Cybersecurity and New Forms of Security
From Protecting Systems to the Resilience of the Digital State Under the Law
1. Executive Summary
This chapter opens the fourth and final layer of the security system in Iraq Vision 2045. After this part defined security, deterrence and readiness, designed the military institution responsible for defence, and distinguished internal security and intelligence from the army, the question becomes: what happens when those institutions themselves depend on data, communications, software, platforms and algorithms? The connected state can work faster, but also carries a larger attack surface and new dependencies. Cybersecurity therefore becomes part of state continuity, not a technical appendix to computer departments.
Iraq is not starting from zero. Since 2025, the National Cybersecurity Centre has been an official body within the Prime Minister's Office, with broad published responsibilities: proposing strategy, policies and standards; assessing compliance; managing national risks; protecting critical digital infrastructure; warning and responding to major incidents; receiving reports; training; and cooperation. Meanwhile, the Iraqi Cybersecurity Strategy 2022–2025 has reached the end of its time horizon, and no published specialist successor for the following period had appeared by the research freeze on 27 August 2026. The problem is therefore less the absence of an authority than translating its mandate into an implementation, measurement and updating cycle.12
The International Telecommunication Union's Global Cybersecurity Index 2024 provides a useful external baseline, and no more: Iraq is in Tier 4 — Evolving, with pillar scores totalling 53.07 out of 100. This score measures commitment and institutional maturity across legal, technical, organisational, capacity-building and cooperation dimensions; it does not measure the percentage of “network security”, incident-detection time or service-recovery time. Because 53.07 matches the value displayed by the National Centre as the “National Readiness Index”, the chapter adopts a methodological decision: the value is interpreted as reflecting the GCI score unless an independent Iraqi operational methodology is published.3
The proposed vision organises cybersecurity as a recurring capability: governance, understanding assets and risks, protection, detection, response, recovery and learning. It places central governance in policy, standards and national-incident leadership, with distributed implementation across ministries, sectors and infrastructure and service owners. It treats resilience—not “preventing every breach”—as the governing outcome: what keeps working? How quickly is deviation detected? How long does containment take? Does service return within an acceptable time? Was the root cause addressed after the incident?4
On rights, the chapter does not equate security with surveillance. The Constitution protects privacy, confidentiality of communications and freedom of expression, and sets limits on restrictions. Purpose, necessity, proportionality, data minimisation and oversight therefore remain fundamental to every digital security system. On artificial intelligence, Iraq has established a National Artificial Intelligence Centre, but official sources in 2026 still describe the national strategy as under development. This chapter's task is therefore security and governance: inventory high-impact systems, assess their risks, protect their data and models, and retain human decision-making responsibility where effects on rights or security are high.56
2. From Internal Security to Protecting the Connected State
The preceding chapter established that professional internal security is not measured by the volume of information collected, and that intelligence or an algorithm does not automatically become a conviction. It left an entire layer outside its scope: databases holding reports, communications transmitting orders, case-management platforms, systems hosting evidence, and digital services used by citizens, police, banks, hospitals and military forces. When this layer fails, the effect is not necessarily “technical”: a public function may stop, or a previously limited crisis may expand.
The chapter therefore asks not “Did the incident occur online?”, but “What is its impact?” A compromised personal account or individual fraud usually remains a crime or technical incident within ordinary jurisdiction. Widespread disruption of a national payment service, loss of highly sensitive data, or failure of a system essential to government, defence or critical infrastructure may exceed a single institution's capacity and become a national-security matter requiring higher-level leadership, coordination and decisions.
3. What Is National Cybersecurity?
This chapter adopts an operational definition of cybersecurity as national management of risks to digital systems, data and services, protecting confidentiality, integrity and availability while adding detection, response, recovery and learning to prevention. The definition puts “function” before “tool”: a firewall, monitoring platform or operations centre is a means; the outcome is reliable service, reduced incident impact and institutional learning.
Cyber resilience is the ability of a digital function to continue or return to an acceptable level after an incident. This matters because “preventing all breaches” is unrealistic even for the most mature states and institutions. Advanced security does not accept breaches as normal; it assumes they can occur and designs layers of prevention, detection, containment and restoration around that possibility. NIST Cybersecurity Framework 2.0 adopts the same logic through GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER.
Source: NIST Cybersecurity Framework 2.0, 2024.
Methodological note: “Learn” is added as a post-incident institutional-learning stage.
3.1 Jurisdictional Boundaries: Cybersecurity, Cybercrime and Cyber Defence
The chapter helps prevent overlapping roles before proposing any programme. Cybersecurity focuses on reducing system and service risks and maintaining continuity. Cybercrime focuses on establishing criminal conduct, investigation, evidence and justice. Cyber defence focuses on protecting military networks and capabilities within the defence system. Data protection regulates individual rights and processing safeguards, while information integrity concerns the public sphere's resilience against organised manipulation. These functions converge during a major incident, but do not become one institution.
| Field | Purpose | Lead authority/approach | Output |
|---|---|---|---|
| Cybersecurity | Reducing risks and maintaining functions | National Centre + regulators + service owners | Standards, assessment, warning, response and recovery |
| Cybercrime | Establishing the crime and holding the perpetrator accountable | Law enforcement, investigation and judiciary | Evidence, referral, judgment and enforcement |
| Cyber Defence | Protecting digital military capabilities | Ministry of Defence and military command within their competence | Defence readiness and continuous military networks |
| Data Protection | Protecting individual rights and regulating processing | A specialised civilian legal and oversight framework | Rights, obligations and enforcement |
| Information Integrity | Reducing the harm of organised manipulation | Government communication + media and society + platforms within the law | Transparency, correction, resilience and protection of expression |
Source: the Iraqi Constitution and applicable laws according to jurisdiction.
4. Where Does Iraq Stand? A Baseline That Distinguishes Maturity from Readiness
Iraq's situation between 2024 and 2026 reveals two parallel tracks. The first is institutional: creation of the National Cybersecurity Centre with broad powers, and emergence of sectoral regulations, exercises and training programmes. The second concerns measurement: public data still provide no unified national dashboard for incident detection, containment and recovery times, multifactor-authentication coverage, completion of critical-asset inventories, or successful backup and restoration tests. The vision must therefore not fill these gaps with other countries' figures or expert estimates.
GCI 2024 shows variation among pillars: organisation at 15.77/20 is relatively stronger, while the technical pillar is 9.60, capacity development 8.38, cooperation 8.11 and legal measures 11.21. This does not mean “Iraq is technically weak by a particular percentage”; it means institutional development has advanced faster than some layers of implementation, skills and cooperation. Early years should therefore not spend most resources on additional tools before defining the assets, functions, skills and obligations that will operate them.
| Dimension | Verified baseline | Year | Decision on Use |
|---|---|---|---|
| Overall GCI | 53.07/100; Tier 4 — Evolving | 2024 | An external commitment/maturity index, not operational readiness |
| Legal Measures | 11.21/20 | 2024 | A relative legislation/enforcement gap |
| Technical Measures | 9.60/20 | 2024 | Priority for stronger technical implementation and measurement |
| Organizational Measures | 15.77/20 | 2024 | Relative governance strength |
| Capacity Development | 8.38/20 | 2024 | One of the relatively weaker pillars |
| Cooperation | 8.11/20 | 2024 | A cooperation and capability-sharing gap |
| MTTD/Containment/Recovery | No unified public national baseline | 2026 | Established in 2027–2028; internal data may exist |
| National Centre coverage | 500+ institutions and 24/7 monitoring, according to the official website | 2026 | An announced operational figure requiring definition of the scope of “protection” |
Source: ITU Global Cybersecurity Index 2024; National Cybersecurity Centre official website. 8
The chapter's most important data decision is to distinguish measurement gaps from legitimate secrecy. An institution may hold response times, asset lists or incident details that should not be published; this is not “absence of data”. Conversely, if institutions use different incident definitions, or the state cannot aggregate sectoral containment times, that is a genuine measurement gap requiring correction. The public document should publish appropriate aggregates, not details that help an attacker or expose a weakness.
4.1 The Legal Framework: Do Not Fill the Protection Gap with a Single Law
Iraq's digital legal environment is distributed among the Constitution, sectoral legislation and standards, institutional instructions and developing legislative proposals. The starting point is not an “all-encompassing cyber law”, because functions differ: personal-data protection needs processing rights and oversight; cybercrime needs defined offences, procedures and safeguards; cybersecurity needs compliance, reporting and continuity standards; and communications and platforms have sectoral regulation. Conflating them may produce a broad text with weak functionality.
As of production, the proposed Law on Combating Information Technology Crimes remained in the legislative process: the Council of Representatives held its first reading on 6 July 2026, and the Security and Defence Committee continued discussing and refining it on 26 August 2026. The chapter therefore bases no power or penalty on an assumption that it is in force. If subsequently enacted, it should be assessed by its criminal and procedural functions and safeguards, not treated as a substitute for data protection or cybersecurity governance.7
For data protection, the Constitution provides a basis for privacy and confidentiality of communications, and sectoral instruments, privacy policies and digital regulations exist. However, verification through the freeze date did not establish a single comprehensive federal framework combining the basis for processing, minimisation, purpose, retention, sharing, individual rights, breach notification and cross-border transfers. Reform must fill these functions, through a general law or an integrated package if constitutional and regulatory arrangements justify it. The essential point is that citizens' rights must not remain scattered across terms of service and instructions without a clear enforcement pathway.
Sectoral regulations from the Communications and Media Commission also emerged in 2025–2026 for cybersecurity services, data centres and digital platforms. They matter because they establish the digital market itself as a regulatory subject. Multiple regulations, however, increase the importance of alignment: providers should know which national standard applies, which regulator reviews them, and how sectoral requirements align with the National Centre without conflict or repeated audits.8
Table 3A: The legal and functional map of digital security
| Instrument | Status at the freeze date | Function | Chapter decision |
|---|---|---|---|
| Constitution of 2005 | In force | Privacy, communications, expression and limits on restrictions | The overriding rights reference |
| Prime Minister's Office Instructions 1/2025 | In force/published | The basis for the NCC, NCAI and their mandates | Principal institutional reference |
| Cybersecurity Strategy 2022–2025 | Its time horizon has ended | Previous objectives, governance and readiness assessment | Review and update; do not disregard |
| National Security Strategy 2025–2030 | In effect as a strategy | The broader security framework | Connects cybersecurity to national security |
| Information Technology Crimes proposal, 2026 | Not in force as of 26 August | Potential criminalisation and procedures | No effective jurisdiction is based on it |
| CMC digital regulations, 2025–2026 | Published sectoral regulations | Security providers, data centres and platforms | Align with national governance |
| Comprehensive data-protection framework | A comprehensive federal law had not been verified by the freeze date | Rights, processing safeguards and enforcement | A reform gap that must be closed |
Source: Constitution of the Republic of Iraq; Instructions on the Formations and Functions of the Prime Minister's Office No. (1) of 2025; Iraqi Council of Representatives; Communications and Media Commission.
4.2 A National Maturity Model: Institutions Do Not All Start at the Same Level
Moving from a general international indicator to actual management requires a simple national maturity model. It does not assume that a ministry, bank and industrial facility are at the same level, or aim to give every institution the same certificate. Its purpose is to identify the starting point and improvement path: is the process unstructured and dependent on individuals? Has it been documented? Is it actually applied? Is it measured? Does it adapt after incidents and technological change?
This model prevents two errors. The first is spending on advanced technology while the institution does not know its assets or their owners. The second is turning maturity into a punitive public ranking that discourages reporting. Details therefore remain internal; only aggregate sectoral progress is published, with sensitive information protected.
Table 3B: A simplified national cyber-maturity model
| Level | Description | Practical test | Required transition |
|---|---|---|---|
| 1 — Unstructured | Fragmented procedures dependent on individuals | No stable inventory or unified incident plan | Define assets, owners and basic policy |
| 2 — Documented | Policies and plans exist | Documents do not establish implementation | Training, implementation and monitoring |
| 3 — Implemented | Controls operate within a defined scope | Outcomes are insufficiently measured | Define indicators and test recovery |
| 4 — Measured | Time, impact and compliance are known | Improvement may remain slow | Causal analysis and cross-institutional learning |
| 5 — Adaptive | Standards change with threats and technology | Requires data and a mature institution | Maintain renewal without permanent emergency |
5. From a New Institution to a Functioning Governance Cycle
The 2025 Instructions on the Formations of the Prime Minister's Office made the National Cybersecurity Centre a clear focus of federal governance, assigning functions beyond technical monitoring to policy, standards, readiness, risks, critical infrastructure, response, training and cooperation. The vision therefore does not need a second “cyber authority”. It needs these mandates translated into measurable responsibility rules: what does the Centre establish? What does the regulator implement? What does the sector own? What must be reported? Who leads when an incident exceeds institutional capacity?
The most suitable model is central governance with distributed implementation. The Centre sets national standards, aggregates the risk picture, measures maturity and leads or coordinates national incidents; sectoral regulators translate the minimum standard into obligations suited to banking, communications, energy or transport risks; and every service owner remains responsible for assets, personnel, plans and budgets. The private sector does not become a government arm, but cannot operate critical infrastructure outside security and reporting obligations.
| Function | National level | Sectoral/institutional level |
|---|---|---|
| Policy and standards | National framework and periodic updating | Sectoral alignment and implementation procedures |
| Risk management | Aggregate national risks and identify CII | Asset and function risk register |
| Monitoring | National picture and aggregate threat intelligence | SOC/monitoring function as needed |
| Response | Leadership/coordination of major national incidents | CSIRT or the institution's incident plan |
| Compliance | Define outcomes and measure maturity | Implementation, audit and correction |
| Continuity | Cross-sector standards and exercises | RTO/RPO, plans and tests |
| Rights | National rules and legal oversight | Purpose Limitation and access and retention controls |
Source: Instructions on the Formations and Functions of the Prime Minister's Office No. (1) of 2025.
5.1 A Strategy Cycle, Not a Periodic Document
The Iraqi Cybersecurity Strategy 2022–2025 did not become worthless when its dates expired. It included readiness assessment, asset inventory and classification, governance, critical-infrastructure protection, response and recovery. The task in 2027 is a closure review: completed, partially completed, unimplemented, transferred to a new mandate or no longer suitable objectives. An updated strategy cycle linked to the National Security Strategy 2025–2030 then follows, reviewed every four years or after a major change in risks.9
This changes strategy from an “objectives document” into a learning mechanism: assessment → priorities → programmes → financing → indicators → review → update. If a new specialist strategy is issued after this chapter's freeze date, it replaces the implementation assumption that “updating is required”, without removing the need for the institutional cycle itself.
6. Protecting Digital Infrastructure: The Critical Function Before the Server
The second pillar begins not with a list of ministries or servers, but with a question: which functions can society or the state not tolerate losing for long? Electricity, communications, payments, water, health, transport and essential government services are categories of potentially critical functions, but “critical” does not mean “government-owned”. A service may be run by a private company, public body or several institutions; its criterion remains the impact of disruption, not asset ownership.
The vision therefore proposes defining Critical Information Infrastructure according to functional impact: people affected, tolerable downtime, safety effects, economic and security effects, available alternatives and interdependence with other sectors. The detailed asset register should be sensitive or classified according to its nature, while sectors, categories and general requirements can be announced. Singapore's model is useful as a designation, obligation and oversight mechanism, not as a ready-made law to replicate.10
| Norm | Classification question | Effect on the CII decision |
|---|---|---|
| Scale of impact | How many people/institutions are affected if the function stops? | Greater impact raises protection priority |
| Tolerable downtime | How long can the service stop before substantial harm occurs? | Determines RTO and continuity requirements |
| Safety | Could disruption cause physical or health harm? | Raises OT and response requirements |
| Alternatives | Is an alternative service available within a reasonable time? | Absence of an alternative increases criticality |
| Interdependence | How many other functions depend on it? | Creates priority for addressing cascading failure |
| Sovereignty/security | Does failure affect defence or national decision-making? | May elevate the incident to national level |
Source: Cyber Security Agency of Singapore, Cybersecurity Act and Critical Information Infrastructure materials.
6.1 From IT to OT: When Bits Produce Physical Effects
Operational technology and industrial control systems, OT/ICS, differ from conventional information-technology environments. Updating an office system may tolerate a brief outage; a system controlling a physical process may place greater priority on safety and continuity, operate for many years and not accept updates in the same way. A single security policy must therefore not be applied automatically to every system.
The required strategic level comprises inventories of systems and functions, boundaries between IT and OT, supplier and change management, appropriate configuration backups and recovery data, alternative operating plans and recovery tests. IEC 62443 can serve as a reference for industrial sectors, not a “mandatory certificate” for every system.11
6.2 Interdependence: Protect the Function Whose Failure Spreads
Digital sectors do not operate as islands. Communications outages may disrupt banking and emergency services; electricity failures may affect data centres and communications; identity or payment-service failures may block multiple government transactions simultaneously. The state therefore needs a qualitative dependency map identifying interconnected functions, alternatives and tolerable downtime, while keeping asset and connection details confidential where necessary.
This shifts investment from “protecting the most expensive asset” to “protecting the function whose failure spreads”. The logic accords with the British Cyber Assessment Framework, which measures protection of essential functions, response, recovery and subsequent learning rather than formal adherence to a single tool.12
6.3 The Risk Map: Threat ≠ Vulnerability ≠ Dependency
The national map should not conflate three different things. A threat is an actor or event capable of causing harm; a vulnerability is a weakness in design, operation, identity, updating or procedure; a dependency is a connection to a service, supplier or sector through which failure can spread. Calling a vulnerability a “threat” pushes an institution to buy a tool against an adversary when the problem is internal. Calling a dependency a “vulnerability” may obscure that the solution is contractual or continuity-related, not solely technical.
Near-term priorities concentrate on categories with broad, cascading impact: ransomware affecting government or critical services; supply-chain compromise; leakage of highly sensitive data; OT incidents; supplier or cloud failure connecting multiple services; insider privilege abuse; and AI-enabled fraud or disinformation. Post-quantum risks belong in long-term planning, not the daily emergency list. The chapter provides no falsely precise numerical probabilities; these are developed after a National Risk Register and years of incident data.
Table 4A: A qualitative, non-operational cyber-risk map
| Risk category | Potential Effect | Horizon | 2027–2030 priority | Publication type |
|---|---|---|---|---|
| Widespread ransomware | Disruption, leakage and extortion | Near term | High | Public aggregates + internal detail |
| Supply-chain compromise | Spread through a trusted supplier | Near/medium term | High | Internal/restricted |
| OT/ICS incident | Physical, safety or economic disruption | Near term | High | Legitimate secrecy for details |
| Cloud/Supplier failure | Disruption of interconnected services | Medium | Medium–high. | Internal |
| Data breach | Privacy, trust and security | Near term | High | Public aggregates |
| AI-enabled fraud/deepfake | Fraud, crisis deception and trust | Near term | High | Public aggregates |
| Post-quantum exposure | Long-lived cryptographic assets | Long term/high uncertainty | Low-cost preparedness | Internal inventory |
7. The National Minimum: A Few High-Impact Controls
Where institutions differ in maturity, the first practical step is not to demand a complex system from every organisation, but to define a clear national floor. This minimum rests on required outcomes: knowing each asset and its owner, controlling identity and permissions, strong authentication for sensitive accounts, risk-based updates, recoverable backups, logging and review, an incident plan, training and supplier management. The minimum does not mean a “single government product”, nor prevent critical sectors imposing higher requirements.13
The minimum should be measured by effectiveness, not tick-box completion. An institution claiming to have backups without testing restoration has no confirmed capability; one with a SOC but no analysts or decision authority may possess a room of screens rather than a security function. Each control therefore has an output: protected privileged accounts, classified assets, successful restoration, alerts with a response pathway, and assessed critical suppliers.
7.1 Identity and Access: Who Has the Right to Enter?
Incidents do not always require complex technology to cause major harm; an account with broad privileges may matter more than a new server. Government security must therefore manage the identity life cycle: appointment, transfer between roles, departure, permission reviews and separation of duties. Privileged accounts need stronger protection and review, and multifactor authentication is a fundamental tool for critical accounts where appropriate.
This section does not rebuild national digital identity. It establishes a simpler requirement: institutions must know who enters a sensitive system, why access is needed, whether it is still needed, and what the user did. As an asset's impact rises, Least Privilege, audit logs and periodic reviews become more important.
7.2 Backup Does Not Equal Recovery
Backups become capability when restored. Every critical-function owner therefore needs an RTO—the target time to restore the function—and an RPO—the acceptable amount of data loss upon recovery—and must test rather than assume them. There is no single national value: a real-time banking function or emergency service differs radically from an information website that can wait hours or days.
Iraqi sectoral models already using RTO/RPO and restoration tests, such as insurance-sector governance requirements, demonstrate that the concept can become a local obligation rather than remain a foreign borrowing.14
8. The Cyber Incident: From Alert to Recovery and Learning
The National Centre's instructions assign it a role in major-incident response and establishing a reporting contact centre. This authority must become a severity dictionary and escalation thresholds: what must a ministry or company report? Within what time? What minimum information is required? Who decides when an incident moves from institutional to sectoral or national level?
Poor design punishes an institution for reporting, encouraging concealment. Better design distinguishes good-faith reporting, gross negligence, deliberate concealment and non-compliance. It provides confidentiality rules and protection for commercial and personal information, alongside clear obligations to report incidents of defined impact.
Capability is measured by stages: MTTD for incident detection, containment time after detection, function-restoration time, the share of material incidents undergoing Post-Incident Review, and the share of root-cause actions closed on time. Alert counts alone are unsuitable: they may rise because detection improved, attacks increased or definitions changed.
| Measure | What does it measure? | What may distort its interpretation? |
|---|---|---|
| MTTD | Time from a detectable event to its detection | Affected by monitoring quality and the definition of incident onset |
| Containment time | From detection to stopping the spread of impact | Requires a unified severity classification |
| Recovery within RTO | Restoration of the function within its target time | Tests must be distinguished from real incidents |
| Root Cause Closure | Closure of actions to prevent recurrence | Does not measure the incident's severity itself |
| Number of incidents | Cases under a unified dictionary | Affected by detection, reporting and definitions |
| Number of alerts | Volume of monitoring signals | Neither the number of “attacks” nor success in itself |
Source: NIST Cybersecurity Framework 2.0; UK National Cyber Security Centre, Cyber Assessment Framework.
8.1 Exercises: Test Decisions, Not Technical Displays
A cyber exercise is not a competition to penetrate systems, but a test of the decision mechanism. A tabletop exercise may reveal that a ministry does not know who declares a crisis, a sector does not know when to notify the Centre, the communications team lacks an initial message, or the recovery copy has not been tested. These gaps may be more dangerous than an individual technical vulnerability because they amplify an incident's effects after it occurs.
The vision proposes three layers: institutional exercises testing incident and restoration plans; sectoral exercises testing dependencies among companies and regulators; and a periodic national exercise testing escalation, decisions, communication and continuity. Scenarios revealing real weaknesses are not published, but aggregate institutional lessons can be: where were decisions delayed? Did the alternative work? Were corrective actions closed?
The exercise indicator is not the “number of exercises”. The outcome is the share of corrective actions closed afterwards, decision time, and teams' ability to restore a function within its standard. Exercises thus become live audits of resilience rather than media events.
9. Data: Protection and Sovereignty Without Geographical Slogans
Data become more valuable as the state becomes more connected. “Data protection”, however, is not synonymous with cybersecurity alone: it also concerns rights, purpose, processing, retention and sharing. The Iraqi Constitution protects privacy and confidentiality of correspondence and communications. The digital state needs to translate this protection into more integrated operational rules for personal data. No single comprehensive federal law comparable to modern integrated frameworks had been verified by 27 August 2026. This means a gap in the general framework, not an absence of all sectoral privacy rules.
The design rule is Data Minimization and Purpose Limitation: institutions collect what they need for a lawful purpose, not whatever they can technically collect, and do not reuse data for a fundamentally different purpose without a legal basis. Retention periods, sharing, access, correction and breach notification should be clearly defined wherever possible.
9.1 Data Sovereignty Is Not the Server's Location
The chapter defines data sovereignty as the legal and practical capacity to set rules, control access, know suppliers, audit, manage appropriate elements of control, transfer data, possess a copy or alternative, and exit dependence. Data Localization therefore does not equal sovereignty: data may be inside the country while operation, keys, support or licensing depend on a party that is difficult to replace. Conversely, the state may use an external service whose contract, controls, portability and alternatives are stronger than those of an unauditable local service.
| Question | Data Localization | Data Sovereignty |
|---|---|---|
| Location | Where are data stored? | One element of the picture |
| Jurisdiction | May be domestic | Who holds legal authority? |
| Access | Does not guarantee who gains access | Defined and auditable permissions |
| Supplier | May remain an external monopoly | Assesses replaceability and exit |
| Transfer | May be geographically restricted | Assesses portability and continuity copies |
| Outcome | Geographical localisation | Practical and legal control and alternative capability |
10. Suppliers and the Cloud: Dependence Measured by the Ability to Exit
National digital security depends on long supply chains: hardware, software, libraries, contractors, cloud services, updates and managed tools. An attack may pass through a trusted supplier instead of targeting each institution separately. Technology procurement must therefore move beyond price and immediate specifications to the life cycle: who owns the data? Can the state audit? How long is update support provided? What is the End-of-Life plan? Can the service be moved? How does it operate if the supplier stops?
Vendor Lock-In is not automatically corruption or “betrayal of sovereignty”. It is a technical, financial, operational and sovereign risk when a critical function cannot be transferred within acceptable time and cost. Dependencies are therefore classified as ordinary, requiring diversification, or critical and requiring an alternative, exit plan or domestic capability. Every critical contract should define Data Ownership, Portability, Audit Rights, Patch Support and an Exit Plan as far as law and market conditions permit.
| Dependency type | Description | Management decision |
|---|---|---|
| Ordinary | Replaceable supplier and portable data | Routine commercial and security management |
| Requires diversification | Change is possible but slow or costly | A second alternative, standardisation and transition plan |
| Critical | Supplier failure stops a national function, or exit is difficult | Recovery plan, robust contracting, alternative/domestic capability and leadership review |
| Cloud concentration | Several critical functions rely on one provider | Dependency Map, failure-scenario test and exit plan |
The cloud is neither a risk nor a solution in itself. Decisions should balance data sensitivity, jurisdiction, continuity, institutional management capacity, audit, portability, access management, sovereign elements and exit planning. Public Cloud, Private/Government Cloud and Hybrid models serve different purposes. Architectural detail belongs in the technology parts; the security question here is whether the state remains able to operate the function and change suppliers when necessary.
11. Cyber Defence and Deterrence: Making Attacks Less Rewarding
This chapter takes only the strategic boundary from “The Professional National Army”: modern armed forces depend on networks, communications, command and control, digital platforms and technological supply chains, and therefore need protection, continuity and Iraqi incident-leadership skills within defence networks. The chapter provides no offensive capabilities, targets, vulnerabilities or operational plan; such information is unnecessary for the public vision and should not be published.
Cyber deterrence is more complex than military deterrence because attribution may remain probabilistic, actors are numerous, and much activity occurs below the threshold of conventional conflict. Iraq's near-term deterrent foundation is therefore denial and resilience: reducing the chance of success and the resulting impact, rapid recovery, legal and diplomatic cooperation, and increasing the cost of exploiting the system. The vision does not recommend “hacking in response to hacking”.
12. Disinformation: Protecting the Information Environment Without a “Ministry of Truth”
A cyberattack targets a system, data or service; information manipulation targets perception, trust, behaviour and decisions, and the two may overlap. The chapter therefore distinguishes unintentional Misinformation, intentional Disinformation designed to mislead, Malinformation using true or partial information in a harmful context, and wider influence operations. An informational error alone is insufficient to make something a national-security case.15
Manipulation rises to a security level when it is widespread, organised and deliberate and linked to substantial harm: inciting violence, disrupting emergency response, large-scale deception during a crisis, or undermining a sensitive national function. Criticism, satire, opinion, opposition and an isolated inaccurate report do not automatically become “threats”. This boundary prevents digital security becoming an overarching jurisdiction above politics and society.
The alternative to a “ministry of truth” is Information Integrity: government channels publishing original data promptly, responsible strategic communication, documented correction, support for independent verification and research, awareness, and platform transparency where regulated by law. Success is not measured by deleted posts, but by the time needed to correct critical government information, the public's ability to verify it, and trust in emergency channels. This approach accords with the Global Digital Compact's emphasis on a more trustworthy information environment and respect for rights.
12.1 Deepfakes: Verification Speed Becomes a Security Capability
Synthetic generation raises verification costs: an official may be impersonated through audio or video, fabricated content used in fraud or a crisis, or evidence confused. This is not solved by one “deepfake detector”; detection tools themselves are probabilistic. A more robust response combines verifiable official channels, Content Provenance where available, verification training for media and institutions, and rapid government communication that does not leave an information vacuum.
Time becomes a security indicator here: how long does it take to confirm or deny information affecting a national function or public safety? Is there an accountable spokesperson? Are updates dated and retrievable? Does the state correct its error if its first assessment proves incomplete? Informational trust is built more through such behaviour than through surveillance.
12.2 Internet Shutdowns: A Last-Resort Instrument, Not a Routine Cybersecurity Measure
Iraq's recent history includes widespread internet shutdowns during the 2019 protests; the United Nations documented their effects on information flows and freedom of expression. This experience makes any broad communications disruption an exceptional option subject to a strict legal test: legal basis, necessity, proportionality, less harmful alternatives, a defined duration and review. Its effects on emergencies, payments, businesses and security itself must also be weighed, rather than assuming that disconnecting a network automatically “increases security”.16
13. The State in the Age of Artificial Intelligence
Artificial intelligence is not a separate “security sector”, but changes both sides of the equation: attackers can accelerate fraud, social engineering, disinformation and vulnerability analysis; defenders can triage alerts, analyse logs, detect patterns and assist analysts. It is therefore insufficient for the state to be an “AI user”: it must know where AI is used, the decision's impact, the data accessed and who bears responsibility.
Iraq established the National Artificial Intelligence Centre within the Prime Minister's Office in 2025, while the national strategy's official website still describes it in 2026 as under development. This chapter therefore creates no new centre and formulates no economic AI policy; it establishes a security and rights gate before high-impact uses spread.17
13.1 Risk-Based Governance
Not every AI system needs the same procedure. A limited internal summarisation tool differs from a system affecting personal liberty, service eligibility, a security decision or critical infrastructure. The vision therefore proposes impact-based classification: low, medium and high impact. Higher impact brings stronger requirements for inventory, impact assessment, data governance, testing, documentation, monitoring, and appeals and human review.
| Governance element | Low-impact use | High-impact use |
|---|---|---|
| Inventory | Simple functional registration | A clear central/sectoral register and accountable owner |
| Impact assessment | Light review | Impact Assessment before deployment and after material changes |
| Data | Institutional policy | Documented source, quality, rights and purpose |
| Security | General baseline | AI Security, testing and supply chain |
| Human review | As needed | Meaningful Human-in-the-Loop/On-the-Loop |
| Audit | Operational log | Auditability, decision records and an appeal pathway |
| Shutdown | Routine procedure | Kill/rollback procedure in the event of danger or material deviation |
Source: NIST AI RMF; UNESCO Recommendation on the Ethics of AI;. 20 21
13.2 Human-in-the-Loop: Responsibility Does Not Transfer to the Algorithm
The governing principle is not to prohibit automation, but to make human oversight proportionate to decision impact. A system may sort, alert, summarise and suggest; decisions affecting liberty, rights, legal entitlements, use of force, or a security classification directly producing punitive consequences require meaningful human review and an accountable person.
The new rule connects to the preceding chapter: More Data ≠ Better Intelligence, joined by More AI ≠ Better Intelligence. A faster model may amplify data errors, bias or hallucinations. And AI Output ≠ Verified Intelligence: automated output requires verification of source, context and confidence before use in a security or legal decision.
13.3 AI Security: Protect the Model, Not Only the Network
AI Security extends beyond protecting the server running the model. Risks include data poisoning in its general sense, sensitive-data leakage, model theft or misuse, untrusted components and suppliers, hallucinations, and excessive reliance on output. In a vision chapter, this category requires no exploitation techniques; it requires procurement, assessment, testing, monitoring and responsibility rules, and an incident plan.
In government procurement, the security questions become: where are data processed? Are they used to train the model? Who owns them? Can auditing occur? How long are they retained? Can the service be moved? What alternative exists if the supplier changes? This does not mean every government model must be “Iraqi”; it means high-impact dependence must be understood, manageable and capable of exit.
14. Personnel: The Bottleneck Licences Cannot Solve
GCI places capacity development among Iraq's relatively weakest pillars. This gap differs from purchasing a security platform: a system without an analyst, engineer, incident responder or leader able to decide becomes supplier-dependent even if the product is world-class. In 2027, the state therefore needs a Workforce Assessment beginning with functions, not publicity figures.
Critical roles may include Incident Response, SOC Analysis, GRC, Security Architecture, IAM, Digital Forensics, OT Security, Cloud Security, Threat Analysis and AI Security. Each pathway needs a role description, skills, practical training, assessment and promotion. Public service needs tools to attract and retain expertise in a market competing locally and internationally. External suppliers may be used, but Outsource Service ≠ Outsource Accountability.
Universities are part of the personnel supply pipeline, not substitutes for operations. Laboratories, practical training, partnerships and lawful research projects are needed, not certificate counts. The private sector is a national partner because important parts of communications, finance, energy and digital services are operated outside government. It needs obligations, standards, reporting and disciplined information sharing, not a relationship of “a customer buying protection from the state”.
14.1 The Private Sector and Threat-Information Sharing
Private or mixed-ownership companies operate parts of communications, payments, cloud services, energy and digital services. Government cannot therefore see the entire national environment through its own networks alone. Information sharing, however, needs design that protects commercial secrets and personal data and prevents a central repository for everything. What is shared is what the other party needs to reduce risk or manage an incident, at the appropriate classification and time.
Sectors can use threat-sharing channels or communities, but this chapter does not require a new ISAC for every sector. The function may already exist within a regulator, association or joint operations room. The test is whether information reaches those who can act, whether recipients know its confidence level and permitted use, and whether access to sensitive data is logged.
Mandatory reporting of critical incidents differs from voluntary sharing of indicators and experience. The former needs a legal definition, time threshold and good-faith protections; the latter rests on trust and mutual benefit. Combining them without distinction may lead companies to avoid cooperation for fear of liability or reputational damage.
15. A Few Standards, with a Clear Function for Each
The vision uses international standards as instruments translating arguments into measurement. NIST CSF 2.0 provides a national language for governance, risks and the operational cycle. ISO/IEC 27001 supports information-security management systems for mature institutions and appropriate contracts. IEC 62443 serves OT. ISO 22301 assists business continuity. NIST AI RMF and ISO/IEC 42001—where appropriate—provide frameworks for AI-risk governance. These names should not become a list of mandatory certifications.
| Framework | Function in the vision | What it does not mean |
|---|---|---|
| NIST CSF 2.0 | National language for governance, outcomes and the risk cycle | Not a product list or law |
| ISO/IEC 27001 | An information-security management system for suitable institutions and contracts | Certification does not mean absence of risk |
| IEC 62443 | A reference for OT industrial-system security | Not applied literally to all IT |
| ISO 22301 | Business continuity and testing recovery capability | Does not replace sectoral technical and operational plans |
| NIST AI RMF | Assessing and managing high-impact AI risks | Not an AI law |
| ISO/IEC 42001 | An AI management system for suitable institutions | Compliance does not eliminate rights review |
Source: NIST; ISO/IEC.
16. What Do We Learn from Abroad? The Mechanism, Not the Country
Comparison requires specific mechanisms. Singapore offers lessons in CII designation and obligations for essential-service owners and regulators. The United Kingdom offers the NCSC model and Cyber Assessment Framework, focused on outcomes, essential functions, response and recovery. Through CISA, the United States highlights a small, high-impact minimum and partnerships with infrastructure owners. Estonia offers lessons in state continuity, exercises and distributed capability after digital crises. Finland helps integrate information resilience into comprehensive security. No country's size, law or institution is copied; governance functions suited to Iraqi mandates are transferred.
| Case | Mechanism | What suits Iraq | What not to copy |
|---|---|---|---|
| Singapore | CII designation and sectoral obligations | Impact criterion + function owner + reporting and exercises | Administrative concentration and country size |
| United Kingdom | NCSC + outcomes-based CAF | Assessment and measurement of functional resilience | The legal and institutional structure unchanged |
| United States | CISA, critical-infrastructure partnerships and CPGs | A high-impact minimum + sectoral partnership | Resource scale and detailed federal arrangements |
| Estonia | Continuity, exercises and a digital state | Recovery testing and distributed capability | Country size and digital-identity architecture |
| Finland | Comprehensive security and information resilience | Crisis communication and participation by society and the private sector | The entire political-administration model |
Comparative sources: Cyber Security Agency of Singapore; UK National Cyber Security Centre; CISA; and relevant official Estonian and Finnish sources.
17. Threats in 2045: Scan the Horizon Without Turning Every Trend into a Project
In the near term, ransomware, supply chains, data leakage, deepfakes, AI-enabled fraud, OT risks and cloud-service concentration remain directly relevant. In the medium term, IoT, smart infrastructure, autonomous systems, intelligent agents and dependence on advanced communications and space services will intensify. Further ahead, post-quantum risks arise for long-lived assets and cryptography. These are not “inevitabilities”: they are Horizon Scanning, elevating a trend into a programme only when probability or impact changes, or long-lived assets justify early investment.
In post-quantum cryptography, for example, uncertainty does not justify an immediate wholesale replacement programme. The more rational starting point is a Crypto Inventory and Crypto-Agility Planning for long-lived assets, so the state knows what needs transition, when and at what cost. This philosophy protects the vision from chasing technological fashion instead of building renewable capability.
17.1 Strategic Scenarios That Do Not Reveal Weaknesses
Scenarios help identify capabilities shared across different threats without producing “digital war plans”. A scenario assumes no particular adversary and names no actual Iraqi asset. It tests only who decides, what alternative exists, whether a copy exists, what communications channel is used, which supplier might fail, and whether the function can be restored.
Table 10A: Non-operational strategic scenarios
| Scenario | Driver | Institutional test | Shared capabilities |
|---|---|---|---|
| Widespread government ransomware | Compromise of an interconnected service | Escalation, backups, continuity and communication | IAM, Backup, CSIRT, Crisis Comms |
| Failure of a major supplier/cloud service | External or supply-chain failure | RTO, alternative and Exit Plan | Dependency Map, Portability, BCP |
| OT incident in a critical sector | Disruption of physical operations | Sectoral and national coordination and safety | OT IR, Recovery, supplier management |
| Deepfake during a crisis | Impersonation of an official or fabricated information | Verification, communication and trust | Official Channels, Provenance, Media Literacy |
| A high-impact government AI system makes an error | Data, model or excessive reliance | Review, responsibility and appeal | AI Inventory, Impact Assessment, Human Review |
18. The Vision for a Digitally Secure Iraq in 2045
A digitally secure Iraq in 2045 is not a state that cannot be breached. It is a state that knows its assets, risks and dependencies; applies a clear minimum and gives critical functions stronger protection; detects and contains incidents and restores services within acceptable times; tests backups and restoration rather than assuming them; can change suppliers or operate alternatives when necessary; and protects citizens' data under purpose, law and oversight.
It is also a state that uses AI without transferring responsibility to an algorithm, counters disinformation through transparency, communication and resilience rather than political management of truth, and has Iraqi personnel leading national incidents and decisions even when using an external supplier or partner. Success means less impact, faster recovery, institutional learning and known dependencies—not a publicity figure for “thwarted attacks”.
19. Transformation Phases, 2027–2045
| Phase | Purpose | Core interventions | Conditions for progression |
|---|---|---|---|
| 2027–2030: Understanding assets and risks | Build a baseline and measurable governance cycle | Strategy review; CII; Asset Inventory; Baseline Controls; Incident Reporting; legal review; Workforce/Supplier Assessment; initial exercises | Critical-function/asset register; approved minimum; incident dictionary; MTTD/Containment/Recovery baselines; data and rights programme |
| 2031–2035: Sectoral defence and resilience | Turn standards into operation and testing | SOC/CSIRT as needed; OT; Backup/Recovery; sectoral exercises; Supply-Chain Controls; career paths; data protection and enforcement | CII coverage; successful recovery tests; repeated closure of root causes; fewer unaddressed dependencies |
| 2036–2040: National digital integration | Connect sectors without excessive operational centralisation | Disciplined information sharing; AI Security; multi-sector response; Dependency Resilience; mature measurement | Most critical sectors at the “measured” level; cross-sector recoverability; stable indicator-data quality |
| 2041–2045: An adaptive state | Make updating and learning normal institutional functions | Periodic standards and strategy updates; Horizon Scanning; critical domestic capabilities; adaptive testing | Continuity across governments; technological change does not stop functions; risks and controls updated automatically without permanent emergency |
20. Indicator and Target Dashboard
A good indicator in this chapter measures function, not noise. Raw incident counts are insufficient: they may rise because reporting improves. Tool or certificate counts are insufficient: an institution may be certified yet slow to recover. The dashboard therefore focuses on coverage, time, restoration, risk closure, personnel, suppliers and AI governance.
| Indicator | Baseline | 2030 | 2035 | 2040 | 2045 |
|---|---|---|---|---|---|
| CII designation and function ownership | Completed in 2027 | 100% of the designated scope | Annual review | Dynamic review | Automatic updating as functions change |
| Baseline Controls for critical government institutions | Established after assessment | 100% within an announced scope | Effectiveness audit | Sectoral improvement | Adaptive Baseline |
| Incident Reporting + Severity Matrix | Not publicly standardised | A complete national system and 24/7 operation | Trend analysis | Cross-sector integration | Monitored machine learning with Human Review |
| MTTD/Containment/Recovery | No public national baseline | Establish the baseline and achieve a meaningful reduction after two years | Numerical target established after the baseline | Continuous improvement | Advanced resilience within risk limits |
| Recovery tests for critical functions | Not standardised | Annual test for every designated function | Cross-sector exercises | Interconnected national exercises | Adaptive tests |
| Critical cyber roles | No unified taxonomy | Taxonomy + baseline + gap-closing plan | Reduce vacancies against the baseline | Stable career path | Self-renewing skills |
| High-impact AI governance | No unified register | Register and assess 100% of new high-impact government systems | Periodic audit | Integrated AI Security | Adaptive governance |
| Data-protection framework | Fragmented framework | An effective general framework or equivalent package | Enforcement and measurement | Alignment with emerging technologies | Continuous updating |
The use of 100% here is confined to coverage obligations with a defined denominator—such as designating all CII functions within an official scope, or assessing all new AI systems classified as high impact—not a claim of 100% security. Time and quality targets are established after an Iraqi baseline; another country's figures are not borrowed as if they were Iraqi capability.
21. Implementation Programmes: From Governance to Resilience
The recommendations become a memorable package. They do not create a new agency for every gap, but distribute functions among the National Centre, regulators, service owners, legal authorities, education and defence according to jurisdiction. Costs are classified qualitatively now and quantified after existing assets, personnel and controls are inventoried.
| Programme | Problem | Lead Body | 2027–2030 | Cost |
|---|---|---|---|---|
| P1 Strategy cycle and baseline | The 2022–2025 horizon has ended; measurement gaps remain | NCC + Prime Minister's Office | Strategy Refresh + maturity/incident baseline + closure matrix | Costing study |
| P2 CII and critical-sector governance | Publicly incomplete designation and obligations | NCC + sectoral regulators | CII criteria + obligations + sector profiles | Moderate regulatory/technical cost |
| P3 National minimum controls | Uneven maturity | NCC | Baseline Controls + audit + remediation | Ongoing, varying by institution |
| P4 Response and reporting | No unified public indicators | NCC | Severity + reporting + exercises + post-incident | Medium |
| P5 Resilience and continuity | Risk of cascading disruption | NCC + service owners | RTO/RPO + recovery tests + dependency maps | Sectoral; requires costing |
| P6 OT/ICS security | The distinct nature of industrial systems | Sectoral regulators + NCC | OT baseline + supplier/legacy management | High at sectoral level |
| P7 Supply chains and dependencies | Vendor lock-in and supplier dependence | PMO/NCC + procurement + sectors | Critical supplier register + exit/portability | Low–moderate organisational cost |
| P8 Personnel | Capacity gap | NCC + public service + education | Workforce taxonomy + career paths + labs | Moderate recurring cost |
| P9 Data protection and sovereignty | Fragmented framework | Competent legislative/oversight authority + NCC | Data framework + classification + breach rules | Legal/regulatory |
| P10 Information integrity | Manipulation without an integrated rights framework | Government communication + CMC + society/media | Rapid comms + transparency + literacy | Low–medium |
| P11 AI governance and security | AI strategy under development | NCAI + NCC + legal authorities | AI inventory + risk tiers + human oversight | Medium |
| P12 Strategic cyber defence | Protecting digital military capabilities | Ministry of Defence + NCC for coordination | Defensive governance + exercises + supplier resilience | Classified/separate costing |
21.1 Concise Implementation Matrix
| Gap | Action | Basis/owner | Start | Indicator | Risk/mitigation |
|---|---|---|---|---|---|
| Strategy whose time horizon has ended | Review 2022–2025 and issue an updated cycle | NCC mandate | 2027 | Strategy approval + closure matrix | A document without implementation → link to indicators and budgets |
| No unified operational baseline | National Cyber Metrics Dictionary | NCC | 2027 | Share of indicators with definitions and owners | Reporting proliferation → a limited dashboard |
| CII not publicly standardised | Designation criteria and obligations | NCC + sector | 2027 | CII coverage | Sensitive disclosure → publish sectors, not assets |
| Uneven controls | National Baseline Controls | NCC | 2027 | Effective compliance | Checklist gaming → audit outcomes |
| Concealed incidents | Reporting rules and good-faith protection | NCC + legislation/regulation | 2027 | Share reported on time | Penalties encouraging concealment → Safe Reporting |
| Unmeasured recovery | RTO/RPO and Recovery Testing | CII owners | 2027 | Successful tests | A paper plan → annual testing |
| Supplier dependence | Critical Dependency Register | PMO/procurement/NCC | 2028 | Dependencies with an Exit Plan | Diversification costs → Risk Tiering |
| Skills gap | Cyber Career Framework | Public service/NCC | 2027 | Critical-role vacancies | Attrition → incentives and career paths |
| AI without an inventory | High-Risk AI Registry | NCAI/NCC | 2027 | Coverage of high-impact systems | Shadow AI → Procurement Gate |
| Crisis disinformation | Rapid Information Integrity Protocol | Government communication | 2027 | Correction time | Politicisation → Narrow Harm Test and review |
22. Costs and Financing: Operational Capability, Not a One-Off Purchase
The chapter sets no aggregate “cybersecurity budget”, because published asset, personnel, control and sector inventories do not support a defensible estimate. An overall figure before inventory would create false precision. The first phase therefore begins with a Costing study linked to the CII Inventory, Workforce Assessment and Current Controls.
Costs comprise governance and compliance, personnel, tools and licences, SOC/CSIRT operation where needed, Backup/DR, OT assessments, training, exercises, standby response services, supplier assurance, and maintenance and updating. CAPEX must be separated from OPEX: cybersecurity is a recurring operational capability, and a tool whose updates and staff are unfunded after a year is not a complete investment.
National financing comes from the public budget for shared capabilities; institutional and sectoral budgets for their own responsibilities; regulated cost sharing with private infrastructure owners where lawful; and technical assistance for training and standards, not permanent operation of sovereign capabilities. The rule is that a service can be outsourced, but accountability cannot.
22.1 What Do We Not Yet Know? The Data-Gap Register
Part of the 2027 programme is not “implementing solutions”, but creating dependable measurement. Public national tables do not currently support unified figures for detection, containment and recovery times, asset-inventory completion or cyber vacancies. These gaps must have owners and baseline-building methods. At the same time, some details are legitimately classified so transparency demands do not expose weaknesses.
Table 14A: Data gaps and legitimate secrecy register
| Data item | Case | Proposed owner | Public/internal | First-phase action |
|---|---|---|---|---|
| Incidents by severity | Not available in unified public form | NCC | Public aggregates | Unified reporting dictionary and definition |
| MTTD/Containment | No public national baseline | NCC/sectors | Aggregate + internal | Measure for 12 months after definitions are standardised |
| Recovery within RTO | Not available in unified form | CII owners/NCC | Aggregate | Annual tests and results report |
| Asset Inventory completeness | Not available in aggregate | Each institution/NCC | Internal + aggregate | Inventory, classification and asset owner |
| MFA for critical accounts | Unavailable | Each institution | Internal/aggregate | Define “critical” and Baseline Controls |
| Critical Supplier Map | Unavailable | PMO/NCC/sectors | Legitimately classified | Dependency Register |
| OT Maturity | Unavailable | Sectoral regulator | Classified/aggregate | Sector Assessment |
| Cyber Workforce Vacancies | Not available in unified form | Public service/NCC | Public aggregates | Workforce Assessment |
| Data Breaches | Not standardised | Data owners/NCC | Public aggregates | Breach Notification Framework |
| AI Systems Inventory | Not available in unified form | NCAI | Internal/aggregate | High-Risk AI Registry |
23. Risks: How Can Cybersecurity Reform Fail?
| Risk | Likelihood | Effect | Warning indicator | Mitigation |
|---|---|---|---|---|
| Excessive centralisation in the NCC | Medium | High | Backlogged requests and slow response | Central policy and distributed implementation |
| Institutional overlap | High | High | Repeated or conflicting instructions | A jurisdictional map and escalation protocol |
| Personnel shortages and attrition | High | High | Vacancies and excessive contractor dependence | Career paths, incentives and practical training |
| Vendor Lock-In | Medium–high | High | Contracts without Exit/Portability | Contractual terms, alternatives and dependency assessment |
| Supply-Chain Compromise | Medium | Very high | An unassessed critical supplier | Supplier Assurance and reporting |
| Ransomware | High | High | Recurrence and restoration failure | Baseline + Recovery Tests |
| Data leakage | High | High | Excessive access/reports | Classification + IAM + Breach Response |
| Mass surveillance | Medium | High rights impact | Expanded access without a purpose | Purpose/necessity/proportionality/oversight |
| SOC without analysts | Medium | Medium–high | Backlogged alerts without decisions | Workforce + a managed service with safeguards |
| Unsupervised AI | Increasing | High | Shadow AI and unexplained decisions | Registry + Procurement Gate + Human Review |
| Politicised counter-disinformation | Medium | High | Targeting legitimate criticism | Narrow Harm Test and independent review |
| Cloud Concentration | Medium | High | Many services on one supplier | Dependency Map + Exit Plan |
| OT Incident | Medium | Very high | No restoration testing/supplier management | A sectoral OT programme and tests |
| Concealed incidents | High | High | A gap between signals and reported cases | Safe Reporting + Metrics |
24. Safeguards: A Secure Digital State Does Not Protect the Government from Citizens
Cybersecurity does not replace the Constitution. Every collection, processing or sharing of security data needs a legitimate purpose, necessity and proportionality limits, and the minimum possible data, retention and access. Surveillance affecting confidentiality of communications requires a legal basis and judicial oversight where constitutionally required. A cybersecurity platform must not become a gateway to political or social dossiers unrelated to a defined threat.
For artificial intelligence, safeguards are identifiable human responsibility, audit logs, impact assessment, bias and discrimination testing, the ability to stop and roll back, and an appeal or review pathway when a decision affects rights, security or a high-impact entitlement. For disinformation, the safeguard is defining harm, intent and scope rather than punishing errors or criticism, while protecting journalism, research and expression.
These safeguards are not a “cost imposed on security”. They prevent a system expanded during crisis from becoming a permanent, unaccountable function. Sustainable security needs trust and cooperation. If citizens fear every digital service is a surveillance channel, the state loses the value of digital transformation itself.
25. Closing Part Three: From Protecting Territory to Protecting Digital Functions
This part has completed four layers of capability. “Security as a Condition for National Renewal” identified what must be protected and defined deterrence, readiness and resilience under the law. “The Professional National Army” translated defence into an institution, doctrine and sustainable capabilities. “Internal Security and Intelligence” assigned everyday protection to professional policing, investigation and intelligence under the law. This chapter adds the digital and information layer on which the preceding three increasingly depend.
The part's equation is therefore: material capability + institutional capability + information and digital capability + law and rights + readiness and resilience. State strength in 2045 is measured not by weapons, agency numbers or security-platform counts, but by the ability to protect territory, society, information and digital functions, continue through shocks, and use physical and digital power under sovereign decision-making, oversight and responsibility.
The chapter does not close the security discussion with a promise of “the end of threats”. It closes with institutions able to update themselves. Risks, suppliers and technology change. Iraq needs not a fixed system for 2045, but a state able to reassess risks, standards, dependencies and skills whenever its environment changes.
26. The Bridge to Part Four: The Economy and National Production
If Iraq achieves a capable state, sovereignty, law, effective government and integrity, then builds national security, a professional army, internal security and digital capability protecting institutions and infrastructure against old and new threats, the question of material endurance remains: can an economy heavily dependent on a single oil resource finance this state and maintain its stability, independence and investment through 2045?
Part Four: The Economy and National Production
Chapter One: The End of the Rentier State
V1-D04-C01
References
- Iraqi Council of Representatives, Constitution of the Republic of Iraq, 2005.
- Ministry of Justice/Iraqi Official Gazette, Instructions on the Formations and Functions of the Prime Minister's Office No. (1) of 2025.
- National Cybersecurity Centre, official website, institutional materials and the Iraqi Cybersecurity Strategy 2022–2025.
- National Security Advisory and Iraqi government authorities, Iraqi National Security Strategy “Iraq First” 2025–2030.
- Iraqi Council of Representatives, official materials on the proposed Law on Combating Information Technology Crimes, 6 July and 26 August 2026.
- Communications and Media Commission, published regulations for cybersecurity services, data centres and digital platforms, 2025–2026.
- International Telecommunication Union, Global Cybersecurity Index 2024 — Iraq country profile.
- NIST, The Cybersecurity Framework (CSF) 2.0, 2024.
- NIST, Artificial Intelligence Risk Management Framework and Generative AI Profile, 2023–2024.
- ISO/IEC 27001:2022, Information Security Management Systems; ISO 22301, Business Continuity; ISO/IEC 42001, AI Management Systems.
- IEC 62443 series, Security for industrial automation and control systems.
- Cyber Security Agency of Singapore, Cybersecurity Act and Critical Information Infrastructure materials.
- UK National Cyber Security Centre, Cyber Assessment Framework.
- CISA, Cross-Sector Cybersecurity Performance Goals.
- United Nations, Global Digital Compact, 2024.
- UNESCO, Recommendation on the Ethics of Artificial Intelligence, 2021, and subsequent governance resources.
- Iraqi National Center for Artificial Intelligence / Prime Minister’s Advisory Office, Iraqi National Artificial Intelligence Strategy portal, status in 2026.
- Iraqi Ministry of Planning, official materials on developing the National Artificial Intelligence Strategy, 2026.
- UNAMI/OHCHR, Human Rights Violations and Abuses in the Context of Demonstrations in Iraq, 2020, concerning internet restrictions and shutdowns during the 2019 protests.
- Iraqi Insurance Diwan, Insurance Sector Governance Guide, 2026, requirements concerning information security, RPO/RTO and recovery tests.
Footnotes
National Cybersecurity Centre, “Iraqi Cybersecurity Strategy 2022–2025”, strategy document published on the official website. ↩︎
Ministry of Justice/Iraqi Official Gazette, Instructions on the Formations and Functions of the Prime Minister's Office No. (1) of 2025, provisions concerning the National Cybersecurity Centre and its mandates. ↩︎
International Telecommunication Union (ITU), Global Cybersecurity Index 2024, Iraq country profile: Tier 4 (Evolving); pillar scores total 53.07/100. ↩︎
U.S. National Institute of Standards and Technology (NIST), The Cybersecurity Framework (CSF) 2.0, 2024. ↩︎
Ministry of Justice/Iraqi Official Gazette, Instructions on the Formations and Functions of the Prime Minister's Office No. (1) of 2025, mandates of the National Artificial Intelligence Centre. ↩︎
Iraqi Council of Representatives, Constitution of the Republic of Iraq, 2005, especially Articles 17, 38, 40 and 46 concerning privacy, confidentiality of communications, freedom of expression and limits on restrictions of rights. ↩︎
Iraqi Council of Representatives, decisions and recommendations of the 6 July 2026 session concerning the first reading of the proposed Law on Combating Information Technology Crimes; and Parliamentary Security and Defence Committee, meeting of 26 August 2026 on continued refinement of the proposal. It was not an effective law as of that date. ↩︎
Iraqi Communications and Media Commission, regulations published during 2025–2026 concerning cybersecurity-service companies, data-centre services, platforms and digital services; used here to establish the development of sectoral regulation, not as a comprehensive data-protection law. ↩︎
Iraqi National Security Strategy “Iraq First” 2025–2030, published Iraqi government materials. ↩︎
Cyber Security Agency of Singapore, Cybersecurity Act and Critical Information Infrastructure materials, used here for the mechanism of designation, obligations, reporting and oversight — not for direct legal transplantation. ↩︎
IEC 62443 series, Security for Industrial Automation and Control Systems, current materials. ↩︎
UK National Cyber Security Centre, Cyber Assessment Framework (CAF), current version, particularly essential functions, response and recovery outcomes. ↩︎
U.S. Cybersecurity and Infrastructure Security Agency (CISA), Cross-Sector Cybersecurity Performance Goals, current materials used for a small high-impact baseline approach. ↩︎
Iraqi Insurance Diwan, Insurance Sector Governance Guide, 2026, requirements concerning information security, RPO/RTO and recovery tests. ↩︎
United Nations, Global Digital Compact, 2024, provisions and commitments concerning information integrity, trustworthy information, platform transparency and digital governance. ↩︎
UNAMI/OHCHR, Human Rights Violations and Abuses in the Context of Demonstrations in Iraq, 2020, documenting broad internet shutdowns/restrictions during the 2019 protests and their human-rights context. ↩︎
Iraqi National Center for Artificial Intelligence / Prime Minister’s Advisory Office, Iraqi National Strategy for Artificial Intelligence portal, which in 2026 described the national strategy as under development. ↩︎