Pacific Cybersecurity in an Interconnected World
Our expanding digital environment brings forth substantial opportunities and attendant risks. For the Pacific Islands, an area with a distinct cultural composition and swift technological uptake, cybersecurity is now a focal point. As our oceanic nations integrate more digital technologies, strong safeguards against cyber attacks become a high priority. This work requires technology but also a complete approach that covers legal frameworks, personnel development, regional collaboration, and current threat knowledge while recognizing global cybersecurity inputs and industry successes.
"the creation and reinforcement of national and regional Computer Emergency Response Teams"
The burgeoning digital space makes available significant prospects alongside inherent risks. For the Pacific Islands, a region defined by its rich cultural makeup and accelerating technological embrace, cybersecurity has ascended to a matter of considerable attention. As nations across this oceanic continent increasingly embed digital technologies, the drive to build strong defenses against a range of cyber intrusions and bad intentions becomes more pronounced. This undertaking extends past technological fortifications and calls for a comprehensive strategy that includes legal structures, skill enhancement, inter-island cooperation, and a keen awareness of the shifting threat environment while acknowledging the contributions of global cybersecurity stakeholders and celebrating achievements in this sector.
Contrary to perceptions of remoteness, the Pacific Islands are integrated into the global digital commons and are consequently exposed to the worldwide increase in cybercriminal operations. The rollout of high-speed internet and the expansion of online services, while unlocking avenues for digital commerce, governance, and communication, simultaneously enlarge the exploitable domain for malevolent initiatives. Island nations confront a variety of cyber offenses, from internet-based fraud and data exfiltration to incursions against foundational systems. The Tongan experience in 2022, when a volcanic event severed its primary international communication line, starkly illustrated the acute reliance of our island states on connectivity and the severe human and economic fallout when these digital conduits are compromised.
Indeed, submarine fiber optic cables, which convey the bulk of global telecommunications at lightspeed, face man-made perils like espionage and deliberate damage, especially amidst rising geopolitical strains. While Pacific leadership often prioritizes undersea cables for socio-economic advancement, the intrinsic security of this infrastructure is a cornerstone of national stability. The Pacific Islands Forum (PIF) has identified cybersecurity as a prominent security concern, notably in the Boe Declaration on Regional Security its members signed in Nauru. Subsequently, the Lagatoi Declaration from the 2023 Pacific ICT Ministerial Meeting in Port Moresby, Papua New Guinea, reinforced this stance as it advocates for the reinforcement of foundational infrastructure, a designation that would logically encompass these essential subsea connections.
And the monetary impact of cybercrime is substantial. Consider Fiji, where, from 2013 to 2015, investigations into cyber-enabled fund diversions from legitimate vendors tallied over one million Fijian dollars (US$ 535,000). The Pink Window Creations incident of 2013 concerning online transactions for undelivered goods valued at around US$70,000 revealed shortcomings in Fiji's cybercrime laws at the time.
In response to these burgeoning threats, South Pacific nations are methodically advancing their cybersecurity legislation and strategic plans. Tonga and Fiji have taken notable strides in this arena. Tonga established its Computer Crimes Act (TCCA) in 2003, which was later superseded by the Computer Crimes Bill 2019, and became a signatory to the Budapest Convention on Cybercrime. The Convention supplies a model for national cybercrime law development and a structure for international teamwork. Tonga's adoption of this is viewed as a significant step in regional cybersecurity governance for it fortifies its mechanisms to counteract online illicit activities.
Meanwhile, Fiji has rolled out its Crimes Decree in 2009 to address computer-related offenses, although questions have been raised regarding its overall efficacy in preventing the full array of online fraudulent acts and cyber offenses. Identified gaps included the handling of unauthorized access, online child exploitation materials, and device misuse. Consequently, new legislative proposals in Fiji aim for more stringent measures against cyber offenders. These proposals include considerable financial penalties for individuals and corporate entities, and enhanced powers for authorities to inspect and confiscate digital devices and data. Similarly, Vanuatu bolstered its legislative arsenal with the Computer Cybercrime Act No. 22 in 2021. The act is designed to criminalize unauthorized digital actions, shield its population, improve electronic evidence gathering, and institute avenues for global cooperation.
Despite these developments, a recurring observation points to vulnerabilities arising from inadequately developed cybersecurity frameworks, occasionally compounded by a lack of comprehensive national policies and sufficiently detailed protective statutes. The swift evolution of ICT means that legal instruments must possess inherent adaptability and carry penalties substantial enough to discourage and redress online transgressions. A further impediment is the shortage of legal professionals specializing in cybersecurity and personnel trained in forensic investigation, enforcement, prosecution, and judicial processes related to cybercrime. A real brain drain issue that our teams witness when we translate legal and judicial documents. Building this human resource, possibly through international training programs and knowledge exchange, is recognized as a key solution for Tonga and holds relevance for other Pacific states.
Now, the responsibility for cybersecurity does not rest solely within local or regional governmental and law enforcement agencies. Private sector firms are instrumental in developing defenses and influencing operational norms. A case in point is Sophos, a developer of enterprise endpoint security software and network firewalls, and its so-called Pacific Rim initiative. This extensive four-year operation started after Sophos identified a widespread exploitation event that targeted its firewall products in early 2020. The operation entailed heightened telemetry gathering from its firewalls to pinpoint compromised devices. Ultimately, it involved the rollout of a kernel implant to obtain novel malware developed by threat actors and prevent its distribution.
Indeed, submarine fiber optic cables, which convey the bulk of global telecommunications at lightspeed, face man-made perils like espionage and deliberate damage, especially amidst rising geopolitical strains. While Pacific leadership often prioritizes undersea cables for socio-economic advancement, the intrinsic security of this infrastructure is a cornerstone of national stability. The Pacific Islands Forum (PIF) has identified cybersecurity as a prominent security concern, notably in the Boe Declaration on Regional Security its members signed in Nauru. Subsequently, the Lagatoi Declaration from the 2023 Pacific ICT Ministerial Meeting in Port Moresby, Papua New Guinea, reinforced this stance as it advocates for the reinforcement of foundational infrastructure, a designation that would logically encompass these essential subsea connections.
And the monetary impact of cybercrime is substantial. Consider Fiji, where, from 2013 to 2015, investigations into cyber-enabled fund diversions from legitimate vendors tallied over one million Fijian dollars (US$ 535,000). The Pink Window Creations incident of 2013 concerning online transactions for undelivered goods valued at around US$70,000 revealed shortcomings in Fiji's cybercrime laws at the time.
In response to these burgeoning threats, South Pacific nations are methodically advancing their cybersecurity legislation and strategic plans. Tonga and Fiji have taken notable strides in this arena. Tonga established its Computer Crimes Act (TCCA) in 2003, which was later superseded by the Computer Crimes Bill 2019, and became a signatory to the Budapest Convention on Cybercrime. The Convention supplies a model for national cybercrime law development and a structure for international teamwork. Tonga's adoption of this is viewed as a significant step in regional cybersecurity governance for it fortifies its mechanisms to counteract online illicit activities.
Meanwhile, Fiji has rolled out its Crimes Decree in 2009 to address computer-related offenses, although questions have been raised regarding its overall efficacy in preventing the full array of online fraudulent acts and cyber offenses. Identified gaps included the handling of unauthorized access, online child exploitation materials, and device misuse. Consequently, new legislative proposals in Fiji aim for more stringent measures against cyber offenders. These proposals include considerable financial penalties for individuals and corporate entities, and enhanced powers for authorities to inspect and confiscate digital devices and data. Similarly, Vanuatu bolstered its legislative arsenal with the Computer Cybercrime Act No. 22 in 2021. The act is designed to criminalize unauthorized digital actions, shield its population, improve electronic evidence gathering, and institute avenues for global cooperation.
Despite these developments, a recurring observation points to vulnerabilities arising from inadequately developed cybersecurity frameworks, occasionally compounded by a lack of comprehensive national policies and sufficiently detailed protective statutes. The swift evolution of ICT means that legal instruments must possess inherent adaptability and carry penalties substantial enough to discourage and redress online transgressions. A further impediment is the shortage of legal professionals specializing in cybersecurity and personnel trained in forensic investigation, enforcement, prosecution, and judicial processes related to cybercrime. A real brain drain issue that our teams witness when we translate legal and judicial documents. Building this human resource, possibly through international training programs and knowledge exchange, is recognized as a key solution for Tonga and holds relevance for other Pacific states.
Now, the responsibility for cybersecurity does not rest solely within local or regional governmental and law enforcement agencies. Private sector firms are instrumental in developing defenses and influencing operational norms. A case in point is Sophos, a developer of enterprise endpoint security software and network firewalls, and its so-called Pacific Rim initiative. This extensive four-year operation started after Sophos identified a widespread exploitation event that targeted its firewall products in early 2020. The operation entailed heightened telemetry gathering from its firewalls to pinpoint compromised devices. Ultimately, it involved the rollout of a kernel implant to obtain novel malware developed by threat actors and prevent its distribution.
Sophos's public disclosure of the Pacific Rim campaign was intended to stimulate dialogue on the accountability and duties of private companies, particularly those that create edge devices such as firewalls and routers. The firm contended that it is essential to elevate the costs for adversaries by neutralizing their tools. Sophos also argued that cybersecurity solution providers must maintain the capacity to safeguard consumer security, thereby contributing to the overall safety of the internet ecosystem.
Shift and enter to skip a line
Enter for a
Enter for a
As you can see, this assertive approach communicated with notable openness included the use of direct terminology like "kernel implant" rather than some softened phrasing. This generated considerable discussion within the cybersecurity community. Sophos positioned its conduct as adhering to principles of responsible, targeted, and measured actions, comparable to standards advocated for governmental entities. This instance shows the multi-faceted function of corporations in active cyber defense and their input to defining acceptable conduct in the digital sphere. Such corporate actions, when grounded in ethical principles and compliant with laws across relevant territories, can effectively augment governmental efforts to secure digital environments.
For, the Pacific Rim campaign achieved measurable success. Reports indicate that over its four-year span, it prevented the deployment of nine zero-day vulnerabilities and seven rootkits by the threat actor. This outcome seemingly compelled the adversary to modify its Tactics, Techniques, and Procedures (TTPs). The adversary shifted from using high-value zero-day exploits for broad network access to reserving such exploits for more specific, valuable targets. Tit for tat, cyber-coconut style.
For, the Pacific Rim campaign achieved measurable success. Reports indicate that over its four-year span, it prevented the deployment of nine zero-day vulnerabilities and seven rootkits by the threat actor. This outcome seemingly compelled the adversary to modify its Tactics, Techniques, and Procedures (TTPs). The adversary shifted from using high-value zero-day exploits for broad network access to reserving such exploits for more specific, valuable targets. Tit for tat, cyber-coconut style.
In fact, the rise of Artificial Intelligence (AI) and Large Language Models (LLMs) in particular have introduced new facets to cybersecurity, since they are both protective instruments and items of vulnerability. LLMs, exemplified by systems like GPT and BERT, exhibit a strong capacity for interpreting and producing text that tries to mimic human language. They find applications in the automation of threat identification, continuous surveillance, and the contextual evaluation of cyber risks. These models can process extensive unstructured datasets to uncover vulnerabilities and forecast likely intrusion methods. LLMs are also being used for flagging phishing attempts, classifying malware, detecting network intrusions, and managing system vulnerabilities. For example, the SecurityBERT architecture, which leverages the BERT model developed by Google, has registered high accuracy in identifying cyber threats within IoT network environments.
Nevertheless, placing reliance on these advanced models is not without its difficulties. Studies suggest that LLMs may not be consistently dependable for Cyber Threat Intelligence (CTI) when analyzing large-scale, dense reports, as distinct from shorter, more straightforward texts. Their operational effectiveness can vary, and they might display unwarranted certainty in their outputs. This is a significant concern when automated defense systems depend on their analyses without access to comprehensive, verified datasets for cross-checking or RAGs (Retrieval Augmented Generation systems).
Shift and enter to skip a line
Enter for
Enter for
Techniques such as few-shot learning and fine-tuning, intended to enhance LLM outputs, have yielded only marginal gains. In certain CTI extraction tasks, these techniques have even proven counterproductive. To give you an example, in data extraction tasks, fine-tuning gpt4o for retrieving campaign-related information resulted in a recall rate of 0.58, which indicates that 42% of such data points were missed. In the context of information generation, a fine-tuned LLM might entirely fail to produce details of CVEs (Common Vulnerability and Exposure records) used by hostile actors. And we are only talking about the large, very English-centric LLM frameworks.
When queried multiple times with the same input, the consistency of LLM-generated information is also a factor as it may result in what is called hallucination. Research reveals a lack of absolute predictability, with fluctuations in precision and recall for identical tasks across several iterations. Moreover, LLMs are often perceived as black box systems, which makes understanding their internal decision-making logic a mystery. This thereby complicates error analysis and the identification of inherent biases.
When queried multiple times with the same input, the consistency of LLM-generated information is also a factor as it may result in what is called hallucination. Research reveals a lack of absolute predictability, with fluctuations in precision and recall for identical tasks across several iterations. Moreover, LLMs are often perceived as black box systems, which makes understanding their internal decision-making logic a mystery. This thereby complicates error analysis and the identification of inherent biases.
Shift and enter to skip a line
Enter for a
Enter for a
Their potential deficiency in domain-specific understanding for complex technical tasks or particular threat environments can also result in inaccuracies. Scalability is yet another hurdle, as the training and operational deployment of these models require considerable computational power. These operational constraints, combined with ethical questions such as the perpetuation of biases from training datasets and the risk of misuse for creating deceptive materials, mean that rigorous oversight and continuous assessment are fundamental. A real Pandora's Box if not handled right.
So, the multifaceted and complex character of cyber threats needs collaborative actions that extend past individual national capacities. Within the Pacific, the Pacific Islands Forum (PIF) contributes to security cooperation, although its traditional mandate has been wider than cybersecurity alone. The Boe Declaration’s broadened security concept, which explicitly includes cybersecurity and transnational crime, does give a foundation for regional initiatives. The Forum Officials Sub-Committee on Regional Security (FSRS) now facilitates dialogue and the coordination of responses.
Now, unsurprisingly, Australia has emerged as a key supporter of cybersecurity initiatives in the region, which is exemplified by the Pacific Cyber Security Operational Network (PaCSON), established in 2017 to coordinate efforts among the area's cybersecurity professionals. Additional Australian-backed projects include the Australia Pacific Security College (APSC) and the Pacific Fusion Centre (PFC). These are designed to improve security expertise and intelligence sharing throughout the Pacific. These efforts aim to align with the objectives of the Boe Declaration and cultivate a network of security specialists. Aotearoa also affirms its Pacific identity and security collaborations through its Pacific Reset and Pacific Resilience strategies. It supports actions against transnational crime and bolsters police capabilities in several island states.
On the bigger picture, international collaboration is also broadening. The United States, for example, engages in conventional security cooperation and is increasingly addressing non-traditional security concerns. These include cybersecurity and the cyber aspects of illegal, unreported, and unregulated (IUU) fishing. Japan, via its Pacific Islands Leaders’ Meeting (PALM), has increasingly focused on strategic security topics. This focus includes maritime order based on legal principles and support for maritime law enforcement capabilities, partly due to China's expanding regional activities. France, through its territories in the Pacific, also participates in regional security. It engages in joint operations and exercises and backs initiatives via the Secretariat of the Pacific Community (SPC). China, while its security role differs from our traditional partners, has broadened its involvement. And this includes military personnel exchanges, training programs, and aid, often linking these to support for the One China policy.
A fundamental component in strengthening the Pacific's cyber defenses is the creation and reinforcement of national and regional Computer Emergency Response Teams (CERTs). Tonga was the pioneer in the South Pacific, establishing its CERT in 2016 and joining the Asia-Pacific CERT. These CERTs act as primary contact points for cybersecurity incidents and enable global partnerships to counter cyber threats. Such regional entities, when working together with international networks, can significantly enhance collective defense capabilities.
On another note, the efforts of private sector firms are also gaining recognition through awards and collaborative ventures. CrowdStrike, a prominent global cybersecurity enterprise based in Austin, Texas, recently honored its 2025 Asia Pacific and Japan (APJ) Partner Award recipients. These accolades acknowledge the contributions of partners in assisting organizations to consolidate their security expenditures and prevent breaches through platforms such as the CrowdStrike Falcon® cybersecurity system. Although many recipients are larger regional or global corporations, the acknowledgment of companies active in or providing services to the Pacific region points to the cooperative spirit essential in cybersecurity.
Shift and enter to skip a line
Enter for a ne
Enter for a ne
Among the notable overall APJ victors named by CrowdStrike were:
• Sekuro Operations Pty Ltd - APJ Partner of the Year
• Ernst & Young - SI Partner of the Year
•Amazon Web Services (AWS) - Technology Alliance Ecosystem Partner of the Year
•Nexus Technologies, Inc. - MSSP of the Year
•Macnica, Inc. - Distributor of the Year
• Sekuro Operations Pty Ltd - APJ Partner of the Year
• Ernst & Young - SI Partner of the Year
•Amazon Web Services (AWS) - Technology Alliance Ecosystem Partner of the Year
•Nexus Technologies, Inc. - MSSP of the Year
•Macnica, Inc. - Distributor of the Year
Shift and enter to skip a line
Enter for a n
Enter for a n
Additionally, awards for specific regions also identified important contributors:
• In the ANZ (Australia and New Zealand) sector, Dell Technologies was recognized as Partner of the Year, and Baidam Solutions Pty Ltd as Growth Partner of the Year.
• For South East & North Asia, Ensign InfoSecurity (Smarttech) Pte Ltd. was awarded Partner of the Year, with Stark Technology Inc. as Growth Partner of the Year.
• In the ANZ (Australia and New Zealand) sector, Dell Technologies was recognized as Partner of the Year, and Baidam Solutions Pty Ltd as Growth Partner of the Year.
• For South East & North Asia, Ensign InfoSecurity (Smarttech) Pte Ltd. was awarded Partner of the Year, with Stark Technology Inc. as Growth Partner of the Year.
Shift and enter to skip a line
Enter for a n
Enter for a n
Such awards cultivate an environment committed to the progress of cybersecurity methods. For a language service provider like Huri Translations, which focuses on Pacific Island languages and supplies cultural expertise, these honored companies, and similar entities active in the region, are often solid partners for collaboration, for they appreciate the requirement for unambiguous, culturally sensitive communication in their cybersecurity operational activities.
The endeavor to safeguard the Pacific's digital sphere requires persistent watchfulness, adaptation to emerging threats, and an unwavering commitment to cooperation across all tiers: Local, national, regional, and global. Legal systems must keep pace with technological progress and the evolving tactics of malicious entities. Human expertise are and will remain essential for managing these complex systems.
The endeavor to safeguard the Pacific's digital sphere requires persistent watchfulness, adaptation to emerging threats, and an unwavering commitment to cooperation across all tiers: Local, national, regional, and global. Legal systems must keep pace with technological progress and the evolving tactics of malicious entities. Human expertise are and will remain essential for managing these complex systems.
A key to stipulating acceptable online conduct and protecting digital assets is the Information Security Policies (ISPs) at the corporate and institutional levels. The formation of CERTs is a firm ground for national cybersecurity incident response and a gateway for international collaboration. However, the application of new technologies such as LLMs in Cyber Threat Intelligence requires judicious, context-aware assessment to prevent undue dependence on instruments that might possess constraints when applied to the distinctive and intricate information environment of the Pacific. No silver bullets here.
To conclude, Pacific nations, while managing geopolitical dynamics and forming partnerships, persistently assert their autonomy and focus on their developmental priorities. As we witness these trends, we remain committed to overcoming linguistic and cultural barriers. The undertaking is not purely technological but integrates an innate human component that has roots in the Pacific region. The path to a secure digital Pacific is one of joint accountability and collective action, where the heritage of the islands can guide the strategies for a resilient tomorrow.
Huri Translations
Tel. +689 89 205 483
[email protected]
PO BOX 365 Maharepa
98728 Mo'orea
French Polynesia
N°TAHITI 876649