Infrastructure, the Application Security Intelligence, and the Advanced & Intelligent Security Operations. Many Lebanese organizations, both in the public and private sectors, have witnessed and still face, at an alarmingly growing rate, Cyber Attacks that mainly target their websites and putting them out of service. Other types of attacks have resulted in the public disclose and release of some personal records of Lebanese citizens. 1.2 Threats Malicious cyber activities are designed to compromise the confidentiality, the integrity, and the availability of Networks, IT Systems, and Information. Malicious cyber activities have some common characteristics: they have no boundaries; they cannot be easily attributed; and they do not necessarily require huge budgets and/or high technical skills. Moreover, different actors can put in place these threats, knowingly or unknowingly, making the range of malicious cyber activities even more difficult to detect, identify, and manage. The main threats can be classified as follows, based on who launches and how the attack is carried out:  Cyber-dependent crimes, where ICT devices can constitute both the main tool for committing the crime and the main target of the crime itself. The most relevant examples are developing and propagating malware for financial gain; hacking to steal sensitive data; DDoS; ransomware and blackmailing; or damaging, altering, or destroying data. Money is generally the main goal of such threats.  Cyber-enabled crimes, where computers are used to commit traditional crimes. The main activities are Cyber-enabled fraud, data theft, espionage, robberies, extortion, propaganda, or destruction. These Cyber Crimes can emanate from other countries and regions but also from inside the country and generally seek to obtain money or data for use in other malicious actions.  States and State-sponsored threats, where foreign States or entities sponsored by foreign States attempt to penetrate the Cyber Space, a public or a private network, or sensitive files on Cloud networks. The purpose is to gain political, diplomatic, military, technological, commercial, financial, and strategic advantage. In particular, these activities target critical national infrastructures of a country, such as defense, finance, energy, health, utilities, and telecommunications assets. Main activities include developing Cyber Espionage and destruction operations capabilities rather than using off-the-shelf techniques. June 2019 LEBANON NATIONAL CYBER SECURITY STRATEGY 13

Select target paragraph3