NATIONAL CYBER SECURITY STRATEGY GREEN PAPER – SUPPORTING DOCUMENT
5.3 CYBER THREATS MAY ALSO ARISE FROM BUSINESS PARTNERS
The need for organisations to take heed of insider threats through their employees is critical.
However consideration also needs to be taken of business partners. It is reported that financial
institutions are increasingly concerned about their ability to combat threats that can arise from
sharing networks and data with business partners, with 41% of respondents stating that they detected
incidents perpetrated by third parties with trusted access. A number of organisations within
healthcare and the utilities industry also admit to forging strategic business relationships without
consideration to robust due diligence, regulatory policies or deployment of monitoring and detection
controls, on third parties with whom they share sensitive information8.
5.4 NO INDUSTRY CAN DO WITHOUT A ROBUST CYBER SECURITY PROGRAM
The public sector is reported to be the primary target of cyber attacks, accounting over 75% of more
than 63,400 incidents reported worldwide during 20149. However, one cannot discount the
vulnerability of any other organisation – public sector or otherwise – from any cyber attack.
The Healthcare industry payers and providers report that information security incidents increased by
60% in 2014, and that costs attributed to such incidents increased to 282%10. For example, identity
theft and fraud is particularly noted within the healthcare industry, with an estimate of around two
million US citzens envisaged to spend over $12 billion as a result of such an incident alone. Cyber
attacks against power and utilities organisations have also transitioned from speculative to
indisputable 11. Article 2.3 of the European Commission’s European Energy Security Strategy, in
particular, states that: “The EU has started to develop a policy to address the physical protection of
critical infrastructure (against threats, hazards) which includes energy infrastructure. Increasing
attention should be given to IT security”12 . Within the Finance sector, its regulators are increasingly
expecting the effective implementation of robust security programs from its operators.
Ultimately, the crux of it all is not simply having a cyber security program, but that its implementation
does not lag behind. ENISA specifically reports in 2014, that falling behind in cyber security continues
to be the number one reason for security incidents such as data breaches.
5.5 A RISK-BASED GOVERNANCE MODEL TO CYBER SECURITY IS NEEDED
As highlighted earlier, the uses of technologies - and in particular, emerging ones - present
opportunities and pose risks too. Hence the need for thorough risk assessments, prior to their
deployment is necessary. Possibly with the aid of widely accepted frameworks, consideration needs to
be given to closely link technologies, processes and personnel skills with enterprise risk management
22
Malta | National Cyber Security Strategy Green Paper – Supporting Document