industrial infrastructure of the state from harmful and undeclared functions in such
equipment and narrow the domestic capacity to counter cyber threats.
Many enterprises, institutions and organizations of all forms of ownership do not provide
cyber protection of electronic information resources at their disposal, which leads to
violations of the rights of users of digital services and discredits the processes of digital
transformation in the state.
The basic landscape of the tools for implementing the outlined cyber threats is
characterized by the growth of a high-tech component and diversity.
The number of cyberattacks aimed at stealing personal and other confidential data of
citizens and organizations using social engineering methods is constantly increasing.
There is a growing risk of phishing attacks, botnets, malware, including extortionate
programs, both from financially motivated cybercrime groups and from hacker groups
controlled by the aggressor country and other countries.
Increasing information in databases and information systems and increasing responsibility
for the leakage of personal data of citizens in leading countries has created a global market
for the development of extortionate programs that require funds to unblock access to
information or not post stolen information on the Internet.
Increasingly, cyberattacks are not directed at governments and organizations. Developers
and vendors of software and hardware are attacked in order to infect popular applications,
make changes to source code, and update processes. In the future, it is used to penetrate a
large number of their customers and cause large-scale damage.
Popular websites, social networks, registries collect a large amount of user identification
and personal data. Leaks of information from databases that belong to them pose a threat
to the use of this data to attack other resources and information systems.
Preconditions and factors that form the outlined threats:
● imperfect legal framework in the field of cybersecurity, as well as its obsolescence in
the field of information protection, slow implementation of European law in
domestic law, insufficient regulation of the digital component of criminal
investigations, as well as low level of legal liability for violations of legislation in this
area;
● the lack of relevant ministries and departments does not have the appropriate
structural units, the necessary staffing and proper control over cybersecurity.
Cybersecurity work is funded on a residual basis with technological errors;
● lack of an independent information security audit system and mechanisms for
disclosing information about vulnerabilities in the context of dynamic digitalization
of all spheres of public administration and life of the country, which requires strict
compliance with relevant standards;