3
Investigation Unit – Computer Emergency Response Team in Lithuania (CERT-LT) –
processed as many as 54, 414 cyber incidents. In 2017, the number of recorded cyber incidents
was 10% higher than in 2016. The Lithuanian national information resources remain the primary
target of cyber-espionage attacks; nonetheless, critical information infrastructure of the private
sector and other enterprises which are of strategic or great importance to the national security is
no exception either. Applying technical cyber security measures the NCSC has identified that the
biggest number of cases of proliferation of malicious software was in the sectors of energy
(27%), public security and legal order (22%) and foreign affairs and security policy (21%).
Compared to 2016, malicious software mostly proliferated in the areas of public security and
legal order, foreign affairs and security policy, and energy. The situation of cyber security in the
country is also strongly affected by the state of websites of public sector which, based on the data
of the Report on the State of National Cyber Security 2017, deteriorated in 2017.
8. The annual reports of the NCSC, SSD and SID provide information on the extent of
proliferation of cyber incidents which shows that every cyber security subject faces situation
where a decision has to be made on how much time, money or any other resources might be
needed to protect the existing communication and information systems or provided services.
Cyber security subjects perform security risk assessment but risk assessment is often conducted
formally only so as to comply with the requirements of legal acts or provision of internationally
recognised standards.
The Risk Analysis Manual published by the Ministry of the Interior of the Republic of
Lithuania reflects the progress and advancement of the risk assessment by research and
innovation tools of the time, however, the provisions of the security risk assessment
methodology have gradually changed and control environment assurance has transformed into
all-encompassing activity risk assessment of an organisation.
9. Individual assessment processes in terms of different security areas in Lithuania have
already reached the point of maturity, however, on the national level, the security risk assessment
culture and cyber security risk assessment are still fragmentary. There is a lack of analysis on
cyber threats and gaps in security as well as full integration into activity risk assessment
processes. Furthermore, rapid development of ICT results in the staff responsible for cyber
security lacking knowledge, skills and practice.
10. To improve the culture of cyber security policy development and implementation, to
update cyber security risk assessment and other requirements, the following significant changes
took place in the field of cyber security in 2018:
10.1. Recast provisions of the Law on Cyber Security helped improve the organisation,
management and control of the cyber security system, specified competence, functions, rights
and duties of authorities which develop and implement cyber security policy, duties and
responsibility of cyber security agents, and established additional cyber security assurance
measures.
10.2. The functions of regulation and safeguarding the security of state information
resources, of the activities of public communications networks, public electronic service