3 Investigation Unit – Computer Emergency Response Team in Lithuania (CERT-LT) – processed as many as 54, 414 cyber incidents. In 2017, the number of recorded cyber incidents was 10% higher than in 2016. The Lithuanian national information resources remain the primary target of cyber-espionage attacks; nonetheless, critical information infrastructure of the private sector and other enterprises which are of strategic or great importance to the national security is no exception either. Applying technical cyber security measures the NCSC has identified that the biggest number of cases of proliferation of malicious software was in the sectors of energy (27%), public security and legal order (22%) and foreign affairs and security policy (21%). Compared to 2016, malicious software mostly proliferated in the areas of public security and legal order, foreign affairs and security policy, and energy. The situation of cyber security in the country is also strongly affected by the state of websites of public sector which, based on the data of the Report on the State of National Cyber Security 2017, deteriorated in 2017. 8. The annual reports of the NCSC, SSD and SID provide information on the extent of proliferation of cyber incidents which shows that every cyber security subject faces situation where a decision has to be made on how much time, money or any other resources might be needed to protect the existing communication and information systems or provided services. Cyber security subjects perform security risk assessment but risk assessment is often conducted formally only so as to comply with the requirements of legal acts or provision of internationally recognised standards. The Risk Analysis Manual published by the Ministry of the Interior of the Republic of Lithuania reflects the progress and advancement of the risk assessment by research and innovation tools of the time, however, the provisions of the security risk assessment methodology have gradually changed and control environment assurance has transformed into all-encompassing activity risk assessment of an organisation. 9. Individual assessment processes in terms of different security areas in Lithuania have already reached the point of maturity, however, on the national level, the security risk assessment culture and cyber security risk assessment are still fragmentary. There is a lack of analysis on cyber threats and gaps in security as well as full integration into activity risk assessment processes. Furthermore, rapid development of ICT results in the staff responsible for cyber security lacking knowledge, skills and practice. 10. To improve the culture of cyber security policy development and implementation, to update cyber security risk assessment and other requirements, the following significant changes took place in the field of cyber security in 2018: 10.1. Recast provisions of the Law on Cyber Security helped improve the organisation, management and control of the cyber security system, specified competence, functions, rights and duties of authorities which develop and implement cyber security policy, duties and responsibility of cyber security agents, and established additional cyber security assurance measures. 10.2. The functions of regulation and safeguarding the security of state information resources, of the activities of public communications networks, public electronic service

Select target paragraph3