38
Cyber Incident Classification in the OSCE Region
Ensuring that relevant stakeholders and constituencies not only
understand the categories and thresholds of a given classification
system, but also report incidents when they are affected is a continuous
challenge. Sometimes this may be due to reputational concerns. It
may also be because the affected entity does not have an effective risk
management model in place and may not have the capacity or resources
to carry out proper assessments of the impact of the incident (on the
service affected, the number of users affected, the area affected and
the impact of the incident on other services or sectors).
Finally, the absence of relevant guidance on category definitions, roles
and responsibilities or what a response within a given category entails,
constitutes a specific challenge to understanding how the system
should be used.
States are overcoming many of the challenges discussed above through
the adoption of targeted regulation (for instance, by requiring critical
infrastructure operators and owners to report cyber incidents and
ransomware payments),; through the provision of more detailed
guidance to stakeholders and constituents, and by regularly testing and
reviewing their classification system, including through regular exercises
and training. Some States are also introducing regulatory requirements
where incident notification and reporting is concerned.