Annex 3: Characteristics of Cyberattack Risks and Matters to Be Considered in the Treatment and Countermeasures that Are Associated with Incident Readiness Characteristics of Cyberattack Risks (i) The presence of attackers, and diverse motives of attack Cyberattacks, unlike natural disasters, are caused by attackers with a motive. The motives of attack are becoming increasingly diverse, including stealing money and/or information, declaration of principles or assertions, and suspension of services through the destruction of systems. Attacks carried out through various means, corresponding with the diverse range of attackers and motives of attack, are conceivable, ranging from attacks planned and carried out by organizations to attacks carried out through internal criminal acts. However, in many cases it is difficult to identify the attacker and motive of attack beforehand. Matters to Be Considered with Regard to Response and Countermeasures [Basic point of view] Recognition of cyberattack risks, and formulation of scenarios leading up to the occurrence of damage [Matters to be considered in the formulation and revision of CP and BCP]  Identify the threat of a cyberattack that could lead to CISs outages in the organization (such as targeted attacks using malware and DDoS attacks) as well as the impact of such an attack. For attacks that have a particularly significant impact on the business, draw up scenarios leading up to the occurrence of damage, and consider the treatment to that scenario.  ▶ Example of scenario leading up to the occurrence of damage Due to devices infected with malware (terminals, USB drives, etc.) brought in by maintenance personnel, malware infects the information systems within the organization, and further via the network, invades critical information systems that are the ultimate target of the attack, leading to manipulation and destruction of the system, and leakage of confidential information. As a result, a serious impact on the continuation of services and businesses is made. Even in cases where there are concerns for the occurrence of a cyberattack, such as in cases that advanced notification of an attack, suspicions of information leakage, or indicative signs of an attack (such as suspicious communications and increase in logs) is detected, consider the possibility for the need to take steps, such as moving to an alert status in preparation for the occurrence of an attack or outage, or carrying out emergency inspections of the countermeasure status. ▶ Examples of situations where there are concerns for the occurrence of a cyberattack Suggestions of a DDoS attack on systems that provide CISs through the Internet, in which money or the suspension of specific business activities is demanded. 35

Select target paragraph3