2 CYBER RISKS Cyber risks are real and manifold. Even if there are no precise details, only rough estimates of how great the risks are, how frequently cyber attacks or technical disruptions occur and how severe the actual damage or damage potential really is, the trend of recent years is undisputed and clear: incidents where states, companies and individuals have been attacked and damaged via data networks are increasing in both number and quality. This is a consequence of the growing integration of information and communication infrastructure, of the mutual dependencies and the complexity of the supporting processes. With growing complexity, these systems also become more susceptible to errors and interference, and the potential attack opportunities increase. It must be kept in mind that cyber attacks are becoming more professional and dangerous. Aside from known cases, it has to be assumed that a large number of attacks go unreported or undetected, whereby the high number of unrecorded cases is also related to the loss of reputation feared by the companies attacked. 2.1 Methods Cyber attacks are carried out on computers, networks and data. They are aimed at disrupting the integrity of the data or the functioning of the infrastructure and restricting or interrupting their availability. They also seek to compromise the confidentiality or authenticity of information by means of unauthorised reading, deletion or modification of data, connections or server services are overloaded, information channels spied upon or surveillance and processing systems are manipulated in a targeted manner. Many different tools are used by cyber attackers. Malware can be deployed in a targeted manner and installed on third-party computers without the user's knowledge in order to undermine the confidentiality, integrity and authenticity of data. The malfunction of insufficiently protected and maintained operating systems and applications (e.g. Internet browser or specialist applications) enables the attackers to take control of the affected computers. These computers can thus be controlled remotely via the Internet, and systems can have additional malware installed that is capable of accessing stored data and enabling the attackers to modify or delete the data, or to transfer it to themselves. Data such as users' keystrokes can be recorded and transferred to the attackers, or undesired access to unsafe websites can be initiated. In this way, credit card numbers, e-banking access codes or other confidential data can be stolen from the user. However, attackers also exploit organisational weaknesses in company security concepts in order to break into protected systems. Perpetrators are often able to break into the corresponding systems via data processing procedures and insecurely designed or poorly maintained systems (e.g. leaving the initial password). Manipulated computers are also used by attackers to send coordinated and widely distributed batch requests to server services. The availability of data is thus disrupted. Such attacks are referred to as distributed denial of service (DDoS) attacks. In many cases, classical espionage methods are used in order to compromise the confidentiality of data (e.g. social engineering, theft or physical intrusion). Users of computer systems are tricked into providing information on security measures, storage media are stolen or infrastructure is changed in situ by manipulating the configuration. Sabotage 9/42

Select target paragraph3