM campaign with a funny video on project. phishing, luxembourg organised several

activities by delivering the right message

3.2.12 Measuring the effectiveness of

to the different visitors of its fair booth at the autumn fair, the united Kingdom used awareness programmes

practical messages and tips to engage with the public in high-traffic areas such as eniSA asked the pilot countries to provide

shopping centres, railways stations, leisure quantitative and qualitative information

centres and other public locations. captured while measuring the achievements of

the eCSM initiatives.

the most common type of data received was ‣ Attack resistance: this approach measures quantitative data. these include, amongst how resistant users are to a potential attack. others, a focus on metrics such as the number this approach provides evidence on the of events organised, number of attendees level of awareness of the people concerned. at events, number of hits on the website however, the number of attack scenarios is or increase in percentage, and number of quite high, and the measure will be specific giveaways distributed. full details are provided to the scenario it is testing. in the sections of the report dedicated to each ‣ efficiency and effectiveness: this approach country. focuses on the actual experience of security incidents. the data can be gathered through Different Member States adopted different the overall security incident but does not methods to assess the effectiveness of eCSM necessarily give a true reflection of security activities. Methods used to capture data awareness. it is not just awareness that included, among others, questionnaires, determines whether incidents occurred. website statistics, general observations, however, in the long term, the trend can be statistics from data centres, data from a good indicator of awareness. hotlines, press clippings, press releases and ‣ internal protection: this approach assesses number of people trained. how well users are protected against threats. the advantage of these measures Generally, the data which have been gathered is that they provide direct evidence of users’ could lead to very similar key performance behaviour. often, though, the campaigns are indicators. this indicates that what the pilot aiming to change behaviour. this can result countries found effective is broadly similar. in many metrics.

table 3 illustrates different performance the data should be continually captured indicators that were mostly used across across all pilot countries (as performance europe. measurement and monitoring the effectiveness of an initiative should be done Table 3: perforManCe indiCaTors used during and after execution), and should ideally aCross europe be reviewed with a view to how future activities might be improved and made more effective. this information should be combined with the

No Performance indicator Approach

results derived from the evaluation metrics. 1 Number of materials distributed per week/ Process improvement the eCSM pilot projects’ objectives need to month be revisited by each country in light of the effectiveness results. reviewing the objectives 2 Number of materials distributed per edition Process improvement allows for a serious assessment to take place. 3 Number of events listed per month Process improvement to this end, a recent study conducted by 4 Number of people attending events per location Process improvement 15 eniSA ( ) reported that the evaluation of an awareness campaign or programme is 5 Number of hits on website per month Process improvement essential to understand its effectiveness, as 6 Number of downloads per video clip Process improvement well as to use the data as a guide to adjust the initiative to make it even more successful. 7 Mean time between discovery and notification Attack resistance this report suggests how to define indicators of an attack and/or new threat to measure the success of an awareness 8 Number of security incidents per month Efficiency and effectiveness programme as well as how to conduct evaluations. Below there are some of the 9 Etc. Etc. indicators which were identified and could be used to measure future eCSMs.

each performance indicator can be redirected to a different approach ( ).

‣ Process improvement: this approach assesses the effectiveness of the campaign by looking at its activities. these measures are easy to define and gather: however, they do not directly measure whether the end result has improved security.

No KPIs (*)

1 % of budget spent on awareness training 2 % of time spent on awareness training per FTE 3 Age of employees attending an awareness training/average age of total employees 4 Cycle time in days between organisation of awareness activities and completion of campaign 5 Number of FTEs IT-security trained/total users 6 Number of qualified hits/month 7 Total cost of awareness initiative per year 8 Total costs of awareness training per FTE 9 Total personnel cost of the planning and management awareness initiatives 10 % customer satisfaction with service delivery (i.e. timelines and quality) 11 % employee capability to perform roles 12 % employee satisfaction 13 % increase confidence for elderly 14 % senior management/executives; middle management/professionals; operational works/staff that attended management development programmes 15 % senior management/executives; middle management/professionals; operational works/staff that received a security review 16 % service delivery performance targets achieved 17 % stakeholder satisfaction with communication about the programme 18 % stakeholder satisfaction with governance arrangements 19 % stakeholder understanding of initiative benefits 20 % stakeholders’ resistance to change 21 % stakeholders’ satisfaction with ability of the system to meet business requirements 22 % employees understanding their role in achieving security goals 23 Average number of learning days per employee 24 Average personnel cost per FTE for the process ‘change management’ 25 Average personnel cost per FTE for the process ‘raising awareness’ 26 Frequency/relevance of surveys 27 Number of benefits realised as stated in business case 28 Number of employees per ‘develop and counsel-learning’ FTE 29 Number of changes in managers’ roles 30 Number of changes in staff activities 31 Number of correct answers on self security assessments/total questions 32 Number of employees in charge of development/total employees 33 Number of FTEs for the process ‘develop and counsel-learning’ per EUR 1 000 cost of continuing operations 34 Number of participants in the awareness survey/total employees 35 Number of self security assessment done/year 36 Total cost of the process ‘develop and counsel-learning’ per EUR 1 000 cost of continuing operations

No KPIs (*)

37 Total internal personnel cost of the process ‘develop and counsel-learning’ per EUR 1 000 cost of Continuing operations 38 Contribution of ICT training to value added per person engaged in % points 39 Number of employees who passed the exam or certification/total Number of employees 40 Number of organisations adopting the tools/year 41 Number of people who passed the exam or certification/total Number of people interviewed 42 Number of tools downloaded/month 43 Number of topics on security in high school and education/total topics 44 Number of topics on security in standard primary and secondary school education/total topics 45 % of budget allocated to awareness training 46 % of employees born after 1950 47 % of businesses with 10 or more employees using Internet 48 Number of access lines and channels in total/per 100 inhabitants 49 Number of households with access to home computer/country 50 Number of households with access to Internet/country 51 Number of mobile subscribers in total/per 100 inhabitants 52 Number of broadband subscribers/per 100 inhabitants 53 Training cost per FTE 54 Cycle time in days to resolve a security problem 55 Mean time between discovery and notification of a new threat 56 Number of identified fault/year 57 Number of alerts, advisories, notifications, recommendations/month 58 Number of communications with other countries/year 59 Number of systems without implemented password policy/total Number of systems 60 Number of tokens/certificates/eID cards issued/total population 61 Number of reported incidents per category/year 62 Number of certification scheme adopted by local or international companies 63 Number of e-government projects using the standards/total projects 64 Number of editions/year 65 Number of events listed/month 66 Number of material distributed/edition 67 Number of material distributed/year 68 Number of people attending awareness trainings per campaign 69 Number of training days per staff/year 70 Number of unique visitors/month 71 Time to organise an awareness initiative

4 Pilot countries

At the meeting, attention was paid to the

4.1 Czech Republic

following issues:

the Czech republic participated in the eCSM ‣ the specific activities of individual from 22 to 26 october 2012. organisations and the possibilities of closer cooperation, and the coordination problems the Ministry of the interior of the Czech of children, their parents and teachers in the republic supported and promoted the area of online communication; european Cyber Security Month in the Czech ‣ possibilities and ways of strengthening republic. cooperation among nGos, relevant public institutions and bodies active in Activities and events were scheduled to take criminal proceedings regarding protection place as follows. of children’s rights on the internet and preventing online crime; ‣ A round table of nGos engaged in the field ‣ options and ways for a common approach of online child protection, Czech internet to dealing with politicians and public hotlines, computer security incident administrations in increasing protection for response teams (CSirts) and industry internet users, especially children. stakeholders. the event was organised under the auspices of Mr Kubice, Minister Visitors to the http://www.saferinternet.cz for the interior of the Czech republic, website were informed about the eCSM and Mrs Simunkova, the government’s initiatives organised in the Czech republic. Commissioner for human rights. this website was the main online source of ‣ online outreach and promotion information, and traffic increased significantly plans through the website to 2 824 visitors, 70.25 % of whom were new http://www.saferinternet.cz and visitors. the same information about the newsletters. eCSM activities was also distributed to the ‣ Media campaign. 6 500 Czech schools via the Safer internet newsletter. the Czech Safer internet Centre (nCBi) joined the eCSM pilot projects initiated by Table 5: CzeCh republiC suMMary Table eniSA to stay safe and secure online. the nCBi organised the first round table of nGos, public administration representatives

Czech Republic

and organisations operating CSirts/Certs (computer emergency response teams) in the Government/national entities taking part Ministry of the Interior of the Czech Republic

Czech republic. in the ECSM

Private sector involved No the event took place on 26 october 2012 in Prague under the auspices of Mr Kubice, Duration 22–26 Oct. 2012 Minister for the interior of the Czech republic, and Mrs Simunkova, the government’s Languages used CZ

Commissioner for human rights. the Director Number of events organised 1 (round table) of Cert-eu, Mr freddy Dezeure, addressed the attendees of the round table with his Number of attendees > 30 speech. Number of locations 1 (Prague)

the main objective of the round table was Target audience NGOs; Czech Internet hotlines; CSIRTs; Industry to increase mutual information exchange stakeholders; Politicians; Public administration; Media and cooperation between organisations and Number of other activities organised 2 (online and media campaigns) companies that are active regarding education

in and promotion of online literacy, safer use Subject matter Internet safety; Online child protection; Cyber bullying of the internet, online crime prevention and dealing with socially pathological phenomena Delivery channels Conference; Giveaways; Stickers; Newsletter; Website; on the internet, or that operate as hotlines Media dealing with internet threats. Number of ENISA giveaways distributed 464

4.2 Luxembourg

luxembourg participated in the ‘Security week’ pilot project with its annual campaign focused this year (2012–13) on risks related to bullying and stalking.

the ‘Bee SeCure’ initiative from the luxembourg government was present with its 80 m fair booth at the autumn fair from 13 to 21 october 2012. Security tips were illustrated to the visitors either by talking through some of the available brochures and leaflets or by helping the visitors test how strong their password was through a computer available at the stand. tablets were at the disposal of citizens interested in taking part in competitions and draws. A table was organised to entertain kids while their parents were visiting the stand. the fair attracted more than 43 000 visitors. the stand was visited by thousands of citizens, emptying the booth of campaign material. During the opening ceremony the Grand Duke of luxembourg paid a visit to the stand.

Luxembourg

Government/national entities taking part in the ECSM BEE SECURE, an initiative of the Ministry of Education, Ministry of Family and Integration and Ministry of the Economy and Foreign Trade, operated by SNJ (the National Youth Agency) and SMILE (Security Made In Lëtzebuerg)

Private sector involved Yes Duration 13–21 Oct. 2012

Languages used FR, DE Number of events organised 1 (fair booth)

Number of attendees 43 000 at the fair, ~ 10 000 at the stand Number of locations 1 (Luxembourg) Target audience Citizens

Number of other activities organised 2 (distribution of posters and flyers through partners) Subject matter Internet safety and security; Strong passwords; Online child protection; Cyber bullying; Stalking

Delivery channels Fair stand; Giveaways; Stickers; Leaflets; Website; Competitions, draws; Brochures and other printed material; Posters Number of posters distributed 3 300

Number of ENISA giveaways distributed 9 250

Number of other giveaways distributed 18 556

Number of flyers and activity reports distributed 6 350

Number of partners’ flyers distributed Hundreds

‣ internal seminars/meetings, with volunteer

4.3 norway

speakers, organised at norwegian norway participated in the european Cyber companies through the ‘national Security Security Month by organising activities and Month’ project and administered through events for citizens and SMes throughout the http://www.sikkert.no. Companies chose month of october. the topic to be covered during the seminar/ meeting from 30 different presentations. the norwegian Centre for information ‣ norSiS gave 30 presentations at different Security (norSiS) ran the ‘Stopp. tenk. Klikk.’ seminars and conferences. (Stop. think. Connect.) campaign during october to celebrate the european Security An education package was distributed to 115 Month. the events and activities were part of a businesses in norway during the month of national public awareness campaign aimed at September in order to have training activities increasing the understanding of cyber threats organised in-house during the month of and enabling norwegian citizens to be safer october. the package included the following: and more secure online. presentations, e-learning, brochures with security tips for employees, posters, videos, the campaign’s main objective was to help all gadgets. citizens become more aware of threats and, Table 7: norWay suMMary Table in particular, better understand how to protect:

‣ personal information and identity by using Norway strong passwords; ‣ businesses by keeping security software Government/national entities taking part Norwegian Centre for Information Security current. in the ECSM

Private sector involved Yes the government and private organisations welcomed the initiative. Duration Whole of October 2012

Languages used NO Activities and events were scheduled to take place during the entire month of october as Number of events organised 37 (conferences and seminars) follows. Number of attendees Approximately 2 000–2 500 ‣ Kick-off event by means of a conference. Number of locations 12 (Bergen, Bærum, Bodø, Gjøvik, Kristiansand, the opening address was given by the Lillehammer, Narvik, Nittedal, Oslo, Skien, Stavanger, Minister for Government Administration, Trondheim) reform and Church Affairs, Mrs rigmor Target audience Citizens; SMEs Aasrud. Video clips were used during the day. Number of other activities organised 7 (distribution of posters and educational material for ‣ Daily radio advertisements. SMEs; radio and Internet advertisements; video clips; ‣ internet advertisements. articles on magazines and newspapers) ‣ Articles in the news. Subject matter Internet safety; Updating programs; Privacy; Passwords; ‣ Distribution of educational packages to Encryption; Security software SMes, including presentations, videos, posters and gadgets raising the information Delivery channels Conferences; Seminars; Giveaways; Stickers; Educational security awareness of approximately 60 000 packages for SMEs including e-learning, presentations, norwegian employees. videos, security tips, posters and gadgets; Leaflets; ‣ Website campaign (http://www.sikkert.no). Posters; Website; Internet advertisement; Video 18 500 visitors were registered for the entire clips; Social media; Articles; Press releases; Radio period. advertisements ‣ Social media campaigns on facebook Number of posters distributed 1 000 (nasjonal Sikkerhetsmåned) and twitter (#sikkerhetsmåned). Number of ENISA giveaways distributed 1 098 ‣ More than 37 conferences and seminars were held throughout norway, from narvik Number of radio advertisements’ listeners Approximately 5 000 000 in the north to oslo, trondheim, Gjøvik, Stavanger and several other locations in the country.

over 4 days, the Portuguese events saw 240

4.4 Portugal

participants (83 attending the workshops and the national Security office, in collaboration 157 the main conference) from approximately with ShadowSeC and the united nations 75 companies and 16 speakers. interregional Crime and Justice research institute (uniCri), organised the second the main theme and agenda of the events edition of infosecDay under the auspices of the were very well received by all attendees, as european Cyber Security Month. well as the quality of the information shared and the time for discussions which was Portugal participated in the ‘Security week’ allowed. pilot project by organising a conference and a series of workshops aimed at discussing the second edition of infosecDay received the main national and international trends excellent press coverage. the website and emerging risks regarding cyber security. dedicated to the events had over the period a the events were held on 1–4 october 2012 in total of 341 visits with an increase of new visits lisbon. A series of workshops were held on by 67,16 %. 1–3 october and a conference on 4 october. the events were open to it professionals, civil servants and government institutions.

Portugal

Government/national entities taking part National Security Office (GNS)

in the ECSM

Private sector involved Yes

Duration 1–4 October 2012 Languages used PT, EN

Number of events organised 4 (workshops and conference)

Number of attendees 240 Number of locations 1 (Lisbon)

Target audience IT professionals; IT civil servants; Government institutions Number of other activities organised NA

Subject matter Cyber crime legislation; National cyber security strategy; Cyber threats; Digital investigation; Data protection; ISO 27001; Cloud security; Responding to security incidents; Public-private partnerships; Software development Delivery channels Conferences; Seminars; Giveaways; Leaflets; Website; Brochures and other printed material; Stickers Number of posters distributed NA

Number of ENISA giveaways distributed 708

financial and banking sectors. this year,

4.5 Romania

202 people attended the conference, which romania participated in the european Cyber through panel discussions covered the Security Month (eCSM) by organising various following: activities to raise romanians’ information security awareness throughout the month ‣ the implications of operational and of october, changing the original plans to security risks generated by it activities and cover only the period 15–19 october 2012. communications in the banking sector; this was mainly due to the fact the organiser ‣ cyber threats and the existing solutions for recognised that social media and online data protection. campaigns would have been more effective and successful if run for at least a period of 4.5.2 online and social media four weeks. campaigns

the romanian Cert organised various Various online and social media campaigns activities to raise information security ran during the month of october. awareness as follows. A dedicated section of the Cert-ro website ‣ Cyber threats 2012: public conference on (http://www.cert-ro.eu/eCSM2012.php) was cyber security. developed and populated with information ‣ Social networks and online campaigns: about the eCSM, its material and posts (18 in information security advice and articles total) on matters related to internet security. were provided to visitors to the website the posts consisted of articles, guides, tips http://www.cert-ro.eu and the relevant and advice, and press releases. Moreover, 15 facebook, twitter, Google+ and linkedin media articles in romanian were published accounts. and also distributed via social media channels ‣ Press releases to inform the population such as facebook, twitter, Google+ and about events organised by Cert-ro during linkedin. the month. Social media were used to share information 4.5.1 Cyber threats Conference 2012 on the eCSM and the activities scheduled in romania, as well as to illustrate, in an the conference was dedicated to raising engaging way, matters regarding information awareness among internet users about the security and the related risks and threats. dangers of cyber attacks, especially in the tweets were posted in romanian and english.

Romania

Government/national entities taking part in the ECSM CERT-RO Private sector involved Yes

Duration Whole of October 2012 Languages used RO, EN

Number of events organised 1 (conference)

Number of attendees 202 Number of locations 1 (Bucharest)

Target audience IT professionals; IT civil servants; Government institutions Number of other activities organised 2 (online and social media campaigns) Subject matter Cyber security

Delivery channels Conference; Social networks; Website; Media; Video clip; Posters

Number of posters distributed 200

Number of ENISA giveaways distributed NA

Number of other giveaways distributed 222

4.6 Slovenia

Slovenia participated in the eCSM by organising various activities to raise Slovenians’ information security awareness for 2 weeks (17–31 october 2012).

the Slovenian Cert organised various activities to raise information security awareness as follows.

‣ facebook campaign: via this social media platform, information security tips were provided to visitors to the page. Quizzes about information security took place and prizes were distributed. By 30 october, 250 people had participated in the quiz, registering 2 200 new ‘likes’ on the dedicated facebook page. ‣ television campaign: tV adverts were broadcast for the entire period of the campaign. the adverts, reminding people how to protect from online fraud, ‣ Students’ fair (23–25 october 2012): the encouraged viewers to visit the educational Slovenian Cert was present with its booth portal ‘Safe on the internet’ and get more at the students’ fair. leaflets and the ABC info about information security. of online safety booklet were distributed. Visitors to the stand had the chance to Table 10: slovenia suMMary Table participate in a quiz game: ‘Are you a web detective?’ A clip on nigerian scams was launched during this initiative ( ). Slovenia ‣ three new video clips were launched in collaboration with two famous Slovenian Government/national entities taking part ARNES SI-CERT comedians. By 30 october, the videos as a

in the ECSM

whole had received more than 18 600 views Private sector involved No 17 on youtube ( ).

Duration 17–31 October 2012 on 17 october, Slovenia officially launched Languages used SL its eCSM campaign with a funny video on phishing ( ), a facebook quiz, tV ads and Number of events organised 1 (fair booth) banners. in the first 24 hours, the website Number of attendees More than 21 000 students and young adults visited http://www.varninainternetu.si/ had more than the students’ fair. The booth was visited by around 200 2 700 views, with a total increase in traffic of people who also participated in the quiz 200 %. During the entire campaign the website got more than 18 000 unique visitors. Number of locations 1 (Ljubljana)

Target audience Citizens; Students

Number of other activities organised 3 (social media campaign; TV adverts; online quizzes)

Subject matter Online safety; Online fraud (Nigerian scams, phishing, fake online stores)

Delivery channels Social media (Facebook, Twitter and YouTube); Online campaigns (i.e. web banners, articles on national (16) http://www.youtube.com/ online news portals); TV adverts; Fair stand; Video clips; watch?v=blDPpm6QGXM&list=uu4-56idnZZn3sizleqbMgV Giveaways; Quizzes, competitions; Leaflets; Booklets w&index=1&feature=plcp (17) the video about fraudulent online stores is available at Number of posters distributed NA http://youtu.be/iPhhoestvKQ (18) http://www.youtube.com/watch?v=A0SQp9reots Number of ENISA giveaways distributed 500

4.7 Spain

Spain participated in the european Cyber Security Month (eCSM) by organising a conference for information security professionals and several activities for children, teenagers and adults throughout the month of october 2012.

inteco ( ) participated in the eCSM by organising the sixth eniSe (international Meeting on information Security). the conference took place on 23–24 october 2012, registering 386 attendees and 18 000 more by video streaming.

Moreover, activities and events to raise the information security awareness of children, teenagers and adults were scheduled to take increase of 20 followers; 12 on the Facebook place throughout the month of october as page ‘oSi’ registering an increase of 1 830 follows. followers; and 12 on the Facebook page ‘Pienso, luego clico’ registering an increase ‘What do you know about security?’ story of 1 443 followers. ‣ and drawing competitions for children from 5 to 12 years old. in the drawing these activities were organised by inteco category, 15 schools participated with 525 through oSi (http://www.osi.es), its national drawings. in the story category, 22 schools security helpdesk for citizens. this website participated with 350 stories. received 102 954 visitors, an increase of 21 %. ‣ ‘Choose your mascot’ campaign: this Table 11: spain suMMary Table initiative tried to teach basic security concepts to students from 5 to 8 years old. the children chose a mascot from

Spain

the Menores oSi website who explained information security to them. A total of three Government/national entities taking part Instituto Nacional de Tecnologías de la Comunicación schools participated in this pilot project. in the ECSM (Inteco) Before deploying this initiative to all schools, Private sector involved Yes pros and cons will be analysed and material reviewed. Duration Whole of October 2012 ‣ lectures about internet security and social networks focused on children, teenagers, Languages used ES parents and teachers. these lectures took Number of events organised 7 (lectures and conference) place in several schools all over Spain: six lectures in three schools, with 326 attendees Number of attendees 722, and 18 000 virtual attendees (309 children and 17 parents and teachers). Number of locations 1 (León) the schedule was as follows: Target audience Information security professionals; Children; Teenagers; » 9/10/2012 — two lectures to students at Adults; Parents; Teachers; Schools San Juan de la Cruz School (león); Number of other activities organised 3 (competition, social media campaign and ‘choose your » 9/10/2012 — one lecture to parents and (competition, social media campaign, etc.) mascot” campaign) teachers at San Juan de la Cruz School (león); Subject matter Information security » 15/10/2012 — two lectures to students at Virgen Blanca School (león); Delivery channels Conference; Lectures; Social networks; Competitions; » 31/10/2012 — one lecture to students at Giveaways Don Bosco School (león). Number of posters distributed NA ‣ Social media campaigns: information security tips were advertised throughout Number of ENISA giveaways distributed 1 004 facebook and tuenti ( ). Various adverts were created: three on tuenti registering an

Cardiff

4.8 United Kingdom

the united Kingdom participated in the ‣ Cardiff central station: from early in the ‘Security week’ pilot project by organising morning until 9.15 a.m. the team gave out initiatives and events in five major cities across leaflets and giveaways to commuters, with a the country from 22 to 26 october 2012. fantastic response. the information staff at the station wore Click & tell badges all day. Get Safe online — the uK’s leading source ‣ Queens Arcade: a stand was set up in of free, practical, expert information and the shopping centre, where leaflets were advice on online safety — organised the handed out to the good shoppers of South seventh annual Get Safe online Week under Wales along with Click & tell foam hands the auspices of the eCSM. this year’s theme and memory sticks. the coach was parked was ‘Click & tell’, designed to get as many outside the arcade all day, and free, practical people as possible across the uK to pass on advice was given on anything from how online safety tips to friends, family, colleagues, not updating antivirus software could be neighbours, vulnerable people, or anyone who making a lady’s computer slow down, to could benefit from the advice. what parental control software is available for iPads, etc. Mr David Jones, Secretary of State for Wales, visited the coach to chat with the team and a group of children from St Cadoc’s r. C. Primary School in llanrumney, Cardiff. the children also chatted with the Get safe online team and its guest experts about online safety live on BBC radio Wales.

London

‣ Waterloo station: a team of seven pitched the Click & tell pop-up display at Waterloo station, remaining in situ until 10 a.m. offering advice to commuters and handing out leaflets and goodies. ‣ Admiralty Arch, trafalgar Square: the coach parked at Admiralty Arch, trafalgar Square where a steady flow of people dropped into speak to the experts on board. ‣ Sir John Cass foundation Sixth form College in Stepney Green: a couple of the focus of Get Safe online Week was a people from the content team addressed roadshow visiting five major uK cities (Cardiff, the school assembly about online safety. london, leeds, edinburgh and Belfast), later in the day, the Get Safe online team engaging with the public in high-traffic areas entertained four of the college’s youngsters such as concourses, shopping centres, railway on the coach in the afternoon — also stations, leisure centres and other public catching up with Parliamentary Secretary locations. the message was also cascaded to the Cabinet office Chloe Smith, who was by Get Safe online’s partner community as visiting at the same time. the minister also well as other interested parties. A number of met supporters from SoCA, Symantec, the celebrities and other well-known personalities Metropolitan Police, hMrC, PhonePayPlus, were recruited to endorse this important Gumtree, three and our government message. ambassadors from the Cabinet office and the Department for Business, innovation the campaign reached 124 160 943 citizens. and Skills. the Get Safe online team visited the following locations.

Leeds, west yorkshire the amount of traffic gained from referring websites increased by over 75 % in a week – ‣ leeds station: the team offered advice to indicating that other websites were helping to the commuters of West yorkshire, who were promote the Get Safe online website and the very receptive of the initiative and the online events organised in the context of the Get Safe safety messages. thousands of flyers and online Week. giveaways were distributed. ‣ Briggate: the Click & tell coach was parked Almost 85 % of the people who visited the in one of the city’s main shopping streets, website during that week had not visited it where the team engaged with the public on previously, indicating excellent reach for the all aspects of online safety. programme.

‣ edinburgh station: the team talked to the

United Kingdom

commuters about the importance of internet security. Government/national entities taking part Get Safe Online ‣ St James Shopping Centre: leaflets, in the ECSM t-shirts, foam hands and good advice Private sector involved Yes were distributed in the true spirit of Click & tell. Again, some themes seemed to Duration 22–26 October 2012 predominate, with questions about safe emailing and keeping children protected. Languages used EN ‣ Castle Street: the coach parked across Number of events organised 2 (roadshow and lecture) Castle Street, where citizens were reminded how to stay safe and secure online. Number of attendees Not provided

Number of locations 5 (Cardiff, London, Leeds, Edinburgh, Belfast) belfast Target audience Citizens; Students; Schools ‣ europa bus centre and Great Victoria Street station: from 8 a.m. to 9.30 a.m. Number of other activities organised 6 (distribution of leaflets, posters, giveaways, printed material and brochures; online campaign) ‣ City hall: from 12 noon to 2 p.m. ‣ tesco extra Knocknagoney road: from 2.30 Subject matter Get safe online p.m to 3.30 p.m. ‣ in all three locations, leaflets and giveaways Delivery channels Roadshow; Lecture; Leaflets; Posters; Giveaways; Printed were distributed and well received, probably material, brochures; Website, blog because some 60 % of the population has Number of posters distributed 5 000 been directly affected by online crime, one of the worst records in the united Kingdom. Number of ENISA giveaways distributed NA ‣ Queen’s university library: the team chatted with students about a number of aspects of Number of other giveaways distributed 10 000 Trend Titanium licenses; 1 000 t-shirts; 1 000 online safety. folduo flying discs; 2 000 Symantec USB sticks

Number of flyers distributed 10 000 During the Get Safe online Week, the website http://www.getsafeonline.org/ had more than 25 000 unique page views, with a total increase of 57 % compared with the previous week ( ).

5 role played by eniSA

eniSA supported the organisation of the eniSA provided guidance and expertise european Cyber Security Month pilot projects on how to organise information security in various ways, as: campaigns by using its methodology on how to prepare and implement awareness campaigns ‣ coordinator of the organisation of the eCSM; ( ), and developed a series of common ‣ hub for all participating countries; messages and material to help Member ‣ collector of available material and generator States prepare their cyber security education of synergies between pilot countries; and awareness campaigns in a similar ways ‣ subject-matter expert on how to organise in the context of the european Cyber Security information security campaigns; Month. this material was recognised by all ‣ facilitator of common messaging within the countries as an important tool in reaching participating countries by providing tips and people and getting them to change their advice on how to be safe and secure online; behaviour, or to reinforce good behaviour. ‣ creator of the eCSM brand and related marketing plan; this material included: ‣ distributor of promotional material (about 15 000 giveaways and 10 000 posters). ‣ tips and advice to provide in-depth information on how to stay safe in a variety of online settings, for example on social networking sites, on gaming sites and on your mobile device; ‣ eCSM posters; ‣ eCSM web banners; ‣ eCSM certificate of appreciation template (white background and coloured background); ‣ eCSM letterhead; ‣ eCSM PowerPoint template; ‣ eCSM name tags form; ‣ eCSM video clip ( ).

Moreover, the Agency produced promotion material for the Member States to help promote awareness messages and also helped to identify speakers for events.

the Agency coordinated the organisation of the 2012 eCSM, trying to become the hub for all pilot countries by providing suggestions, (22) The new users’ guide: How to raise information security replying to enquiries and generating synergies awareness, eniSA, november 2010, available at http://www. between countries when possible. for enisa.europa.eu/activities/cert/security-month/deliveraexample, the interaction between luxembourg bles/2010/new-users-guide (23) As of 15 november 2012, the eCSM clip had 1 099 and norway and that between the united views. the video is available at http://www.youtube.com/ Kingdom and Slovenia, along with norway, watch?v=q00uiu0yWoo A short version of the same clip had demonstrated how successful synergies could 870 views. the video is available at http://www.youtube.com/ be. watch?v=7d9l6ua3p0s

5.1 brand marketing plan 5.1.4 Social media

A series of activities were planned to market Dedicated social media accounts were created the european Cyber Security Month project. as a source of useful advice about information security in general, as well as tips and recommendations on how to protect your PC

5.1.1 visual identity

and personal and business information. the to strengthen visibility and public recognition accounts provided information on the activities of the european Cyber Security Month, eniSA and events organised in each of the pilot created a visual identity including a logo, a countries. colour chart, typography rules, guidelines Accounts were set up and activated on the on use of imagery, design templates and a manual of formal guidelines on the proper use following social networking sites: of these elements. ‣ twitter ‣ facebook the design was created following consultation ‣ linkedin. with the Member States and the european Commission. Moreover, the eniSA social media channels ( ) were used to advertise the eCSM activities. More than 2 300 unique page views ( ) were

5.1.2 Slogan

originated from eniSA social media traffic in relation to the european Cyber Security the slogan ‘Be aware. Be secure.’ was created Month. this data represents almost 25 % of to give the project an identity and a positive the total unique page views of all eniSA social image. it was used in some of the material media traffic for the period 18 September 2012 and giveaways produced for the european – 31 october 2012. Cyber Security Month project. the slogan always appeared when information security tips were displayed in posters and in any other relevant material.

5.1.3 advertising campaign

the european Cyber Security Month featured a diverse range of activities and events, and as part of the build-up eniSA launched a campaign that gave people the chance to feature in advertisements and (24) eniSA launched its social media channels on 19 Sepother promotional material by sending in tember 2012. Social Media channels officially launched on 19 September included twitter and facebook. linkedin was photographs of themselves. an automatically generated page already active and youtube page was created on 6 July 2012. eniSA aimed to bring the slogan of the (25) Data related to period 18 September 2012 – 31 october project, ‘Be aware. Be secure.’, to life. 2012.

5.1.4.1 Facebook campaigns the facebook campaigns, along with the press releases and the new items published by eniSA ran six facebook campaigns in order the Agency during the months of September to make citizens aware of the project and and october, registered a total of 44 363 its activities and build brand recognition. unique page views ( ), an increase of 5.44 % Campaigns were organised at european and compared to the previous 2 months. Member States’ level targeting: luxembourg; Moreover, the media campaign and the video norway; Portugal; Slovenia; and Spain. 27 of Vice President neelie Kroes ( ) launching the european Cyber Security Month had a All campaigns targeted the same audience significant impact on the media coverage, and were created in the language of the 28 the total number of facebook ‘likes’ ( ) and relevant country. the duration of each the number of followers of the eCSM twitter campaign was set according to the length 29 account ( ). of the activities planned in the targeted pilot countries. All campaigns pointed to the Details about how the six facebook campaigns dedicated eniSA webpages. were set-up and related data can be found in the sections below.

5.1.4.1.1 eURoPe

‣ who live in Austria, Belgium, Bulgaria, CounTries: Cyprus, the Czech republic, Denmark,

E

Austria, Belgium, Bulgaria, Cyprus, Czech estonia, finland, france, Germany, republic, Denmark, estonia, finland, Greece, hungary, iceland, ireland, france, Germany, Greece, hungary, italy, latvia, liechtenstein, lithuania, iceland, ireland, italy, latvia, liechtenstein, luxembourg, Malta, the netherlands, lithuania, luxembourg, Malta, netherlands, norway, Poland, Portugal, romania, norway, Poland, Portugal, romania, Slovakia, Slovenia, Spain, Sweden or the Slovakia, Slovenia, Spain, Sweden, united united Kingdom; Kingdom. ‣ aged 18 and older, ‣ in one of the categories: science/ sTaTus: technology, computer programming, small Europ business owners, mobile (all), iPhone,

completed riM/Blackberry, Android, Windows Phone, others, iPad, active feature phone users or duraTion: technology early adopters. 3/9/2012–1/10/2012 31 CaMpaign reaCh ( ): naMe: 1 246 064 Join the eu CyberSecMonth 32 frequenCy ( ): 11.8 adverT: october is the eu Cyber Security Month. nuMber of iMpressions ( ) : Check out how to stay safe and secure 7 507 532 online nuMber of CliCks ( ): TargeTing ( ) : 364 (pointing to http://www.enisa.europa.eu/ 98 580 420 users: activities/cert/security-month/pilots)

5.1.4.1.2 LUxeMboURg

luxembourg frequenCy:

XEM

39 (pointing to http://www.enisa.europa. Mois ue de Cybersécurité eu/activities/cert/security-month/pilots/ luxembourg) adverT: Découvrez toutes les activités locales et manifestations prévues à luxembourg figure 3: audienCe of luxeMbourg’s TargeTing: faCebook CaMpaign 125 660 users

G

‣ who live in luxembourg; ‣ aged 18 and older; ‣ in one of the categories: science/ technology, computer programming, small business owners, technology early adopters, mobile users (all), smartphone/ tablet users, feature phone users, Sony, lG, Motorola, htC, Android (other), Samsung or Android (all).

5.1.4.1.3 noRway

completed 8.8

norw

Se hvilke lokale aktiviteter og arrangement som er planlagt i norge figure 4: audienCe of norWay’s faCebook TargeTing: CaMpaign 1 641 940 users

‣ who live in norway; ‣ aged 18 and older; ‣ in one of the categories: science/ technology, computer programming, small business owners, technology early adopters, mobile users (all), smartphone/ tablet users, feature phone users, Sony, lG, Motorola, htC, Android (other), Samsung or Android (all). Targeted 1 641 940 Reached 27 476 graph 4: response To norWay’s faCebook CaMpaign

5.1.4.1.4 PoRtUgaL

portu

Portugal 184 746

completed 9.5

4/9/2012–2/10/2012 1 752 870

G

Mês de Cibersegurança 86 (pointing to http://www.enisa.europa. Advert: Confira a variedade de actividades eu/activities/cert/security-month/pilots/

a

locais e eventos a serem realizados em portugal) Portugal

L

‣ who live in Portugal; ‣ aged 18 and older; ‣ in one of the categories: computer programming, small business owners, mobile users (all), smartphone/tablet users, feature phone users, Sony, lG, Motorola, htC, Android (other) or Samsung.

5.1.4.1.5 SLovenia

nia vE o

eu/activities/cert/security-month/pilots/ adverT: slovenia) Preveri lokalne dejavnosti in dogodke, ki se SL bodo odvijali v Sloveniji. Pridruži se nam!

‣ who live in Slovenia; ‣ aged 18 and older; ‣ in one of the categories: science/ technology, computer programming, small business owners, technology early adopters, mobile users (all), smartphone/ tablet users, feature phone users, Sony, lG, Motorola, htC, Android (other), Samsung or Android (all).

5.1.4.1.6 SPain

Spain 422 012 Sp

completed 3.4

10/9/2012–5/10/2012 692 416

Mes seguridad cibernética 85 (pointing to http://www.enisa.europa.eu/ activities/cert/security-month/pilots/spain)

Consulta todas las actividades que se celebrarán en españa para el mes europeo

de seguridad

9 926 640 users

‣ who live in Spain; ‣ aged 18 and older; ‣ in one of the categories: science/ technology, computer programming, small business owners, mobile (all), iPhone, riM/Blackberry, Android, Windows Phone, others, iPad, active feature phone users or technology early adopters.

6 lessons learned

the analysis of the data gathered throughout ‣ Produce video clips in different formats in this report as well as the inputs received by order to allow their use for tV adverts. the participating countries helped to identify ‣ Make sure there are enough staff available a set of lessons learned. in addition, the during events. Particular attention should be experience of eniSA in its role of coordinator paid to the number of staff available during of the eCSM was key while performing this weekends compared to weekdays. exercise. these lessons could be applied to ‣ Produce giveaways according to the season future eCSMs. of distribution (i.e. t-shirts distributed in cold weather did not appear to be a good ‣ Better define the specific audience that is idea). targeted by the awareness initiative in order ‣ involve an increased number of private to tailor the message content to the target companies to increase impact. group’s knowledge or technical aptitude ‣ Deal with changes in plans and keep using the most effective communication interested parties informed. channels. ‣ ensure media coverage by planning possible ‣ Produce all relevant material in at least interviews in advance. Be prepared for lastall the official languages of participating minute cancellations. countries. ‣ Make press releases available in at least all the official languages of participating countries.

7 Conclusions

the data gathered and the analysis carried ‣ increasing their efficiency in organising out led to the conclusion that the first eCSM initiatives;leveraging existing ever european Cyber Security Month was material; a successful pilot project. the significant ‣ sharing experiences and information with experience of the eCSM’s participating the other countries and eniSA. countries and their commitment to achieving long-lasting change in human behaviour and Several elements ensured the success in the perception of risks were the two key elements organisation of the eCSM: that led to a successful project. ‣ the Member States were fully engaged; ‣ intermediaries were involved in almost all the eCSM aimed at bringing citizens to reflect countries; on the importance of being safe and secure ‣ media coverage was significant both at online and raising awareness of niS issues. european and at national level; Moreover, the pilot countries received benefits ‣ the eCSM brand logo and associated values from this initiative by: started to be recognised.

‣ including their national security events in a to conclude, eniSA believes that the 2012 european initiative context; european Cyber Security Month pilot project ‣ increasing their visibility at european level; set the scene for the organisation of a fully ‣ improving positive public opinion about fledged eCSM in the years to come. information security;

european network and information security agency

be aware, be secure.

synThesis of The resulTs of The firsT european Cyber seCuriTy MonTh

P.o. Box 1309, 71001 heraklion, Greece www.enisa.europa.eu

Fotnoter

  1. European Network and Information Security Agency
  2. B e A W A r e , B e S e C u r e . I
  3. II B e A W A r e , B e S e C u r e .
  4. B e A W A r e , B e S e C u r e. 1
  5. 2 B e A W A r e , B e S e C u r e .
  6. B e A W A r e , B e S e C u r e. 3
  7. 4 B e A W A r e , B e S e C u r e .
  8. levels. this approach was broadly endorsed by (5) european principles and guidelines for internet resil-
  9. 4 ience and stability (http://ec.europa.eu/information_society/ the Council in 2009 ( ). policy/nis/docs/principles_ciip/guidelines_internet_fin.pdf). (6) european principles and guidelines for internet resilience and stability (http://ec.europa.eu/information_society/ (1) CoM(2005) 229. policy/nis/docs/principles_ciip/guidelines_internet_fin.pdf). (2) CoM(2006) 251. (7) CoM(2010) 245. (3) CoM(2009) 149. (8) Council conclusions of 31 May 2010 on Digital Agenda (4) Council resolution of 18 December 2009 on a collabora- for europe (10130/10). tive european approach to network and information security (9) CoM(2010) 2020 and conclusions of the european Coun- (2009/C 321/01). cil of 25/26 March 2010 (euCo 7/10).
  10. B e A W A r e , B e S e C u r e. 5
  11. 6 B e A W A r e , B e S e C u r e .
  12. B e A W A r e , B e S e C u r e. 7
  13. tabLe 1: 2012 eventS CaLenDaR
  14. 8 B e A W A r e , B e S e C u r e .
  15. Table 2: CaTegorisaTion of The TargeT groups
  16. B e A W A r e , B e S e C u r e. 9
  17. 10 B e A W A r e , B e S e C u r e .
  18. figure 2: grouping of delivery Channels
  19. B e A W A r e , B e S e C u r e . 11
  20. 12 B e A W A r e , B e S e C u r e .
  21. The new users’ guide: How to raise information security
  22. awareness, eniSA, november 2010, available at (14) http://www.enisa.europa.eu/activities/cert/security-month/
  23. Information security awareness initiatives: Current prac-
  24. tice and the measurement of success, eniSA, July 2007. deliverables/2010/new-users-guide
  25. B e A W A r e , B e S e C u r e . 13
  26. Table 4: exaMples of perforManCe indiCaTors
  27. 14 B e A W A r e , B e S e C u r e .
  28. (*) Most KPis are expressed on a pro rata basis (i.e. number of units per fte or per eur 1 000 of spend) rather than in absolute terms. % = percentage; fte = full-time equivalent.
  29. B e A W A r e , B e S e C u r e . 15
  30. 16 B e A W A r e , B e S e C u r e .
  31. Table 6: luxeMbourg suMMary Table
  32. B e A W A r e , B e S e C u r e . 17
  33. 18 B e A W A r e , B e S e C u r e .
  34. Table 8: porTugal suMMary Table
  35. B e A W A r e , B e S e C u r e . 19
  36. Table 9: roMania suMMary Table
  37. 20 B e A W A r e , B e S e C u r e .
  38. B e A W A r e , B e S e C u r e . 21
  39. (19) http://www.inteco.es (20) tuenti is a Spain-based, invitation-only private social networking website for students and young people.
  40. 22 B e A W A r e , B e S e C u r e .
  41. B e A W A r e , B e S e C u r e . 23
  42. edinburgh Table 12: uniTed kingdoM suMMary Table
  43. (21) the website http://www.getsafeonline.org/ had 61 248 page views up from 36 595 (+ 67.37 %) the previous week.
  44. 24 B e A W A r e , B e S e C u r e .
  45. B e A W A r e , B e S e C u r e . 25
  46. 26 B e A W A r e , B e S e C u r e .
  47. (26) http://www.enisa.europa.eu/activities/cert/security- (31) the number of individual people who saw sponsored month stories or adverts in this campaign during the dates (27) http://www.youtube.com/watch?v=7uwtAWrfpGi selected. this isdifferent to impressions, which includes 28 people seeing them multiple times. ( ) http://www.facebook.com/CyberSecMonth. As of 19 (32) the average number of times each person saw the november 2012, the facebook CyberSecMonth account has 65 likes. eCSM campaign’s sponsored stories or adverts 29 (33) the total number of times adverts have been shown on ( ) https://twitter.com/CyberSecMonth. As of 19 november 2012, the twitter CyberSecMonth account has 230 fol- the site. lowers, 110 tweets and 61 following. (34) the number of clicks this campaign’s sponsored stories (30) the number of individual people who were targeted by or adverts have received. this campaign.
  48. B e A W A r e , B e S e C u r e . 27
  49. CaMpaign reaCh: CounTry: 33 987 Lu
  50. sTaTus: 19.9 completed nuMber of iMpressions: duraTion: 676 101 1/10/2012–13/10/2012 nuMber of CliCks: naMe: bour
  51. Targeted 125 660 graph 3: response To luxeMbourg’s Reached 33 987 faCebook CaMpaign
  52. Clicks Actions
  53. 28 B e A W A r e , B e S e C u r e .
  54. CounTry: CaMpaign reaCh: norway 27 476 ay sTaTus: frequenCy:
  55. duraTion: nuMber of iMpressions: 29/9/2012–26/10/2012 247 474
  56. naMe: nuMber of CliCks: Delta i eu-CyberSecMonth 3 (pointing to http://www.enisa.europa.eu/ activities/cert/security-month/pilots/norway) adverT:
  57. Clicks Actions
  58. B e A W A r e , B e S e C u r e . 29
  59. CounTry: CaMpaign reaCh:
  60. sTaTus: frequenCy:
  61. duraTion: nuMber of iMpressions:
  62. naMe: nuMber of CliCks:
  63. TargeTing: 1 452 440 users figure 5: audienCe of porTugal’s faCebook CaMpaign
  64. Targeted 1 452 440 graph 5: response To porTugal’s 184 746 Reached faCebook CaMpaign
  65. Clicks Actions
  66. 30 B e A W A r e , B e S e C u r e .
  67. CounTry: CaMpaign reaCh: Slovenia 99 005
  68. sTaTus: frequenCy: completed 18.9
  69. duraTion: nuMber of iMpressions: 24/9/2012–5/10/2012 1 869 882
  70. naMe: nuMber of CliCks: eu mesec spletne varnosti 85 (pointing to http://www.enisa.europa.
  71. TargeTing: figure 6: audienCe of slovenia’s faCebook CaMpaign 282 840 users
  72. graph 6: response To slovenia’s Targeted 282 840 faCebook CaMpaign Reached 99 005
  73. Clicks Actions
  74. B e A W A r e , B e S e C u r e . 31
  75. CounTry: CaMpaign reaCh:
  76. sTaTus: frequenCy: ain
  77. duraTion: nuMber of iMpressions:
  78. naMe: nuMber of CliCks:
  79. figure 7: audienCe of spain’s faCebook
  80. CaMpaign TargeTing:
  81. Targeted 9 926 640 Reached 422 012 graph 7: response To spain’s faCebook CaMpaign
  82. Clicks Actions
  83. 32 B e A W A r e , B e S e C u r e .
  84. B e A W A r e , B e S e C u r e . 33
  85. luxembourg: publications office of the european union, 2012 isbn 978-92-9204-063-5 doi: 10.2824/24665 Catalogue number: Tp-30-12-136-en-n
  86. European Network and Information Security Agency
  87. doi: 10.2824/24665