Core CSAN: Cyber Attacks Impair Society’s Central Nervous System | CSAN 2021
Core CSAN: Cyber Attacks
Impair Society’s Central
Nervous System
Digital processes are the ‘central nervous system’ of society, as they are indispensable to its
uninterrupted functioning. Cyber attacks impair this central nervous system and this can
ultimately lead to paralysis, as also noted in the Cybersecurity Assessment Netherlands (CSAN)
2020. COVID-19 has accelerated the digitisation of processes, including in healthcare and
education. The digital and the physical world are increasingly interlinked and it is becoming
more and more difficult to distinguish between the two. There are hardly any processes left
without a digital component.
As the digital and the physical world are so interlinked, a
governance approach that addresses the importance of
cybersecurity, the cyber threat and resilience solely from a
technology-based perspective is too narrow. This is also, and
perhaps above all, about how organisations and people use
digitisation, and therefore about the functionality for society and
the economy. A cyber incident affects digital processes and when
these do not work properly, this affects the functioning of
organisations. Chain reactions can affect entire sectors or even
society as a whole. For example, a ransomware attack on a
municipality, university, hospital or electricity distributor renders
systems unusable: the technology no longer works. As a result, the
municipality can no longer perform its duties properly, research
and education come to a halt, patient care is impeded or there may
be a power outage. This means that the cyber threat jeopardises not
only the functioning of technology, but also a range of other
interests. Therefore, resilience-enhancing measures not only
contribute to the security of technology, but also help to protect
our society and economy.
Cybersecurity remains inextricably interlinked with national
security: cybersecurity breaches can lead to social disruption. The
cyber threat keeps evolving as actors continue to develop and the
geopolitical context keeps changing, and is also impacted by
current events such as COVID-19. Resilience also continues to
evolve. Whether there is an adequate balance between the various
interests, the cyber threat and resilience is a question that needs to
be resolved through governance and/or risk management.
In this Cybersecurity Assessment Netherlands, the National
Coordinator for Security and Counterterrorism identifies four risks
to national security:
1. Unauthorised access to information (and possibly its
publication), in particular through espionage. Examples
include espionage targeting communications within the
central government or the development of innovative
technologies.
2. Inaccessibility of processes, due to sabotage and/or the use of
ransomware or preparations for this. Examples include
infiltration in processes that ensure the distribution of
electricity.
3. Breaches of (the security of ) cyberspace, such as through the
abuse of global IT supply chains.
4. Large-scale outages: a situation where one or more processes
are disrupted due to natural or technical causes or
unintentional human action.
7