Figure 2 – Common Cyber Threat Sources
2.4.1.4
Threat Actor
A threat actor is an entity that actually performs the attack or, in the case of accidents,
will exploit the accident. For example, if an organised crime group corrupts an employee,
then the group is the Threat Source and the employee is the Threat Actor.
2.4.1.5
Vulnerability
The intentions of threat sources and threat actors often materialise into attacks largely
because they exploit weaknesses in the security controls. The weakness may include
lack of software patching and poor configuration. Even sound technical controls may fail
if social engineering attacks dupe staff with weak knowledge into breaching security.
2.4.2
SECURITY RISK
Whenever you see phrases security risk or cyber risk, know that we mean the probability
that a threat will exploit a vulnerability to breach the security of an asset. It is important
for States to manage cyber risks. However, as most readers know, functional IT systems
operate with a degree of exposure to threats because full elimination of risk is either too
expensive or undesirable. As such, a national cybersecurity strategy is the first step in
ensuring that all stakeholders assume responsibility for and take steps to reduce risk.
2.4.3
CYBER ATTACKS
A cyber attack occurs when a threat breaches security controls around a physical or an
information asset. We categorise cyber attacks by state and origin as follows:
16