Figure 2 – Common Cyber Threat Sources 2.4.1.4 Threat Actor A threat actor is an entity that actually performs the attack or, in the case of accidents, will exploit the accident. For example, if an organised crime group corrupts an employee, then the group is the Threat Source and the employee is the Threat Actor. 2.4.1.5 Vulnerability The intentions of threat sources and threat actors often materialise into attacks largely because they exploit weaknesses in the security controls. The weakness may include lack of software patching and poor configuration. Even sound technical controls may fail if social engineering attacks dupe staff with weak knowledge into breaching security. 2.4.2 SECURITY RISK Whenever you see phrases security risk or cyber risk, know that we mean the probability that a threat will exploit a vulnerability to breach the security of an asset. It is important for States to manage cyber risks. However, as most readers know, functional IT systems operate with a degree of exposure to threats because full elimination of risk is either too expensive or undesirable. As such, a national cybersecurity strategy is the first step in ensuring that all stakeholders assume responsibility for and take steps to reduce risk. 2.4.3 CYBER ATTACKS A cyber attack occurs when a threat breaches security controls around a physical or an information asset. We categorise cyber attacks by state and origin as follows: 16

Select target paragraph3