NATIONAL CYBER SECURITY STRATEGY GREEN PAPER – SUPPORTING DOCUMENT
organisation’s weaknesses and vulnerabilities. It could also be due to user error; potentially resulting
from user negligence 2 or lack of employee security training3.
Information leakage
It relates to a set of threats that emerge due to unintentional or maliciously triggered exposure of
sensitive data, mainly through technical or organisational weaknesses to an unauthorised party.
Software application vulnerabilities resulting in areas such as their coding or implementation are also
cited as sources for informatin leakage. Social media is also reported as a major channel for
information leakage that can be used in other attacks. Proper security controls are also necessary to
ensure protection of data in transit or at rest on mobile and cloud computing technology.
Identity theft, fraud and cyber espionage
Identity theft is a cyber threat that aims at collecting personal identifying information (PII) which
includes credentials, personal profiling, details of financial identification/authentication methods,
credit card information, various access codes, technical identification data, etc. An increase in
identity theft/fraud incidents has led to consumer mistrust in using digital means to perform financial
transactions.Increased interoperability within the consumer market may increase the likelihood of
such threat, particularly if one vulnerable application falls victim to it.Emerging yet security immature technologies, as well as older technologies having poor security controls are envisaged as
likely targets for identity theft. Sophisticated methods are increasingly being used to target both
large organisations as well as small to medium sized enterprises.
Ransomware, rogueware and scareware
Although this threat belongs to the family of malware, it may still be considered on its own merits, due
to recently introduced features which enable it to infiltrate mobile devices.
14
Malta | National Cyber Security Strategy Green Paper – Supporting Document