 An expanding range of targeted devices The Internet of Things (IoT) and Industrial Internet of Things (IIoT) create new opportunities for exploitation and increase the potential impact of attacks, which can cause both ICT and physical damage, and even death. The rapid implementation of connectivity in Industrial Control Processes in critical systems across a wide range of industries, such as energy, mining, agriculture, and aviation, has created the Industrial Internet of Things. This process allows devices and industrial and non-industrial operations, which were never vulnerable to such interferences in the past, to be hacked and tampered with, leading to potentially disastrous consequences.  Poor Cyber Hygiene and Compliance These two elements depend on and can be addressed through the adequate technical solutions and implementations. However, they also heavily rely on cultural awareness. In fact, without a proper understanding of the importance of the concept of Cyber Hygiene, neither defense solutions nor compliance with existing or upcoming Cyber Security standards would be sufficient. If not enough awareness is raised, maintained, and nourished at the widest national level, across all the public and private institutions of the country, and amongst individual citizens, the country and all its infrastructures will never be safe from threats. The below list of facts and scenarios gives an idea of possible risks and their consequences if the Government, across all its institutions, the public and private institutions, at large, do not take full awareness of the seriousness of the threats:  99% of Exploit-Based Attacks will still not be based on 0-Day Vulnerabilities. This means that, for example, if citizens do not understand the importance of very simple, basic security actions, such as “Windows Update” and if they do not apply them properly and regularly, their computers will always be prone to mass-attacks that will exploit known and public vulnerabilities;  Home Networks in Work-From-Home scenarios will expose Enterprises to BYOD-like Security Risks. The employee working from home must understand the importance of simple best practices, such as changing the default password on his/her home router, rather than always using VPNs in order to remotely connect to his/her office;  Sextortion Cases will rise dramatically;  The skills gap will widen and fewer trained experts will be available to fill security roles. Such lack in human resources will result in improper/poor testing, auditing, and certifying Cyber Security compliances in different environments and under different scenarios. June 2019 LEBANON NATIONAL CYBER SECURITY STRATEGY 17

Select target paragraph3