Insufficient training and skills
The gap in Cyber skills is a national vulnerability that needs to be resolved. There
is a lack in the following:
Skills and knowledge to meet Cyber Security across both the public and
private sectors;
Awareness building and formal training in Cyber Security for all public
employees, who deal, in any form, with IT systems;
Hands-on training and simulations on the actual implementation of Cyber
Security defense measures and techniques.
Legacy and unpatched systems
Using vulnerable legacy systems with no updated versions means having
unpatched systems that make entire networks vulnerable to attacks leading
to massive data breaches, allowing the attackers to steal thousands, if not
millions, of personal and business data;
Using unsupported software for which updates and patching no longer
exist leads to an increased level of vulnerability that might be used by
attackers to succeed in their criminal operations.
Availability of hacking resources
Widely available free hacking information and hacking tools on the
Internet give hackers access to knowledge and know-how that can be used
for criminal purposes. This is something that cannot be combated, since
the Internet itself is intrinsically designed for sharing information of any
kind, both legal and not.
The availability of such information and hacking resources cannot be
considered a crime (thus not allowing the blacklisting of such data),
because most of the time, such know-how, tools, and how-to guides are (or
claim to be) meant to foster knowledge about Cyber Security and security
testing, even though in some cases they may be used as attacking knowhow.
The only solution to countering all the above Cyber
Threats and Cyber Attacks is the creation of a
nation-wide system that can orchestrate a
coordinated response, within a unified legal and
technical framework.
June 2019
LEBANON NATIONAL CYBER SECURITY STRATEGY
18