NATIONAL CYBER SECURITY STRATEGY GREEN PAPER – SUPPORTING DOCUMENT organisation’s weaknesses and vulnerabilities. It could also be due to user error; potentially resulting from user negligence 2 or lack of employee security training3. Information leakage It relates to a set of threats that emerge due to unintentional or maliciously triggered exposure of sensitive data, mainly through technical or organisational weaknesses to an unauthorised party. Software application vulnerabilities resulting in areas such as their coding or implementation are also cited as sources for informatin leakage. Social media is also reported as a major channel for information leakage that can be used in other attacks. Proper security controls are also necessary to ensure protection of data in transit or at rest on mobile and cloud computing technology. Identity theft, fraud and cyber espionage Identity theft is a cyber threat that aims at collecting personal identifying information (PII) which includes credentials, personal profiling, details of financial identification/authentication methods, credit card information, various access codes, technical identification data, etc. An increase in identity theft/fraud incidents has led to consumer mistrust in using digital means to perform financial transactions.Increased interoperability within the consumer market may increase the likelihood of such threat, particularly if one vulnerable application falls victim to it.Emerging yet security immature technologies, as well as older technologies having poor security controls are envisaged as likely targets for identity theft. Sophisticated methods are increasingly being used to target both large organisations as well as small to medium sized enterprises. Ransomware, rogueware and scareware Although this threat belongs to the family of malware, it may still be considered on its own merits, due to recently introduced features which enable it to infiltrate mobile devices. 14 Malta | National Cyber Security Strategy Green Paper – Supporting Document

Select target paragraph3