2
CYBER RISKS
Cyber risks are real and manifold. Even if there are no precise details, only rough estimates
of how great the risks are, how frequently cyber attacks or technical disruptions occur and
how severe the actual damage or damage potential really is, the trend of recent years is
undisputed and clear: incidents where states, companies and individuals have been attacked
and damaged via data networks are increasing in both number and quality.
This is a consequence of the growing integration of information and communication
infrastructure, of the mutual dependencies and the complexity of the supporting processes.
With growing complexity, these systems also become more susceptible to errors and
interference, and the potential attack opportunities increase. It must be kept in mind that
cyber attacks are becoming more professional and dangerous. Aside from known cases, it
has to be assumed that a large number of attacks go unreported or undetected, whereby the
high number of unrecorded cases is also related to the loss of reputation feared by the
companies attacked.
2.1
Methods
Cyber attacks are carried out on computers, networks and data. They are aimed at disrupting
the integrity of the data or the functioning of the infrastructure and restricting or interrupting
their availability. They also seek to compromise the confidentiality or authenticity of
information by means of unauthorised reading, deletion or modification of data, connections
or server services are overloaded, information channels spied upon or surveillance and
processing systems are manipulated in a targeted manner.
Many different tools are used by cyber attackers. Malware can be deployed in a targeted
manner and installed on third-party computers without the user's knowledge in order to
undermine the confidentiality, integrity and authenticity of data. The malfunction of
insufficiently protected and maintained operating systems and applications (e.g. Internet
browser or specialist applications) enables the attackers to take control of the affected
computers. These computers can thus be controlled remotely via the Internet, and systems
can have additional malware installed that is capable of accessing stored data and enabling
the attackers to modify or delete the data, or to transfer it to themselves. Data such as users'
keystrokes can be recorded and transferred to the attackers, or undesired access to unsafe
websites can be initiated. In this way, credit card numbers, e-banking access codes or other
confidential data can be stolen from the user. However, attackers also exploit organisational
weaknesses in company security concepts in order to break into protected systems.
Perpetrators are often able to break into the corresponding systems via data processing
procedures and insecurely designed or poorly maintained systems (e.g. leaving the initial
password).
Manipulated computers are also used by attackers to send coordinated and widely
distributed batch requests to server services. The availability of data is thus disrupted. Such
attacks are referred to as distributed denial of service (DDoS) attacks.
In many cases, classical espionage methods are used in order to compromise the
confidentiality of data (e.g. social engineering, theft or physical intrusion). Users of computer
systems are tricked into providing information on security measures, storage media are
stolen or infrastructure is changed in situ by manipulating the configuration. Sabotage
9/42