Core CSAN: Cyber Attacks Impair Society’s Central Nervous System | CSAN 2021 Core CSAN: Cyber Attacks Impair Society’s Central Nervous System Digital processes are the ‘central nervous system’ of society, as they are indispensable to its uninterrupted functioning. Cyber attacks impair this central nervous system and this can ultimately lead to paralysis, as also noted in the Cybersecurity Assessment Netherlands (CSAN) 2020. COVID-19 has accelerated the digitisation of processes, including in healthcare and education. The digital and the physical world are increasingly interlinked and it is becoming more and more difficult to distinguish between the two. There are hardly any processes left without a digital component. As the digital and the physical world are so interlinked, a governance approach that addresses the importance of cybersecurity, the cyber threat and resilience solely from a technology-based perspective is too narrow. This is also, and perhaps above all, about how organisations and people use digitisation, and therefore about the functionality for society and the economy. A cyber incident affects digital processes and when these do not work properly, this affects the functioning of organisations. Chain reactions can affect entire sectors or even society as a whole. For example, a ransomware attack on a municipality, university, hospital or electricity distributor renders systems unusable: the technology no longer works. As a result, the municipality can no longer perform its duties properly, research and education come to a halt, patient care is impeded or there may be a power outage. This means that the cyber threat jeopardises not only the functioning of technology, but also a range of other interests. Therefore, resilience-enhancing measures not only contribute to the security of technology, but also help to protect our society and economy. Cybersecurity remains inextricably interlinked with national security: cybersecurity breaches can lead to social disruption. The cyber threat keeps evolving as actors continue to develop and the geopolitical context keeps changing, and is also impacted by current events such as COVID-19. Resilience also continues to evolve. Whether there is an adequate balance between the various interests, the cyber threat and resilience is a question that needs to be resolved through governance and/or risk management. In this Cybersecurity Assessment Netherlands, the National Coordinator for Security and Counterterrorism identifies four risks to national security: 1. Unauthorised access to information (and possibly its publication), in particular through espionage. Examples include espionage targeting communications within the central government or the development of innovative technologies. 2. Inaccessibility of processes, due to sabotage and/or the use of ransomware or preparations for this. Examples include infiltration in processes that ensure the distribution of electricity. 3. Breaches of (the security of ) cyberspace, such as through the abuse of global IT supply chains. 4. Large-scale outages: a situation where one or more processes are disrupted due to natural or technical causes or unintentional human action. 7

Select target paragraph3