Skip to content
V1-D03-C04
Iraq Vision 2045 · Part Three: Security, Defence and Deterrence
V1-D03-C04

Cybersecurity and New Forms of Security

From Protecting Systems to the Resilience of the Digital State Under the Law

Data freeze: 27 August 2026 · Version 1.0

1. Executive Summary

This chapter opens the fourth and final layer of the security system in Iraq Vision 2045. After this part defined security, deterrence and readiness, designed the military institution responsible for defence, and distinguished internal security and intelligence from the army, the question becomes: what happens when those institutions themselves depend on data, communications, software, platforms and algorithms? The connected state can work faster, but also carries a larger attack surface and new dependencies. Cybersecurity therefore becomes part of state continuity, not a technical appendix to computer departments.

Iraq is not starting from zero. Since 2025, the National Cybersecurity Centre has been an official body within the Prime Minister's Office, with broad published responsibilities: proposing strategy, policies and standards; assessing compliance; managing national risks; protecting critical digital infrastructure; warning and responding to major incidents; receiving reports; training; and cooperation. Meanwhile, the Iraqi Cybersecurity Strategy 2022–2025 has reached the end of its time horizon, and no published specialist successor for the following period had appeared by the research freeze on 27 August 2026. The problem is therefore less the absence of an authority than translating its mandate into an implementation, measurement and updating cycle.12

The International Telecommunication Union's Global Cybersecurity Index 2024 provides a useful external baseline, and no more: Iraq is in Tier 4 — Evolving, with pillar scores totalling 53.07 out of 100. This score measures commitment and institutional maturity across legal, technical, organisational, capacity-building and cooperation dimensions; it does not measure the percentage of “network security”, incident-detection time or service-recovery time. Because 53.07 matches the value displayed by the National Centre as the “National Readiness Index”, the chapter adopts a methodological decision: the value is interpreted as reflecting the GCI score unless an independent Iraqi operational methodology is published.3

The proposed vision organises cybersecurity as a recurring capability: governance, understanding assets and risks, protection, detection, response, recovery and learning. It places central governance in policy, standards and national-incident leadership, with distributed implementation across ministries, sectors and infrastructure and service owners. It treats resilience—not “preventing every breach”—as the governing outcome: what keeps working? How quickly is deviation detected? How long does containment take? Does service return within an acceptable time? Was the root cause addressed after the incident?4

On rights, the chapter does not equate security with surveillance. The Constitution protects privacy, confidentiality of communications and freedom of expression, and sets limits on restrictions. Purpose, necessity, proportionality, data minimisation and oversight therefore remain fundamental to every digital security system. On artificial intelligence, Iraq has established a National Artificial Intelligence Centre, but official sources in 2026 still describe the national strategy as under development. This chapter's task is therefore security and governance: inventory high-impact systems, assess their risks, protect their data and models, and retain human decision-making responsibility where effects on rights or security are high.56

2. From Internal Security to Protecting the Connected State

The preceding chapter established that professional internal security is not measured by the volume of information collected, and that intelligence or an algorithm does not automatically become a conviction. It left an entire layer outside its scope: databases holding reports, communications transmitting orders, case-management platforms, systems hosting evidence, and digital services used by citizens, police, banks, hospitals and military forces. When this layer fails, the effect is not necessarily “technical”: a public function may stop, or a previously limited crisis may expand.

The chapter therefore asks not “Did the incident occur online?”, but “What is its impact?” A compromised personal account or individual fraud usually remains a crime or technical incident within ordinary jurisdiction. Widespread disruption of a national payment service, loss of highly sensitive data, or failure of a system essential to government, defence or critical infrastructure may exceed a single institution's capacity and become a national-security matter requiring higher-level leadership, coordination and decisions.

3. What Is National Cybersecurity?

This chapter adopts an operational definition of cybersecurity as national management of risks to digital systems, data and services, protecting confidentiality, integrity and availability while adding detection, response, recovery and learning to prevention. The definition puts “function” before “tool”: a firewall, monitoring platform or operations centre is a means; the outcome is reliable service, reduced incident impact and institutional learning.

Cyber resilience is the ability of a digital function to continue or return to an acceptable level after an incident. This matters because “preventing all breaches” is unrealistic even for the most mature states and institutions. Advanced security does not accept breaches as normal; it assumes they can occur and designs layers of prevention, detection, containment and restoration around that possibility. NIST Cybersecurity Framework 2.0 adopts the same logic through GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER.

Figure 1: The national cyber-capability cycle

Source: NIST Cybersecurity Framework 2.0, 2024.

Methodological note: “Learn” is added as a post-incident institutional-learning stage.

3.1 Jurisdictional Boundaries: Cybersecurity, Cybercrime and Cyber Defence

The chapter helps prevent overlapping roles before proposing any programme. Cybersecurity focuses on reducing system and service risks and maintaining continuity. Cybercrime focuses on establishing criminal conduct, investigation, evidence and justice. Cyber defence focuses on protecting military networks and capabilities within the defence system. Data protection regulates individual rights and processing safeguards, while information integrity concerns the public sphere's resilience against organised manipulation. These functions converge during a major incident, but do not become one institution.

Table 1: Functional boundaries between cybersecurity, crime, defence and data protection
Field Purpose Lead authority/approach Output
Cybersecurity Reducing risks and maintaining functions National Centre + regulators + service owners Standards, assessment, warning, response and recovery
Cybercrime Establishing the crime and holding the perpetrator accountable Law enforcement, investigation and judiciary Evidence, referral, judgment and enforcement
Cyber Defence Protecting digital military capabilities Ministry of Defence and military command within their competence Defence readiness and continuous military networks
Data Protection Protecting individual rights and regulating processing A specialised civilian legal and oversight framework Rights, obligations and enforcement
Information Integrity Reducing the harm of organised manipulation Government communication + media and society + platforms within the law Transparency, correction, resilience and protection of expression

Source: the Iraqi Constitution and applicable laws according to jurisdiction.

4. Where Does Iraq Stand? A Baseline That Distinguishes Maturity from Readiness

Iraq's situation between 2024 and 2026 reveals two parallel tracks. The first is institutional: creation of the National Cybersecurity Centre with broad powers, and emergence of sectoral regulations, exercises and training programmes. The second concerns measurement: public data still provide no unified national dashboard for incident detection, containment and recovery times, multifactor-authentication coverage, completion of critical-asset inventories, or successful backup and restoration tests. The vision must therefore not fill these gaps with other countries' figures or expert estimates.

GCI 2024 shows variation among pillars: organisation at 15.77/20 is relatively stronger, while the technical pillar is 9.60, capacity development 8.38, cooperation 8.11 and legal measures 11.21. This does not mean “Iraq is technically weak by a particular percentage”; it means institutional development has advanced faster than some layers of implementation, skills and cooperation. Early years should therefore not spend most resources on additional tools before defining the assets, functions, skills and obligations that will operate them.

Table 2: A concise cybersecurity-maturity baseline and its limits
Dimension Verified baseline Year Decision on Use
Overall GCI 53.07/100; Tier 4 — Evolving 2024 An external commitment/maturity index, not operational readiness
Legal Measures 11.21/20 2024 A relative legislation/enforcement gap
Technical Measures 9.60/20 2024 Priority for stronger technical implementation and measurement
Organizational Measures 15.77/20 2024 Relative governance strength
Capacity Development 8.38/20 2024 One of the relatively weaker pillars
Cooperation 8.11/20 2024 A cooperation and capability-sharing gap
MTTD/Containment/Recovery No unified public national baseline 2026 Established in 2027–2028; internal data may exist
National Centre coverage 500+ institutions and 24/7 monitoring, according to the official website 2026 An announced operational figure requiring definition of the scope of “protection”

Source: ITU Global Cybersecurity Index 2024; National Cybersecurity Centre official website. 8

The chapter's most important data decision is to distinguish measurement gaps from legitimate secrecy. An institution may hold response times, asset lists or incident details that should not be published; this is not “absence of data”. Conversely, if institutions use different incident definitions, or the state cannot aggregate sectoral containment times, that is a genuine measurement gap requiring correction. The public document should publish appropriate aggregates, not details that help an attacker or expose a weakness.

4.1 The Legal Framework: Do Not Fill the Protection Gap with a Single Law

Iraq's digital legal environment is distributed among the Constitution, sectoral legislation and standards, institutional instructions and developing legislative proposals. The starting point is not an “all-encompassing cyber law”, because functions differ: personal-data protection needs processing rights and oversight; cybercrime needs defined offences, procedures and safeguards; cybersecurity needs compliance, reporting and continuity standards; and communications and platforms have sectoral regulation. Conflating them may produce a broad text with weak functionality.

As of production, the proposed Law on Combating Information Technology Crimes remained in the legislative process: the Council of Representatives held its first reading on 6 July 2026, and the Security and Defence Committee continued discussing and refining it on 26 August 2026. The chapter therefore bases no power or penalty on an assumption that it is in force. If subsequently enacted, it should be assessed by its criminal and procedural functions and safeguards, not treated as a substitute for data protection or cybersecurity governance.7

For data protection, the Constitution provides a basis for privacy and confidentiality of communications, and sectoral instruments, privacy policies and digital regulations exist. However, verification through the freeze date did not establish a single comprehensive federal framework combining the basis for processing, minimisation, purpose, retention, sharing, individual rights, breach notification and cross-border transfers. Reform must fill these functions, through a general law or an integrated package if constitutional and regulatory arrangements justify it. The essential point is that citizens' rights must not remain scattered across terms of service and instructions without a clear enforcement pathway.

Sectoral regulations from the Communications and Media Commission also emerged in 2025–2026 for cybersecurity services, data centres and digital platforms. They matter because they establish the digital market itself as a regulatory subject. Multiple regulations, however, increase the importance of alignment: providers should know which national standard applies, which regulator reviews them, and how sectoral requirements align with the National Centre without conflict or repeated audits.8

Table 3A: The legal and functional map of digital security

Instrument Status at the freeze date Function Chapter decision
Constitution of 2005 In force Privacy, communications, expression and limits on restrictions The overriding rights reference
Prime Minister's Office Instructions 1/2025 In force/published The basis for the NCC, NCAI and their mandates Principal institutional reference
Cybersecurity Strategy 2022–2025 Its time horizon has ended Previous objectives, governance and readiness assessment Review and update; do not disregard
National Security Strategy 2025–2030 In effect as a strategy The broader security framework Connects cybersecurity to national security
Information Technology Crimes proposal, 2026 Not in force as of 26 August Potential criminalisation and procedures No effective jurisdiction is based on it
CMC digital regulations, 2025–2026 Published sectoral regulations Security providers, data centres and platforms Align with national governance
Comprehensive data-protection framework A comprehensive federal law had not been verified by the freeze date Rights, processing safeguards and enforcement A reform gap that must be closed

Source: Constitution of the Republic of Iraq; Instructions on the Formations and Functions of the Prime Minister's Office No. (1) of 2025; Iraqi Council of Representatives; Communications and Media Commission.

4.2 A National Maturity Model: Institutions Do Not All Start at the Same Level

Moving from a general international indicator to actual management requires a simple national maturity model. It does not assume that a ministry, bank and industrial facility are at the same level, or aim to give every institution the same certificate. Its purpose is to identify the starting point and improvement path: is the process unstructured and dependent on individuals? Has it been documented? Is it actually applied? Is it measured? Does it adapt after incidents and technological change?

This model prevents two errors. The first is spending on advanced technology while the institution does not know its assets or their owners. The second is turning maturity into a punitive public ranking that discourages reporting. Details therefore remain internal; only aggregate sectoral progress is published, with sensitive information protected.

Table 3B: A simplified national cyber-maturity model

Level Description Practical test Required transition
1 — Unstructured Fragmented procedures dependent on individuals No stable inventory or unified incident plan Define assets, owners and basic policy
2 — Documented Policies and plans exist Documents do not establish implementation Training, implementation and monitoring
3 — Implemented Controls operate within a defined scope Outcomes are insufficiently measured Define indicators and test recovery
4 — Measured Time, impact and compliance are known Improvement may remain slow Causal analysis and cross-institutional learning
5 — Adaptive Standards change with threats and technology Requires data and a mature institution Maintain renewal without permanent emergency

5. From a New Institution to a Functioning Governance Cycle

The 2025 Instructions on the Formations of the Prime Minister's Office made the National Cybersecurity Centre a clear focus of federal governance, assigning functions beyond technical monitoring to policy, standards, readiness, risks, critical infrastructure, response, training and cooperation. The vision therefore does not need a second “cyber authority”. It needs these mandates translated into measurable responsibility rules: what does the Centre establish? What does the regulator implement? What does the sector own? What must be reported? Who leads when an incident exceeds institutional capacity?

The most suitable model is central governance with distributed implementation. The Centre sets national standards, aggregates the risk picture, measures maturity and leads or coordinates national incidents; sectoral regulators translate the minimum standard into obligations suited to banking, communications, energy or transport risks; and every service owner remains responsible for assets, personnel, plans and budgets. The private sector does not become a government arm, but cannot operate critical infrastructure outside security and reporting obligations.

Table 3: Central governance and distributed implementation model
Function National level Sectoral/institutional level
Policy and standards National framework and periodic updating Sectoral alignment and implementation procedures
Risk management Aggregate national risks and identify CII Asset and function risk register
Monitoring National picture and aggregate threat intelligence SOC/monitoring function as needed
Response Leadership/coordination of major national incidents CSIRT or the institution's incident plan
Compliance Define outcomes and measure maturity Implementation, audit and correction
Continuity Cross-sector standards and exercises RTO/RPO, plans and tests
Rights National rules and legal oversight Purpose Limitation and access and retention controls

Source: Instructions on the Formations and Functions of the Prime Minister's Office No. (1) of 2025.

5.1 A Strategy Cycle, Not a Periodic Document

The Iraqi Cybersecurity Strategy 2022–2025 did not become worthless when its dates expired. It included readiness assessment, asset inventory and classification, governance, critical-infrastructure protection, response and recovery. The task in 2027 is a closure review: completed, partially completed, unimplemented, transferred to a new mandate or no longer suitable objectives. An updated strategy cycle linked to the National Security Strategy 2025–2030 then follows, reviewed every four years or after a major change in risks.9

This changes strategy from an “objectives document” into a learning mechanism: assessment → priorities → programmes → financing → indicators → review → update. If a new specialist strategy is issued after this chapter's freeze date, it replaces the implementation assumption that “updating is required”, without removing the need for the institutional cycle itself.

6. Protecting Digital Infrastructure: The Critical Function Before the Server

The second pillar begins not with a list of ministries or servers, but with a question: which functions can society or the state not tolerate losing for long? Electricity, communications, payments, water, health, transport and essential government services are categories of potentially critical functions, but “critical” does not mean “government-owned”. A service may be run by a private company, public body or several institutions; its criterion remains the impact of disruption, not asset ownership.

The vision therefore proposes defining Critical Information Infrastructure according to functional impact: people affected, tolerable downtime, safety effects, economic and security effects, available alternatives and interdependence with other sectors. The detailed asset register should be sensitive or classified according to its nature, while sectors, categories and general requirements can be announced. Singapore's model is useful as a designation, obligation and oversight mechanism, not as a ready-made law to replicate.10

Table 4: Criteria for designating critical information infrastructure
Norm Classification question Effect on the CII decision
Scale of impact How many people/institutions are affected if the function stops? Greater impact raises protection priority
Tolerable downtime How long can the service stop before substantial harm occurs? Determines RTO and continuity requirements
Safety Could disruption cause physical or health harm? Raises OT and response requirements
Alternatives Is an alternative service available within a reasonable time? Absence of an alternative increases criticality
Interdependence How many other functions depend on it? Creates priority for addressing cascading failure
Sovereignty/security Does failure affect defence or national decision-making? May elevate the incident to national level

Source: Cyber Security Agency of Singapore, Cybersecurity Act and Critical Information Infrastructure materials.

6.1 From IT to OT: When Bits Produce Physical Effects

Operational technology and industrial control systems, OT/ICS, differ from conventional information-technology environments. Updating an office system may tolerate a brief outage; a system controlling a physical process may place greater priority on safety and continuity, operate for many years and not accept updates in the same way. A single security policy must therefore not be applied automatically to every system.

The required strategic level comprises inventories of systems and functions, boundaries between IT and OT, supplier and change management, appropriate configuration backups and recovery data, alternative operating plans and recovery tests. IEC 62443 can serve as a reference for industrial sectors, not a “mandatory certificate” for every system.11

6.2 Interdependence: Protect the Function Whose Failure Spreads

Digital sectors do not operate as islands. Communications outages may disrupt banking and emergency services; electricity failures may affect data centres and communications; identity or payment-service failures may block multiple government transactions simultaneously. The state therefore needs a qualitative dependency map identifying interconnected functions, alternatives and tolerable downtime, while keeping asset and connection details confidential where necessary.

This shifts investment from “protecting the most expensive asset” to “protecting the function whose failure spreads”. The logic accords with the British Cyber Assessment Framework, which measures protection of essential functions, response, recovery and subsequent learning rather than formal adherence to a single tool.12

6.3 The Risk Map: Threat ≠ Vulnerability ≠ Dependency

The national map should not conflate three different things. A threat is an actor or event capable of causing harm; a vulnerability is a weakness in design, operation, identity, updating or procedure; a dependency is a connection to a service, supplier or sector through which failure can spread. Calling a vulnerability a “threat” pushes an institution to buy a tool against an adversary when the problem is internal. Calling a dependency a “vulnerability” may obscure that the solution is contractual or continuity-related, not solely technical.

Near-term priorities concentrate on categories with broad, cascading impact: ransomware affecting government or critical services; supply-chain compromise; leakage of highly sensitive data; OT incidents; supplier or cloud failure connecting multiple services; insider privilege abuse; and AI-enabled fraud or disinformation. Post-quantum risks belong in long-term planning, not the daily emergency list. The chapter provides no falsely precise numerical probabilities; these are developed after a National Risk Register and years of incident data.

Table 4A: A qualitative, non-operational cyber-risk map

Risk category Potential Effect Horizon 2027–2030 priority Publication type
Widespread ransomware Disruption, leakage and extortion Near term High Public aggregates + internal detail
Supply-chain compromise Spread through a trusted supplier Near/medium term High Internal/restricted
OT/ICS incident Physical, safety or economic disruption Near term High Legitimate secrecy for details
Cloud/Supplier failure Disruption of interconnected services Medium Medium–high. Internal
Data breach Privacy, trust and security Near term High Public aggregates
AI-enabled fraud/deepfake Fraud, crisis deception and trust Near term High Public aggregates
Post-quantum exposure Long-lived cryptographic assets Long term/high uncertainty Low-cost preparedness Internal inventory

7. The National Minimum: A Few High-Impact Controls

Where institutions differ in maturity, the first practical step is not to demand a complex system from every organisation, but to define a clear national floor. This minimum rests on required outcomes: knowing each asset and its owner, controlling identity and permissions, strong authentication for sensitive accounts, risk-based updates, recoverable backups, logging and review, an incident plan, training and supplier management. The minimum does not mean a “single government product”, nor prevent critical sectors imposing higher requirements.13

The minimum should be measured by effectiveness, not tick-box completion. An institution claiming to have backups without testing restoration has no confirmed capability; one with a SOC but no analysts or decision authority may possess a room of screens rather than a security function. Each control therefore has an output: protected privileged accounts, classified assets, successful restoration, alerts with a response pathway, and assessed critical suppliers.

7.1 Identity and Access: Who Has the Right to Enter?

Incidents do not always require complex technology to cause major harm; an account with broad privileges may matter more than a new server. Government security must therefore manage the identity life cycle: appointment, transfer between roles, departure, permission reviews and separation of duties. Privileged accounts need stronger protection and review, and multifactor authentication is a fundamental tool for critical accounts where appropriate.

This section does not rebuild national digital identity. It establishes a simpler requirement: institutions must know who enters a sensitive system, why access is needed, whether it is still needed, and what the user did. As an asset's impact rises, Least Privilege, audit logs and periodic reviews become more important.

7.2 Backup Does Not Equal Recovery

Backups become capability when restored. Every critical-function owner therefore needs an RTO—the target time to restore the function—and an RPO—the acceptable amount of data loss upon recovery—and must test rather than assume them. There is no single national value: a real-time banking function or emergency service differs radically from an information website that can wait hours or days.

Iraqi sectoral models already using RTO/RPO and restoration tests, such as insurance-sector governance requirements, demonstrate that the concept can become a local obligation rather than remain a foreign borrowing.14

8. The Cyber Incident: From Alert to Recovery and Learning

The National Centre's instructions assign it a role in major-incident response and establishing a reporting contact centre. This authority must become a severity dictionary and escalation thresholds: what must a ministry or company report? Within what time? What minimum information is required? Who decides when an incident moves from institutional to sectoral or national level?

Poor design punishes an institution for reporting, encouraging concealment. Better design distinguishes good-faith reporting, gross negligence, deliberate concealment and non-compliance. It provides confidentiality rules and protection for commercial and personal information, alongside clear obligations to report incidents of defined impact.

Capability is measured by stages: MTTD for incident detection, containment time after detection, function-restoration time, the share of material incidents undergoing Post-Incident Review, and the share of root-cause actions closed on time. Alert counts alone are unsuitable: they may rise because detection improved, attacks increased or definitions changed.

Table 5: Response indicators and what should not be inferred from them
Measure What does it measure? What may distort its interpretation?
MTTD Time from a detectable event to its detection Affected by monitoring quality and the definition of incident onset
Containment time From detection to stopping the spread of impact Requires a unified severity classification
Recovery within RTO Restoration of the function within its target time Tests must be distinguished from real incidents
Root Cause Closure Closure of actions to prevent recurrence Does not measure the incident's severity itself
Number of incidents Cases under a unified dictionary Affected by detection, reporting and definitions
Number of alerts Volume of monitoring signals Neither the number of “attacks” nor success in itself

Source: NIST Cybersecurity Framework 2.0; UK National Cyber Security Centre, Cyber Assessment Framework.

8.1 Exercises: Test Decisions, Not Technical Displays

A cyber exercise is not a competition to penetrate systems, but a test of the decision mechanism. A tabletop exercise may reveal that a ministry does not know who declares a crisis, a sector does not know when to notify the Centre, the communications team lacks an initial message, or the recovery copy has not been tested. These gaps may be more dangerous than an individual technical vulnerability because they amplify an incident's effects after it occurs.

The vision proposes three layers: institutional exercises testing incident and restoration plans; sectoral exercises testing dependencies among companies and regulators; and a periodic national exercise testing escalation, decisions, communication and continuity. Scenarios revealing real weaknesses are not published, but aggregate institutional lessons can be: where were decisions delayed? Did the alternative work? Were corrective actions closed?

The exercise indicator is not the “number of exercises”. The outcome is the share of corrective actions closed afterwards, decision time, and teams' ability to restore a function within its standard. Exercises thus become live audits of resilience rather than media events.

9. Data: Protection and Sovereignty Without Geographical Slogans

Data become more valuable as the state becomes more connected. “Data protection”, however, is not synonymous with cybersecurity alone: it also concerns rights, purpose, processing, retention and sharing. The Iraqi Constitution protects privacy and confidentiality of correspondence and communications. The digital state needs to translate this protection into more integrated operational rules for personal data. No single comprehensive federal law comparable to modern integrated frameworks had been verified by 27 August 2026. This means a gap in the general framework, not an absence of all sectoral privacy rules.

The design rule is Data Minimization and Purpose Limitation: institutions collect what they need for a lawful purpose, not whatever they can technically collect, and do not reuse data for a fundamentally different purpose without a legal basis. Retention periods, sharing, access, correction and breach notification should be clearly defined wherever possible.

9.1 Data Sovereignty Is Not the Server's Location

The chapter defines data sovereignty as the legal and practical capacity to set rules, control access, know suppliers, audit, manage appropriate elements of control, transfer data, possess a copy or alternative, and exit dependence. Data Localization therefore does not equal sovereignty: data may be inside the country while operation, keys, support or licensing depend on a party that is difficult to replace. Conversely, the state may use an external service whose contract, controls, portability and alternatives are stronger than those of an unauditable local service.

Table 6: Data localisation versus data sovereignty
Question Data Localization Data Sovereignty
Location Where are data stored? One element of the picture
Jurisdiction May be domestic Who holds legal authority?
Access Does not guarantee who gains access Defined and auditable permissions
Supplier May remain an external monopoly Assesses replaceability and exit
Transfer May be geographically restricted Assesses portability and continuity copies
Outcome Geographical localisation Practical and legal control and alternative capability

10. Suppliers and the Cloud: Dependence Measured by the Ability to Exit

National digital security depends on long supply chains: hardware, software, libraries, contractors, cloud services, updates and managed tools. An attack may pass through a trusted supplier instead of targeting each institution separately. Technology procurement must therefore move beyond price and immediate specifications to the life cycle: who owns the data? Can the state audit? How long is update support provided? What is the End-of-Life plan? Can the service be moved? How does it operate if the supplier stops?

Vendor Lock-In is not automatically corruption or “betrayal of sovereignty”. It is a technical, financial, operational and sovereign risk when a critical function cannot be transferred within acceptable time and cost. Dependencies are therefore classified as ordinary, requiring diversification, or critical and requiring an alternative, exit plan or domestic capability. Every critical contract should define Data Ownership, Portability, Audit Rights, Patch Support and an Exit Plan as far as law and market conditions permit.

Table 7: Classifying and managing digital dependence
Dependency type Description Management decision
Ordinary Replaceable supplier and portable data Routine commercial and security management
Requires diversification Change is possible but slow or costly A second alternative, standardisation and transition plan
Critical Supplier failure stops a national function, or exit is difficult Recovery plan, robust contracting, alternative/domestic capability and leadership review
Cloud concentration Several critical functions rely on one provider Dependency Map, failure-scenario test and exit plan

The cloud is neither a risk nor a solution in itself. Decisions should balance data sensitivity, jurisdiction, continuity, institutional management capacity, audit, portability, access management, sovereign elements and exit planning. Public Cloud, Private/Government Cloud and Hybrid models serve different purposes. Architectural detail belongs in the technology parts; the security question here is whether the state remains able to operate the function and change suppliers when necessary.

11. Cyber Defence and Deterrence: Making Attacks Less Rewarding

This chapter takes only the strategic boundary from “The Professional National Army”: modern armed forces depend on networks, communications, command and control, digital platforms and technological supply chains, and therefore need protection, continuity and Iraqi incident-leadership skills within defence networks. The chapter provides no offensive capabilities, targets, vulnerabilities or operational plan; such information is unnecessary for the public vision and should not be published.

Cyber deterrence is more complex than military deterrence because attribution may remain probabilistic, actors are numerous, and much activity occurs below the threshold of conventional conflict. Iraq's near-term deterrent foundation is therefore denial and resilience: reducing the chance of success and the resulting impact, rapid recovery, legal and diplomatic cooperation, and increasing the cost of exploiting the system. The vision does not recommend “hacking in response to hacking”.

12. Disinformation: Protecting the Information Environment Without a “Ministry of Truth”

A cyberattack targets a system, data or service; information manipulation targets perception, trust, behaviour and decisions, and the two may overlap. The chapter therefore distinguishes unintentional Misinformation, intentional Disinformation designed to mislead, Malinformation using true or partial information in a harmful context, and wider influence operations. An informational error alone is insufficient to make something a national-security case.15

Manipulation rises to a security level when it is widespread, organised and deliberate and linked to substantial harm: inciting violence, disrupting emergency response, large-scale deception during a crisis, or undermining a sensitive national function. Criticism, satire, opinion, opposition and an isolated inaccurate report do not automatically become “threats”. This boundary prevents digital security becoming an overarching jurisdiction above politics and society.

The alternative to a “ministry of truth” is Information Integrity: government channels publishing original data promptly, responsible strategic communication, documented correction, support for independent verification and research, awareness, and platform transparency where regulated by law. Success is not measured by deleted posts, but by the time needed to correct critical government information, the public's ability to verify it, and trust in emergency channels. This approach accords with the Global Digital Compact's emphasis on a more trustworthy information environment and respect for rights.

Figure 2: The response pathway for information manipulation with widespread impact

12.1 Deepfakes: Verification Speed Becomes a Security Capability

Synthetic generation raises verification costs: an official may be impersonated through audio or video, fabricated content used in fraud or a crisis, or evidence confused. This is not solved by one “deepfake detector”; detection tools themselves are probabilistic. A more robust response combines verifiable official channels, Content Provenance where available, verification training for media and institutions, and rapid government communication that does not leave an information vacuum.

Time becomes a security indicator here: how long does it take to confirm or deny information affecting a national function or public safety? Is there an accountable spokesperson? Are updates dated and retrievable? Does the state correct its error if its first assessment proves incomplete? Informational trust is built more through such behaviour than through surveillance.

12.2 Internet Shutdowns: A Last-Resort Instrument, Not a Routine Cybersecurity Measure

Iraq's recent history includes widespread internet shutdowns during the 2019 protests; the United Nations documented their effects on information flows and freedom of expression. This experience makes any broad communications disruption an exceptional option subject to a strict legal test: legal basis, necessity, proportionality, less harmful alternatives, a defined duration and review. Its effects on emergencies, payments, businesses and security itself must also be weighed, rather than assuming that disconnecting a network automatically “increases security”.16

13. The State in the Age of Artificial Intelligence

Artificial intelligence is not a separate “security sector”, but changes both sides of the equation: attackers can accelerate fraud, social engineering, disinformation and vulnerability analysis; defenders can triage alerts, analyse logs, detect patterns and assist analysts. It is therefore insufficient for the state to be an “AI user”: it must know where AI is used, the decision's impact, the data accessed and who bears responsibility.

Iraq established the National Artificial Intelligence Centre within the Prime Minister's Office in 2025, while the national strategy's official website still describes it in 2026 as under development. This chapter therefore creates no new centre and formulates no economic AI policy; it establishes a security and rights gate before high-impact uses spread.17

13.1 Risk-Based Governance

Not every AI system needs the same procedure. A limited internal summarisation tool differs from a system affecting personal liberty, service eligibility, a security decision or critical infrastructure. The vision therefore proposes impact-based classification: low, medium and high impact. Higher impact brings stronger requirements for inventory, impact assessment, data governance, testing, documentation, monitoring, and appeals and human review.

Table 8: AI governance according to impact level
Governance element Low-impact use High-impact use
Inventory Simple functional registration A clear central/sectoral register and accountable owner
Impact assessment Light review Impact Assessment before deployment and after material changes
Data Institutional policy Documented source, quality, rights and purpose
Security General baseline AI Security, testing and supply chain
Human review As needed Meaningful Human-in-the-Loop/On-the-Loop
Audit Operational log Auditability, decision records and an appeal pathway
Shutdown Routine procedure Kill/rollback procedure in the event of danger or material deviation

Source: NIST AI RMF; UNESCO Recommendation on the Ethics of AI;. 20 21

13.2 Human-in-the-Loop: Responsibility Does Not Transfer to the Algorithm

The governing principle is not to prohibit automation, but to make human oversight proportionate to decision impact. A system may sort, alert, summarise and suggest; decisions affecting liberty, rights, legal entitlements, use of force, or a security classification directly producing punitive consequences require meaningful human review and an accountable person.

The new rule connects to the preceding chapter: More Data ≠ Better Intelligence, joined by More AI ≠ Better Intelligence. A faster model may amplify data errors, bias or hallucinations. And AI Output ≠ Verified Intelligence: automated output requires verification of source, context and confidence before use in a security or legal decision.

13.3 AI Security: Protect the Model, Not Only the Network

AI Security extends beyond protecting the server running the model. Risks include data poisoning in its general sense, sensitive-data leakage, model theft or misuse, untrusted components and suppliers, hallucinations, and excessive reliance on output. In a vision chapter, this category requires no exploitation techniques; it requires procurement, assessment, testing, monitoring and responsibility rules, and an incident plan.

In government procurement, the security questions become: where are data processed? Are they used to train the model? Who owns them? Can auditing occur? How long are they retained? Can the service be moved? What alternative exists if the supplier changes? This does not mean every government model must be “Iraqi”; it means high-impact dependence must be understood, manageable and capable of exit.

14. Personnel: The Bottleneck Licences Cannot Solve

GCI places capacity development among Iraq's relatively weakest pillars. This gap differs from purchasing a security platform: a system without an analyst, engineer, incident responder or leader able to decide becomes supplier-dependent even if the product is world-class. In 2027, the state therefore needs a Workforce Assessment beginning with functions, not publicity figures.

Critical roles may include Incident Response, SOC Analysis, GRC, Security Architecture, IAM, Digital Forensics, OT Security, Cloud Security, Threat Analysis and AI Security. Each pathway needs a role description, skills, practical training, assessment and promotion. Public service needs tools to attract and retain expertise in a market competing locally and internationally. External suppliers may be used, but Outsource Service ≠ Outsource Accountability.

Universities are part of the personnel supply pipeline, not substitutes for operations. Laboratories, practical training, partnerships and lawful research projects are needed, not certificate counts. The private sector is a national partner because important parts of communications, finance, energy and digital services are operated outside government. It needs obligations, standards, reporting and disciplined information sharing, not a relationship of “a customer buying protection from the state”.

14.1 The Private Sector and Threat-Information Sharing

Private or mixed-ownership companies operate parts of communications, payments, cloud services, energy and digital services. Government cannot therefore see the entire national environment through its own networks alone. Information sharing, however, needs design that protects commercial secrets and personal data and prevents a central repository for everything. What is shared is what the other party needs to reduce risk or manage an incident, at the appropriate classification and time.

Sectors can use threat-sharing channels or communities, but this chapter does not require a new ISAC for every sector. The function may already exist within a regulator, association or joint operations room. The test is whether information reaches those who can act, whether recipients know its confidence level and permitted use, and whether access to sensitive data is logged.

Mandatory reporting of critical incidents differs from voluntary sharing of indicators and experience. The former needs a legal definition, time threshold and good-faith protections; the latter rests on trust and mutual benefit. Combining them without distinction may lead companies to avoid cooperation for fear of liability or reputational damage.

15. A Few Standards, with a Clear Function for Each

The vision uses international standards as instruments translating arguments into measurement. NIST CSF 2.0 provides a national language for governance, risks and the operational cycle. ISO/IEC 27001 supports information-security management systems for mature institutions and appropriate contracts. IEC 62443 serves OT. ISO 22301 assists business continuity. NIST AI RMF and ISO/IEC 42001—where appropriate—provide frameworks for AI-risk governance. These names should not become a list of mandatory certifications.

Table 9: Selected standards and their functions
Framework Function in the vision What it does not mean
NIST CSF 2.0 National language for governance, outcomes and the risk cycle Not a product list or law
ISO/IEC 27001 An information-security management system for suitable institutions and contracts Certification does not mean absence of risk
IEC 62443 A reference for OT industrial-system security Not applied literally to all IT
ISO 22301 Business continuity and testing recovery capability Does not replace sectoral technical and operational plans
NIST AI RMF Assessing and managing high-impact AI risks Not an AI law
ISO/IEC 42001 An AI management system for suitable institutions Compliance does not eliminate rights review

Source: NIST; ISO/IEC.

16. What Do We Learn from Abroad? The Mechanism, Not the Country

Comparison requires specific mechanisms. Singapore offers lessons in CII designation and obligations for essential-service owners and regulators. The United Kingdom offers the NCSC model and Cyber Assessment Framework, focused on outcomes, essential functions, response and recovery. Through CISA, the United States highlights a small, high-impact minimum and partnerships with infrastructure owners. Estonia offers lessons in state continuity, exercises and distributed capability after digital crises. Finland helps integrate information resilience into comprehensive security. No country's size, law or institution is copied; governance functions suited to Iraqi mandates are transferred.

Table 10: Selected international comparisons
Case Mechanism What suits Iraq What not to copy
Singapore CII designation and sectoral obligations Impact criterion + function owner + reporting and exercises Administrative concentration and country size
United Kingdom NCSC + outcomes-based CAF Assessment and measurement of functional resilience The legal and institutional structure unchanged
United States CISA, critical-infrastructure partnerships and CPGs A high-impact minimum + sectoral partnership Resource scale and detailed federal arrangements
Estonia Continuity, exercises and a digital state Recovery testing and distributed capability Country size and digital-identity architecture
Finland Comprehensive security and information resilience Crisis communication and participation by society and the private sector The entire political-administration model

Comparative sources: Cyber Security Agency of Singapore; UK National Cyber Security Centre; CISA; and relevant official Estonian and Finnish sources.

17. Threats in 2045: Scan the Horizon Without Turning Every Trend into a Project

In the near term, ransomware, supply chains, data leakage, deepfakes, AI-enabled fraud, OT risks and cloud-service concentration remain directly relevant. In the medium term, IoT, smart infrastructure, autonomous systems, intelligent agents and dependence on advanced communications and space services will intensify. Further ahead, post-quantum risks arise for long-lived assets and cryptography. These are not “inevitabilities”: they are Horizon Scanning, elevating a trend into a programme only when probability or impact changes, or long-lived assets justify early investment.

In post-quantum cryptography, for example, uncertainty does not justify an immediate wholesale replacement programme. The more rational starting point is a Crypto Inventory and Crypto-Agility Planning for long-lived assets, so the state knows what needs transition, when and at what cost. This philosophy protects the vision from chasing technological fashion instead of building renewable capability.

17.1 Strategic Scenarios That Do Not Reveal Weaknesses

Scenarios help identify capabilities shared across different threats without producing “digital war plans”. A scenario assumes no particular adversary and names no actual Iraqi asset. It tests only who decides, what alternative exists, whether a copy exists, what communications channel is used, which supplier might fail, and whether the function can be restored.

Table 10A: Non-operational strategic scenarios

Scenario Driver Institutional test Shared capabilities
Widespread government ransomware Compromise of an interconnected service Escalation, backups, continuity and communication IAM, Backup, CSIRT, Crisis Comms
Failure of a major supplier/cloud service External or supply-chain failure RTO, alternative and Exit Plan Dependency Map, Portability, BCP
OT incident in a critical sector Disruption of physical operations Sectoral and national coordination and safety OT IR, Recovery, supplier management
Deepfake during a crisis Impersonation of an official or fabricated information Verification, communication and trust Official Channels, Provenance, Media Literacy
A high-impact government AI system makes an error Data, model or excessive reliance Review, responsibility and appeal AI Inventory, Impact Assessment, Human Review

18. The Vision for a Digitally Secure Iraq in 2045

A digitally secure Iraq in 2045 is not a state that cannot be breached. It is a state that knows its assets, risks and dependencies; applies a clear minimum and gives critical functions stronger protection; detects and contains incidents and restores services within acceptable times; tests backups and restoration rather than assuming them; can change suppliers or operate alternatives when necessary; and protects citizens' data under purpose, law and oversight.

It is also a state that uses AI without transferring responsibility to an algorithm, counters disinformation through transparency, communication and resilience rather than political management of truth, and has Iraqi personnel leading national incidents and decisions even when using an external supplier or partner. Success means less impact, faster recovery, institutional learning and known dependencies—not a publicity figure for “thwarted attacks”.

19. Transformation Phases, 2027–2045

Table 11: Cyber transformation phases, 2027–2045
Phase Purpose Core interventions Conditions for progression
2027–2030: Understanding assets and risks Build a baseline and measurable governance cycle Strategy review; CII; Asset Inventory; Baseline Controls; Incident Reporting; legal review; Workforce/Supplier Assessment; initial exercises Critical-function/asset register; approved minimum; incident dictionary; MTTD/Containment/Recovery baselines; data and rights programme
2031–2035: Sectoral defence and resilience Turn standards into operation and testing SOC/CSIRT as needed; OT; Backup/Recovery; sectoral exercises; Supply-Chain Controls; career paths; data protection and enforcement CII coverage; successful recovery tests; repeated closure of root causes; fewer unaddressed dependencies
2036–2040: National digital integration Connect sectors without excessive operational centralisation Disciplined information sharing; AI Security; multi-sector response; Dependency Resilience; mature measurement Most critical sectors at the “measured” level; cross-sector recoverability; stable indicator-data quality
2041–2045: An adaptive state Make updating and learning normal institutional functions Periodic standards and strategy updates; Horizon Scanning; critical domestic capabilities; adaptive testing Continuity across governments; technological change does not stop functions; risks and controls updated automatically without permanent emergency

20. Indicator and Target Dashboard

A good indicator in this chapter measures function, not noise. Raw incident counts are insufficient: they may rise because reporting improves. Tool or certificate counts are insufficient: an institution may be certified yet slow to recover. The dashboard therefore focuses on coverage, time, restoration, risk closure, personnel, suppliers and AI governance.

Table 12: Indicators and targets, 2030–2045
Indicator Baseline 2030 2035 2040 2045
CII designation and function ownership Completed in 2027 100% of the designated scope Annual review Dynamic review Automatic updating as functions change
Baseline Controls for critical government institutions Established after assessment 100% within an announced scope Effectiveness audit Sectoral improvement Adaptive Baseline
Incident Reporting + Severity Matrix Not publicly standardised A complete national system and 24/7 operation Trend analysis Cross-sector integration Monitored machine learning with Human Review
MTTD/Containment/Recovery No public national baseline Establish the baseline and achieve a meaningful reduction after two years Numerical target established after the baseline Continuous improvement Advanced resilience within risk limits
Recovery tests for critical functions Not standardised Annual test for every designated function Cross-sector exercises Interconnected national exercises Adaptive tests
Critical cyber roles No unified taxonomy Taxonomy + baseline + gap-closing plan Reduce vacancies against the baseline Stable career path Self-renewing skills
High-impact AI governance No unified register Register and assess 100% of new high-impact government systems Periodic audit Integrated AI Security Adaptive governance
Data-protection framework Fragmented framework An effective general framework or equivalent package Enforcement and measurement Alignment with emerging technologies Continuous updating

The use of 100% here is confined to coverage obligations with a defined denominator—such as designating all CII functions within an official scope, or assessing all new AI systems classified as high impact—not a claim of 100% security. Time and quality targets are established after an Iraqi baseline; another country's figures are not borrowed as if they were Iraqi capability.

21. Implementation Programmes: From Governance to Resilience

The recommendations become a memorable package. They do not create a new agency for every gap, but distribute functions among the National Centre, regulators, service owners, legal authorities, education and defence according to jurisdiction. Costs are classified qualitatively now and quantified after existing assets, personnel and controls are inventoried.

Table 13: Implementation programme package
Programme Problem Lead Body 2027–2030 Cost
P1 Strategy cycle and baseline The 2022–2025 horizon has ended; measurement gaps remain NCC + Prime Minister's Office Strategy Refresh + maturity/incident baseline + closure matrix Costing study
P2 CII and critical-sector governance Publicly incomplete designation and obligations NCC + sectoral regulators CII criteria + obligations + sector profiles Moderate regulatory/technical cost
P3 National minimum controls Uneven maturity NCC Baseline Controls + audit + remediation Ongoing, varying by institution
P4 Response and reporting No unified public indicators NCC Severity + reporting + exercises + post-incident Medium
P5 Resilience and continuity Risk of cascading disruption NCC + service owners RTO/RPO + recovery tests + dependency maps Sectoral; requires costing
P6 OT/ICS security The distinct nature of industrial systems Sectoral regulators + NCC OT baseline + supplier/legacy management High at sectoral level
P7 Supply chains and dependencies Vendor lock-in and supplier dependence PMO/NCC + procurement + sectors Critical supplier register + exit/portability Low–moderate organisational cost
P8 Personnel Capacity gap NCC + public service + education Workforce taxonomy + career paths + labs Moderate recurring cost
P9 Data protection and sovereignty Fragmented framework Competent legislative/oversight authority + NCC Data framework + classification + breach rules Legal/regulatory
P10 Information integrity Manipulation without an integrated rights framework Government communication + CMC + society/media Rapid comms + transparency + literacy Low–medium
P11 AI governance and security AI strategy under development NCAI + NCC + legal authorities AI inventory + risk tiers + human oversight Medium
P12 Strategic cyber defence Protecting digital military capabilities Ministry of Defence + NCC for coordination Defensive governance + exercises + supplier resilience Classified/separate costing

21.1 Concise Implementation Matrix

Table 14: Concise implementation matrix, 2027–2030
Gap Action Basis/owner Start Indicator Risk/mitigation
Strategy whose time horizon has ended Review 2022–2025 and issue an updated cycle NCC mandate 2027 Strategy approval + closure matrix A document without implementation → link to indicators and budgets
No unified operational baseline National Cyber Metrics Dictionary NCC 2027 Share of indicators with definitions and owners Reporting proliferation → a limited dashboard
CII not publicly standardised Designation criteria and obligations NCC + sector 2027 CII coverage Sensitive disclosure → publish sectors, not assets
Uneven controls National Baseline Controls NCC 2027 Effective compliance Checklist gaming → audit outcomes
Concealed incidents Reporting rules and good-faith protection NCC + legislation/regulation 2027 Share reported on time Penalties encouraging concealment → Safe Reporting
Unmeasured recovery RTO/RPO and Recovery Testing CII owners 2027 Successful tests A paper plan → annual testing
Supplier dependence Critical Dependency Register PMO/procurement/NCC 2028 Dependencies with an Exit Plan Diversification costs → Risk Tiering
Skills gap Cyber Career Framework Public service/NCC 2027 Critical-role vacancies Attrition → incentives and career paths
AI without an inventory High-Risk AI Registry NCAI/NCC 2027 Coverage of high-impact systems Shadow AI → Procurement Gate
Crisis disinformation Rapid Information Integrity Protocol Government communication 2027 Correction time Politicisation → Narrow Harm Test and review

22. Costs and Financing: Operational Capability, Not a One-Off Purchase

The chapter sets no aggregate “cybersecurity budget”, because published asset, personnel, control and sector inventories do not support a defensible estimate. An overall figure before inventory would create false precision. The first phase therefore begins with a Costing study linked to the CII Inventory, Workforce Assessment and Current Controls.

Costs comprise governance and compliance, personnel, tools and licences, SOC/CSIRT operation where needed, Backup/DR, OT assessments, training, exercises, standby response services, supplier assurance, and maintenance and updating. CAPEX must be separated from OPEX: cybersecurity is a recurring operational capability, and a tool whose updates and staff are unfunded after a year is not a complete investment.

National financing comes from the public budget for shared capabilities; institutional and sectoral budgets for their own responsibilities; regulated cost sharing with private infrastructure owners where lawful; and technical assistance for training and standards, not permanent operation of sovereign capabilities. The rule is that a service can be outsourced, but accountability cannot.

22.1 What Do We Not Yet Know? The Data-Gap Register

Part of the 2027 programme is not “implementing solutions”, but creating dependable measurement. Public national tables do not currently support unified figures for detection, containment and recovery times, asset-inventory completion or cyber vacancies. These gaps must have owners and baseline-building methods. At the same time, some details are legitimately classified so transparency demands do not expose weaknesses.

Table 14A: Data gaps and legitimate secrecy register

Data item Case Proposed owner Public/internal First-phase action
Incidents by severity Not available in unified public form NCC Public aggregates Unified reporting dictionary and definition
MTTD/Containment No public national baseline NCC/sectors Aggregate + internal Measure for 12 months after definitions are standardised
Recovery within RTO Not available in unified form CII owners/NCC Aggregate Annual tests and results report
Asset Inventory completeness Not available in aggregate Each institution/NCC Internal + aggregate Inventory, classification and asset owner
MFA for critical accounts Unavailable Each institution Internal/aggregate Define “critical” and Baseline Controls
Critical Supplier Map Unavailable PMO/NCC/sectors Legitimately classified Dependency Register
OT Maturity Unavailable Sectoral regulator Classified/aggregate Sector Assessment
Cyber Workforce Vacancies Not available in unified form Public service/NCC Public aggregates Workforce Assessment
Data Breaches Not standardised Data owners/NCC Public aggregates Breach Notification Framework
AI Systems Inventory Not available in unified form NCAI Internal/aggregate High-Risk AI Registry

23. Risks: How Can Cybersecurity Reform Fail?

Table 15: Strategic risk register
Risk Likelihood Effect Warning indicator Mitigation
Excessive centralisation in the NCC Medium High Backlogged requests and slow response Central policy and distributed implementation
Institutional overlap High High Repeated or conflicting instructions A jurisdictional map and escalation protocol
Personnel shortages and attrition High High Vacancies and excessive contractor dependence Career paths, incentives and practical training
Vendor Lock-In Medium–high High Contracts without Exit/Portability Contractual terms, alternatives and dependency assessment
Supply-Chain Compromise Medium Very high An unassessed critical supplier Supplier Assurance and reporting
Ransomware High High Recurrence and restoration failure Baseline + Recovery Tests
Data leakage High High Excessive access/reports Classification + IAM + Breach Response
Mass surveillance Medium High rights impact Expanded access without a purpose Purpose/necessity/proportionality/oversight
SOC without analysts Medium Medium–high Backlogged alerts without decisions Workforce + a managed service with safeguards
Unsupervised AI Increasing High Shadow AI and unexplained decisions Registry + Procurement Gate + Human Review
Politicised counter-disinformation Medium High Targeting legitimate criticism Narrow Harm Test and independent review
Cloud Concentration Medium High Many services on one supplier Dependency Map + Exit Plan
OT Incident Medium Very high No restoration testing/supplier management A sectoral OT programme and tests
Concealed incidents High High A gap between signals and reported cases Safe Reporting + Metrics

24. Safeguards: A Secure Digital State Does Not Protect the Government from Citizens

Cybersecurity does not replace the Constitution. Every collection, processing or sharing of security data needs a legitimate purpose, necessity and proportionality limits, and the minimum possible data, retention and access. Surveillance affecting confidentiality of communications requires a legal basis and judicial oversight where constitutionally required. A cybersecurity platform must not become a gateway to political or social dossiers unrelated to a defined threat.

For artificial intelligence, safeguards are identifiable human responsibility, audit logs, impact assessment, bias and discrimination testing, the ability to stop and roll back, and an appeal or review pathway when a decision affects rights, security or a high-impact entitlement. For disinformation, the safeguard is defining harm, intent and scope rather than punishing errors or criticism, while protecting journalism, research and expression.

These safeguards are not a “cost imposed on security”. They prevent a system expanded during crisis from becoming a permanent, unaccountable function. Sustainable security needs trust and cooperation. If citizens fear every digital service is a surveillance channel, the state loses the value of digital transformation itself.

25. Closing Part Three: From Protecting Territory to Protecting Digital Functions

This part has completed four layers of capability. “Security as a Condition for National Renewal” identified what must be protected and defined deterrence, readiness and resilience under the law. “The Professional National Army” translated defence into an institution, doctrine and sustainable capabilities. “Internal Security and Intelligence” assigned everyday protection to professional policing, investigation and intelligence under the law. This chapter adds the digital and information layer on which the preceding three increasingly depend.

The part's equation is therefore: material capability + institutional capability + information and digital capability + law and rights + readiness and resilience. State strength in 2045 is measured not by weapons, agency numbers or security-platform counts, but by the ability to protect territory, society, information and digital functions, continue through shocks, and use physical and digital power under sovereign decision-making, oversight and responsibility.

The chapter does not close the security discussion with a promise of “the end of threats”. It closes with institutions able to update themselves. Risks, suppliers and technology change. Iraq needs not a fixed system for 2045, but a state able to reassess risks, standards, dependencies and skills whenever its environment changes.

26. The Bridge to Part Four: The Economy and National Production

If Iraq achieves a capable state, sovereignty, law, effective government and integrity, then builds national security, a professional army, internal security and digital capability protecting institutions and infrastructure against old and new threats, the question of material endurance remains: can an economy heavily dependent on a single oil resource finance this state and maintain its stability, independence and investment through 2045?

Part Four: The Economy and National Production
Chapter One: The End of the Rentier State
V1-D04-C01

References

  1. Iraqi Council of Representatives, Constitution of the Republic of Iraq, 2005.
  2. Ministry of Justice/Iraqi Official Gazette, Instructions on the Formations and Functions of the Prime Minister's Office No. (1) of 2025.
  3. National Cybersecurity Centre, official website, institutional materials and the Iraqi Cybersecurity Strategy 2022–2025.
  4. National Security Advisory and Iraqi government authorities, Iraqi National Security Strategy “Iraq First” 2025–2030.
  5. Iraqi Council of Representatives, official materials on the proposed Law on Combating Information Technology Crimes, 6 July and 26 August 2026.
  6. Communications and Media Commission, published regulations for cybersecurity services, data centres and digital platforms, 2025–2026.
  7. International Telecommunication Union, Global Cybersecurity Index 2024 — Iraq country profile.
  8. NIST, The Cybersecurity Framework (CSF) 2.0, 2024.
  9. NIST, Artificial Intelligence Risk Management Framework and Generative AI Profile, 2023–2024.
  10. ISO/IEC 27001:2022, Information Security Management Systems; ISO 22301, Business Continuity; ISO/IEC 42001, AI Management Systems.
  11. IEC 62443 series, Security for industrial automation and control systems.
  12. Cyber Security Agency of Singapore, Cybersecurity Act and Critical Information Infrastructure materials.
  13. UK National Cyber Security Centre, Cyber Assessment Framework.
  14. CISA, Cross-Sector Cybersecurity Performance Goals.
  15. United Nations, Global Digital Compact, 2024.
  16. UNESCO, Recommendation on the Ethics of Artificial Intelligence, 2021, and subsequent governance resources.
  17. Iraqi National Center for Artificial Intelligence / Prime Minister’s Advisory Office, Iraqi National Artificial Intelligence Strategy portal, status in 2026.
  18. Iraqi Ministry of Planning, official materials on developing the National Artificial Intelligence Strategy, 2026.
  19. UNAMI/OHCHR, Human Rights Violations and Abuses in the Context of Demonstrations in Iraq, 2020, concerning internet restrictions and shutdowns during the 2019 protests.
  20. Iraqi Insurance Diwan, Insurance Sector Governance Guide, 2026, requirements concerning information security, RPO/RTO and recovery tests.

Footnotes

  1. National Cybersecurity Centre, “Iraqi Cybersecurity Strategy 2022–2025”, strategy document published on the official website. ↩︎

  2. Ministry of Justice/Iraqi Official Gazette, Instructions on the Formations and Functions of the Prime Minister's Office No. (1) of 2025, provisions concerning the National Cybersecurity Centre and its mandates. ↩︎

  3. International Telecommunication Union (ITU), Global Cybersecurity Index 2024, Iraq country profile: Tier 4 (Evolving); pillar scores total 53.07/100. ↩︎

  4. U.S. National Institute of Standards and Technology (NIST), The Cybersecurity Framework (CSF) 2.0, 2024. ↩︎

  5. Ministry of Justice/Iraqi Official Gazette, Instructions on the Formations and Functions of the Prime Minister's Office No. (1) of 2025, mandates of the National Artificial Intelligence Centre. ↩︎

  6. Iraqi Council of Representatives, Constitution of the Republic of Iraq, 2005, especially Articles 17, 38, 40 and 46 concerning privacy, confidentiality of communications, freedom of expression and limits on restrictions of rights. ↩︎

  7. Iraqi Council of Representatives, decisions and recommendations of the 6 July 2026 session concerning the first reading of the proposed Law on Combating Information Technology Crimes; and Parliamentary Security and Defence Committee, meeting of 26 August 2026 on continued refinement of the proposal. It was not an effective law as of that date. ↩︎

  8. Iraqi Communications and Media Commission, regulations published during 2025–2026 concerning cybersecurity-service companies, data-centre services, platforms and digital services; used here to establish the development of sectoral regulation, not as a comprehensive data-protection law. ↩︎

  9. Iraqi National Security Strategy “Iraq First” 2025–2030, published Iraqi government materials. ↩︎

  10. Cyber Security Agency of Singapore, Cybersecurity Act and Critical Information Infrastructure materials, used here for the mechanism of designation, obligations, reporting and oversight — not for direct legal transplantation. ↩︎

  11. IEC 62443 series, Security for Industrial Automation and Control Systems, current materials. ↩︎

  12. UK National Cyber Security Centre, Cyber Assessment Framework (CAF), current version, particularly essential functions, response and recovery outcomes. ↩︎

  13. U.S. Cybersecurity and Infrastructure Security Agency (CISA), Cross-Sector Cybersecurity Performance Goals, current materials used for a small high-impact baseline approach. ↩︎

  14. Iraqi Insurance Diwan, Insurance Sector Governance Guide, 2026, requirements concerning information security, RPO/RTO and recovery tests. ↩︎

  15. United Nations, Global Digital Compact, 2024, provisions and commitments concerning information integrity, trustworthy information, platform transparency and digital governance. ↩︎

  16. UNAMI/OHCHR, Human Rights Violations and Abuses in the Context of Demonstrations in Iraq, 2020, documenting broad internet shutdowns/restrictions during the 2019 protests and their human-rights context. ↩︎

  17. Iraqi National Center for Artificial Intelligence / Prime Minister’s Advisory Office, Iraqi National Strategy for Artificial Intelligence portal, which in 2026 described the national strategy as under development. ↩︎

Iraq Vision 2045 · Part Three: Security, Defence and Deterrence · V1-D03-C04Prepared by:

What are you looking for?

Search content published on the website.