NATIONAL CYBER SECURITY STRATEGY GREEN PAPER – SUPPORTING DOCUMENT Phishing Technical deception, through spoofed emails and counterfeit Websites as well as social engineering significantly contribute to phishing. Social networking sites as well as the proliferation of new technologies having vulnerabilities and weak security controls are also likely to enable phishing, leading to information theft or leakage. End-user behaviour and awareness may help in defending against phishing. Exploit kits They are increasingly complex and sophsticated automated tools applied by a number of threat agents that mainly detect vulnerabilities at user end-devices so as to download and manage malicious content. It is noted that organisations deploying vulnerability management, based upon mature and formal methods, are less likely to be infected from exploit kits. Data breaches It is a result of successful cyber-attacks or erroneous unintentional user activities, all leading to disclosure of confidential information. Due to their impact and their long term consequences, data breaches are among the most thoroughly managed and investigated cyber incidents. Security preparedness for new technologies, such as for mobile and cloud computing, is still in its early maturity phases, with challenges arising with respect to data ownership in off-premises environments. However it also needs to be kept in view that over 50% of data breaches are attributed to a lax regard to security controls and procedures by end-users. Physical damage, theft and loss Various cyber-security incidents, mainly data breaches and identity theft, may be a result of such a threat. Theft and loss of end user ICT devices rank high in related statistics. Insider threat Top most information types that have been breached by organisation insiders are intellectual property, customer data and financial records, whilst the top five activities of insider misuse assessed include privilege abuse, non-approved hardware, bribery and email misuse and data mishandling. Such an attack is possible due to the inherent ability to bypass existing security controls through available access rights, insider knowledge of existing protection and the awareness of an 13 Malta | National Cyber Security Strategy Green Paper – Supporting Document

Select target paragraph3