2022-10-27
With the end of the European Cybersecurity Month, the National Audit Office calls for improvement of the cybersecurity assurance system
According to the National Cybersecurity Centre, 11 659 cyber incidents were registered between 2019 and 2021. Due to the high number of these incidents, their modernisation and the potential risks of significant effects of cyber-attacks and incidents, it is increasingly important to ensure cybersecurity at the national level, to protect critical information infrastructure and the state‘s electronic information resources. To assess whether cybersecurity is ensured in Lithuania, the National Audit Office carried out an audit “Ensuring Cybersecurity” and recommended that the system of ensuring cybersecurity be improved.
“The growing threat from cyber and hybrid attacks requires critical information infrastructure and electronic information to be protected with great responsibility. Lithuania ranks sixth among the world’s countries according to the 2021 United Nations International Telecommunication Union Cybersecurity Index. The result is relatively optimistic, however, the findings of our audit show that we can and must improve the country’s cybersecurity assurance system", said Markas Marcinkevičius, Head of the Information Technology Audit Department.
The auditors stress that cybersecurity risks should be monitored and analysed in a more integrated way at the national level, compliance assessment and monitoring of security requirements should be digitalised, and the legal requirements for cybersecurity and electronic information safety should be consistent.
Cybersecurity exercises, training and advice contribute to building cyber resilience but are not yet sufficient to strengthen institutions’ capacity to manage cyber incidents. For example, in the last three years, around a third of cyber security entities have never participated in cybersecurity exercises, half of them have not been trained in cybersecurity, and one in four cyber security entities do not have a cyber incident management plan. Cybersecurity entities do not ascertain the actual state of the information security management system they manage: in the period 2019-2021, almost half (45 %) of the managers/processors of state information resources never carried out an information technology (IT) safety conformity assessment and more than a third (38 %) of them did not carry out a cybersecurity risk assessment.
The National Audit Office has submitted recommendations to the Ministry of National Defence, responsible for organising and coordinating the implementation of cybersecurity policy, that, if implemented at the national level, would allow for more effective management of IT security risks, and provide conditions to carry out digital cybersecurity and IT safety compliance assessment and monitoring. For example, the establishment and annual update of the national cybersecurity risk profile would not only identify risks but also periodically assess their potential impacts, and provide risk management measures to ensure resilience against cyber threats. The implementation of other recommendations of the National Audit Office would ensure smoother communication on cyber incidents, strengthen the competencies of cyber security entities, and adopt a typical detailed plan for the management of these incidents.