CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012 The following authorities of the Republic of Cyprus are to be kept informed of the activities described herein and are observers at this stage:     Law Office of the Republic of Cyprus Auditor General Internal Audit Service Central Bank of Cyprus. It is noted that the competent authority of the Republic of Cyprus that has responsibilities relating to Classified Information (CI) and European Union Classified Information (EU CI) is the National Security Authority. Even though this document is not aimed exclusively or directly at the protection of Classified Information, any electronic transmission of such information is essentially implemented through communications infrastructure of communications service providers. 2.4 Threats in Cyberspace Today The use of computers and communications systems has nowadays penetrated our lives to a very high degree, and so our level of dependence on these technologies for much of our daily activity is increasing. These technologies are used today in many sectors beyond just for communications: they are used for the production and distribution of energy, the management of water and sewage systems, financial services, in the armed forces and law enforcement, governmental departments and services, health services, etc. Even though the benefits stemming from information and communications technologies (ICT) are huge, new network technologies have introduced a plethora of security issues that are taken advantage of by malicious actors that target vulnerabilities in infrastructure and network components, such as computers, routers, switches, etc. The last few years have seen multiple threats appearing in communications networks, especially with the explosion in the use of the Internet by citizens. ICT has been used in malicious ways for theft from bank accounts, access to confidential information, damage to important websites (consequent denial of access to the public), etc. Examples of information that has been stolen from companies include confidential contracts, product designs, credit card information, account numbers and other personal data. Such incidents can induce severe damages to an organisation, given that its reputation and customer trust can be seriously affected, in addition to any direct (monetary) damages. The probability of such incidents occurring can however be significantly reduced if appropriate measures are taken by an organisation or enterprise. It has been observed, on a global level, that not only is the frequency of attacks in cyberspace increasing, but also the complexity of such attacks. The public, in most cases, is not aware of the extent of these attacks, nor of the damages that can be caused by them. A relatively recent phenomenon that is being observed in cyberspace is that of ‘botnets’ – automated virtual networks involving large numbers of computers (some have been reported with tens of thousands of ‘members’) that are controlled by malicious actors. These computers can be found in homes and businesses, and also 12

Select target paragraph3