The Nature and the Evolving Trends of the Cyber Threat and of the Vulnerabilities of the National ICT Infrastructures organizations. As such, they are in a unique position to mount a robust cyber operational capability. Protecting the military command and control networks and ensuring their full operational capability and their resilience has always been a top priority for any State. The advent of cyberspace, and its key role in ensuring the functioning of virtually every national sensitive infrastructure, industrial process and public services, has extended the mandate of the State to the protection of all ICT critical networks. In fact, the most sophisticated cyber attacks may not only impair and paralyze the State’s most vital communication nodes and the provision of essential public services, but may also have potentially destructive effects if directed against critical infrastructures such as, for instance, the aviation traffic management control system or dams and energy installation’s supervisory control and management systems, resulting in great physical damages and the eventual loss of human life. The strategic advantage implicit in the possibility of inflicting a great loss to the enemy’s critical infrastructures by striking at great distance makes it very likely that future military confrontation will entail the full use of cyberspace. It is therefore no surprise that nowadays virtually every nation considers it relevant in its force planning to foresee the requirements of a cyber defence capability that is adequate to protect national critical ICT infrastructures. Espionage, sabotage, warfare and supply chain cyber threat The defence of cyber networks requires the development of an effective and uninterrupted capability of monitoring and analyzing all ongoing malicious activities. States are striving to ensure themselves with this expertise, either directly or through proxies, and considering in many cases also the potential advantages of developing aggressive tools. It is a well-know fact that some States already possess the capability to penetrate public and private networks of other States, and use this capability for espionage and in order to map ICT systems that could be potential targets in case of future attacks. In such a situation, is also highly plausible that certain States may consider mobilizing their national industry to install through the ICT supply chain components that could allow for future stealthy cyber exploitation of the end-user computer systems and ICT infrastructure. Hacktivism Some cyber attacks are ideologically motivated and have primarily a demonstrative intent, like damaging the image of the target and/or causing a temporary malfunctioning of the attacked ICT systems. Examples of this type of cyber attack are the Distributed Denial of Service (DDoS) attacks, that, through coordinated attacks originating from a number of unaware and remotely controlled computer (botnets), cause the intentional overload of servers that host 15

Select target paragraph3