An expanding range of targeted devices
The Internet of Things (IoT) and Industrial Internet of Things (IIoT) create new
opportunities for exploitation and increase the potential impact of attacks, which
can cause both ICT and physical damage, and even death. The rapid
implementation of connectivity in Industrial Control Processes in critical systems
across a wide range of industries, such as energy, mining, agriculture, and aviation,
has created the Industrial Internet of Things. This process allows devices and
industrial and non-industrial operations, which were never vulnerable to such
interferences in the past, to be hacked and tampered with, leading to potentially
disastrous consequences.
Poor Cyber Hygiene and Compliance
These two elements depend on and can be addressed through the adequate
technical solutions and implementations. However, they also heavily rely on
cultural awareness. In fact, without a proper understanding of the importance of
the concept of Cyber Hygiene, neither defense solutions nor compliance with
existing or upcoming Cyber Security standards would be sufficient.
If not enough awareness is raised, maintained, and nourished at the widest
national level, across all the public and private institutions of the country, and
amongst individual citizens, the country and all its infrastructures will never be
safe from threats. The below list of facts and scenarios gives an idea of possible
risks and their consequences if the Government, across all its institutions, the
public and private institutions, at large, do not take full awareness of the
seriousness of the threats:
99% of Exploit-Based Attacks will still not be based on 0-Day
Vulnerabilities. This means that, for example, if citizens do not understand
the importance of very simple, basic security actions, such as “Windows
Update” and if they do not apply them properly and regularly, their
computers will always be prone to mass-attacks that will exploit known and
public vulnerabilities;
Home Networks in Work-From-Home scenarios will expose Enterprises
to BYOD-like Security Risks. The employee working from home must
understand the importance of simple best practices, such as changing the
default password on his/her home router, rather than always using VPNs
in order to remotely connect to his/her office;
Sextortion Cases will rise dramatically;
The skills gap will widen and fewer trained experts will be available to fill
security roles. Such lack in human resources will result in improper/poor
testing, auditing, and certifying Cyber Security compliances in different
environments and under different scenarios.
June 2019
LEBANON NATIONAL CYBER SECURITY STRATEGY
17