The most prominent crises last year and early this year – the second year of Covid-19 pandemic, the Belarusian hybrid attack against Lithuania, the Russian aggression against Ukraine – had a significant influence on the cybersecurity situation in Lithuania as well.
While the pandemic and the number of cyber-incidents linked to it which is still high has impelled us to focus more closely on strengthening cybersecurity maturity and training in the country, the war against Ukraine and intensification of corresponding cybersecurity risks has forced us to urgently take additional measures for strengthening the security of the state and critical infrastructure,
Minister of National Defence Arvydas Anušauskas
In the wake of the war in Ukraine, Lithuania put in place preventive measures for strengthening protection of the state and critical infrastructure against cyber threats, surveyed business continuity plans of the public sector, held an exercise to test the Secure Data Transfer Network and the ability of public institutions to function in the event of internet connection disruption across the country.
Pertaining to the fact that not every cybersecurity entities in the country are conscious yet about the benefit and effect of a timely and smooth implementation of cybersecurity requirement, the National Cyber Security Centre (NKSC) under the Ministry of National Defence fortified the means of influence in its mandate by additional legislation. That means entities are not only undergoing scheduled inspections but are also obliged to present draft internal security documents for confirmation, there entities have already been awarded administrative penalty notices to date.
Statistics on cyber-incidents and crimes
The number of cyber-incidents in 2021 kept at a similar level as in 2020 when the COVID-19 pandemic was gathering pace. Even if the NKSC recorded 5% fewer cyber-incidents last year as compared to 2020, the number of complex, targeted and destructive cyber-incidents significantly increased.
The trends in 2022 fail to show any decrease in cyber-incidents. 1020 cases have been recorded in the first quarter of 2022. It is more than in the same quarter a year ago, specifically, 981. During the eighth week of 2022, when Russia began the war in Ukraine, the number of cyber-attack cases surged by one third. Such a surge is explained by the grown cybersecurity concern and measures of companies and persons, which later, however, decreased again. Public and critical infrastructure managers have to maintain the alert level and readiness to ensure business continuity in case of various contingency scenarios.
The growth in recorded cybercrime was seen in 2021 too. The Lithuanian Police registered 51.7% more offences in electronic data and IS than the year before, while Lithuanian people and companies lost twice as much money, EUR 10.2 million, to financial scams than in 2020.
Activity by hostile states in cyberspace
In terms of national security, China and Russia were considered to be threats to Lithuania’s national security in 2021. Russia’s cyber espionage groups have been seen in Lithuania’s information networks most often, though China increases the scope of cyber espionage consistently as well.
Tensions were exceptionally high in information environment in 2021 too. The Strategic Communication Department of the Lithuanian Armed Forces recorded the 47% growth of hostile information activities against Lithuania.
Assistance to Ukraine
Resource limitations and universal cyber-security challenges highlight the need for more international cooperation. The Regional Cyber Defence Centre (a branch of NKSC), operational since last summer, responded to this need by initiating a Securing Cyber Space of Ukraine Together project in February 2022. Regional Cyber Defence Centre partners the United States, Georgia and Ukraine were successfully joined by Poland in its implementation. Another step in support to Ukraine was activation of the EU Cyber Rapid Response Teams for the first time, in February 2022.