various devices and equipment connected to data networks have made a great impact on daily life, on the economy, and on the functioning of the State. In addition, the Internet is becoming increasingly accessible, the number of users continues to grow, and new technological services and solutions such as Internet of Things (IoT), Industrial Internet of Things (IIoT) and cloud services are on the rise. All the above result in a wider threat landscape and in a growth of attack vectors that have increased complexity, sophistication, and damages when successful. The number of State Actors involved in Cyber Space and engaged in Cyber Espionage activities targeting computers connected to the Internet as well as closed networks continues to grow. This reality is due to the fact that collecting information on national security as well as economic assets represents an important resource in the regional and international arena. The number and activeness of Nations capable to perform State-sponsored Cyber Attacks are increasing, posing unknown and unexpected critical threats and risks to Lebanon. In addition to the activeness of State actors, politically-motivated individuals and groups with limited financial means have a growing ability to organize their activities using social networks and carry out Denial of Service and other types of attacks. Moreover, the recent but fast-growing diffusion and implementation of encryption standards by governmental institutions and private companies – such as the SSL or the SSH protocols, just to mention a couple – revealed an unexpected side effect: They rendered real-time detection, post-incident analysis, defense, and investigation much more complex. Under some specific circumstances and ICT architectures, such as very large and complex data centers, it is becoming nearly impossible to perform real-time detection successfully. Nowadays, such scenarios are allowing different Threat Actors massively to exfiltrate sensitive and critical information using the very same encryption protocols that the victims use to enhance their Cyber Security. Very often this causes previously used detection and data protection solutions, such as DLP (Data Leakage Prevention), to fail in their core scope, usually greatly broadening the so-called “attack window” and resulting in increased and long-lasting data breaches, instead of the previously totally undetected, shorter breaches. The rapid evolution in the profile and capabilities of attackers makes tracing and attributing the attack drastically more complex. 1.4 Challenges The main Cyber Security risks arise from the extensive and growing dependence on ICT infrastructure and e-services by the Lebanese State, economy, and population. June 2019 LEBANON NATIONAL CYBER SECURITY STRATEGY 15

Select target paragraph3