CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012
The following authorities of the Republic of Cyprus are to be kept informed of the activities described
herein and are observers at this stage:
Law Office of the Republic of Cyprus
Auditor General
Internal Audit Service
Central Bank of Cyprus.
It is noted that the competent authority of the Republic of Cyprus that has responsibilities relating to
Classified Information (CI) and European Union Classified Information (EU CI) is the National Security
Authority. Even though this document is not aimed exclusively or directly at the protection of Classified
Information, any electronic transmission of such information is essentially implemented through
communications infrastructure of communications service providers.
2.4
Threats in Cyberspace Today
The use of computers and communications systems has nowadays penetrated our lives to a very high
degree, and so our level of dependence on these technologies for much of our daily activity is
increasing. These technologies are used today in many sectors beyond just for communications: they
are used for the production and distribution of energy, the management of water and sewage systems,
financial services, in the armed forces and law enforcement, governmental departments and services,
health services, etc. Even though the benefits stemming from information and communications
technologies (ICT) are huge, new network technologies have introduced a plethora of security issues
that are taken advantage of by malicious actors that target vulnerabilities in infrastructure and network
components, such as computers, routers, switches, etc.
The last few years have seen multiple threats appearing in communications networks, especially with
the explosion in the use of the Internet by citizens. ICT has been used in malicious ways for theft from
bank accounts, access to confidential information, damage to important websites (consequent denial of
access to the public), etc. Examples of information that has been stolen from companies include
confidential contracts, product designs, credit card information, account numbers and other personal
data. Such incidents can induce severe damages to an organisation, given that its reputation and
customer trust can be seriously affected, in addition to any direct (monetary) damages. The probability
of such incidents occurring can however be significantly reduced if appropriate measures are taken by
an organisation or enterprise.
It has been observed, on a global level, that not only is the frequency of attacks in cyberspace
increasing, but also the complexity of such attacks. The public, in most cases, is not aware of the extent
of these attacks, nor of the damages that can be caused by them. A relatively recent phenomenon that
is being observed in cyberspace is that of ‘botnets’ – automated virtual networks involving large
numbers of computers (some have been reported with tens of thousands of ‘members’) that are
controlled by malicious actors. These computers can be found in homes and businesses, and also
12