Enhancing Cybersecurity for Cypriot Small and Medium Enterprises 2023
ClosedDescription
The Programme aims to ensure that SMEs reach a basic level of cybersecurity in order to protect their infrastructures, systems and information. This will be achieved through the purchase of solutions and services to maintain and strengthen the level of security and resilience of small and medium enterprises (SMEs), as well as through the evaluation and identification of challenges and weaknesses. Additionally, the Programme seeks to achieve their compliance of SMES with European and internationally accepted measures and standards through a certification scheme, the Cyber-Hygiene Framework for Small and Medium Enterprises (SME) of the NCC-CY. Through the Programme, SMEs will have the opportunity to obtain a Cybersecurity Certification. The Certification is issued by Certification Bodies, which have been accredited according to ISO 17021 and ISO 27006, hence are competent to carry out inspections and certifications for information security management systems according to ISO/IEC 27001:2013 and/or ISO/IEC 27001:2022. Following acquirement of the Certification, enterprises will be able to assess their current level of maturity, identify vulnerabilities and mitigate risk, while strengthening their cybersecurity practices. It will also allow them to invest in the protection of information and data, based on specific specifications and minimum requirements set out in the NCC-CY Cyber-Hygiene Framework for SMEs. More info about the Cyber-Hygiene Framework can be found https://ncc.cy/certification-scheme
Beneficiary & submission
Announcement Date: 08 Dec 2023 The Research and Innovation Foundation (RIF) in collaboration with the Digital Security Authority (DSA) as the National Cybersecurity Coordination Centre (NCC-CY), announce the Call for Proposals for the Programme "Enhancing Cybersecurity for Small and Medium Enterprises in the Republic of Cyprus 2023" and invites beneficiaries to submit relevant Project Proposals (Proposals). The Programme has a simple procedure for submitting proposals, short time for the evaluation and announcement of results and ensures timely implementation of projects in the pre-defined maximum implementation period for resolving problems faced by enterprises in cybersecurity matters. For the purposes of participating in the Programme and submitting a Proposal, a gap analysis is required. The gap analysis will determine an SMEs’ current cybersecurity situation in real time, at a technical, operational and strategic level in relation to the set of rules, control measures and procedures set out for establishing a basic level of cybersecurity as defined in the NCC-CY Cyber-Hygiene for SMEs framework and which are summarized as follows: 1.Security Policy Control Measure 1.1: The organisation's senior management has created, approved and communicated its cybersecurity policy internally and externally. The cybersecurity policy shall be reviewed at least once a year and updated as required. 2.Awareness and Training Control Measure 2.1: Staff employed by the organisation and users who have access to its information (regardless of their employment relationship) must be aware of information security and in particular how they contribute to it through their role. Appropriate cybersecurity awareness activities shall be carried out on a regular basis and at least once a year. Control Measure 2.2: Staff employed by the organisation and users who have access to its information (regardless of their employment relationship) receive education, training and information on the policies, procedures, security measures implemented by the organisation as well as relevant technological or organizational issues. The training provided shall be tailored to the security requirements of the different roles within the organisation. 3.Software Update Control Measure 3.1: The organisation's IT and communications systems must have the latest, stable security updates installed from trusted sources only (e.g. the manufacturer). Control Measure 3.2: Automated vulnerability scanning and penetration tests are implemented once a year. Control Measure 3.3: Information and communication systems that are no longer supported by their manufacturers with (at least) end-of-life security updates shall not be used by the organisation. 4.Protection from Malicious Software Control Measure 4.1: Malicious software protection programmes and functions are installed on all of the organisation's IT and communication systems and are updated on a regular basis. 5.Network Security Control Measure 5.1: The organisation has installed and configured firewalls at appropriate points in its network, in order to effectively protect its systems and information from relevant threats. Control Measure 5.2: If the organisation provides the capability for wireless access to the organisation's network, this should be done with appropriate routing and protection through the installed firewall(s). 6.Backups Control Measure 6.1: The organisation identifies its critical information and backs it up on a regular basis in alignment with the relevant backup policy. 7.Access Control Control Measure 7.1: The organisation identifies where important information is located. For each information type and based on its use and criticality, the organisation has created a structure in an appropriate storage area, which allows it to grant access rights to authorized and authenticated users following the need-to-know principle. Control Measure 7.2: The organisation has created an appropriate password policy, which is implemented in all its systems. Control Measure 7.3: Administrative rights or privileged rights (admin/privileged rights) are granted to a minimum necessary number of authorized staff. 8.Security Incidents Control Measure 8.1: The organisation has established structures and process for responding to security incidents. The staff involved in the respective procedures are appropriately trained. 9.Physical Security Measures Control Measure 9.1: The organisation has adopted physical security measures to protect systems and facilities from natural and environmental threats. 10.Data Protection Control Measure 10.1: The organisation designs, implements, approves and publishes a Personal Data Protection Policy based on the general GDPR regulation. 11.Operational Impact Analysis Control Measure 11.1: The organization has designed and implemented an appropriate methodology for operational impact analysis. The results and key figures resulting from the application of the methodology are recorded, maintained and utilized accordingly to design relevant measures and implementations. Depending on the analysis of the current situation of the company in relation to the above analysis, interested enterprises will prepare their proposal, which will include the list of solutions and services they intend to use in order to gain the “Cyber-Hygiene Framework for SME of NCC-CY” certification. SUBMISSION: Proposals are submitted through the Research and Innovation Foundation’s IRIS Portal (https://iris.research.org.cy/#!/). It is noted that, the Project Coordinator and all local participating organizations of the Cypriot Consortium, should register in advance on the IRIS Portal. Potential applicants are advised to read the general «Guide for Applicants» and «IRIS Portal User Manual» which can be found on the IRIS Portal (https://iris.research.org.cy/#/documentlibrary). Evaluation Procedure For the evaluation of the Proposals in this Call, a process of Preliminary Check and Evaluation by an Independent Evaluation Committee (IEC) will be followed. The committee will include experts with a background in business and specialization in cybersecurity issues. Proposals that meet all the criteria will be forwarded for evaluation by the members of the IEC. During the IEC session, the members rank the Proposals in order of priority (ranking list) and document the rationale for their decision in a relevant Evaluation Report. Upon completion of the process, the Evaluation Report from the IEC regarding each proposal will be communicated to the Project Coordinator. It should be noted that the work of the IEC will be supported by RIF staff. The final decision regarding the selection of a proposal for funding by the RIF, is at the discretion of the Committee. The Committee’s decision is final and cannot be appealed against. Evaluation Criteria 1. Relevance – Weight 30% Alignment of the Proposal and the expected project results with the objectives and activities described in this Call Degree of cybersecurity upgrading/development in the company in relation to the current state/operation of the company (holistic approach based on gap analysis and obtaining the Cybersecurity certification). 2.Added Value and Benefit – Weight 40% Degree to which the proposed project can ensure the expected results and deliverables stated in this Call. Effectiveness of the proposed actions in terms of visibility to demonstrate the benefits of the funding. Degree of enhancement of the competitiveness of the enterprise and effectiveness of the funding in terms of increasing the level of cyber security of the enterprise itself and thereby providing increased security to its customers and recipients of its services. Degree of positive impact on the overall operations of the business as a result of the increased level of cybersecurity (resilience, increased efficiency, reduced costs, exploitation of new capabilities/opportunities). 3.Implementation – Weight 30% Maturity of the proposed project and adequacy of the needs analysis based on the existing infrastructure in the Host Organization. Completeness and appropriateness of the action plan, timeline and budget for securing the products and services based on the gap analysis and certification. Completeness, quality and capacity of the Host Organization to carry out the project and implement the proposed objectives and action plan. Plan to ensure that the increased level of cybersecurity resulting from the funding is preserved over time. Selection Proposals deemed as eligible following proposal evaluation will be selected for funding according to their ranking. It is clarified that the total requested funding of selected projects will not exceed the total Call budget. The Host Organizations whose Proposals will be selected for funding will become beneficiaries by the 30th of May 2024.
Further information
SPECIFIC RESTRICTIONS AND CONDITIONS FOR PARTICIPATION The Host Organisation (HO) of the Project must be a small or a medium-sized enterprise. Each organization can only receive funding as a Host Organization once. Participation of entities engaged in an economic activity in a proposal shall be deemed valid, if they are legally established and are active in territories under the control of the Republic of Cyprus. The activity of the entities is documented by the existence of facilities and staff in territories under the control of the Republic of Cyprus and, indicatively and not restrictively, by audited financial statements, the tax return of the entity in the Republic of Cyprus, etc. These conditions should be met to the satisfaction of RIF and without prejudice to the Foundation to request further data and information from the entities. Upon completion of the projects, each SME will be required to undertake at least one publicity activity (media/social media publication, video, event, etc.) highlighting the achievement of the Certification following the implementation of the funded project, with references to the benefit derived from the funding. For publicity actions, the obligations for promotion and publicity for projects funded by the Digital Europe Programme should be applied, including the logos of the NCC-CY, the Research and Innovation Foundation (RIF), the Commissioner of Communications and the Digital Security Authority, as well as reference to the co-funding by the Republic of Cyprus.