BE NIS2 RA v20240108
BE NIS2 RA v20240108
ORGANIZAT
CyFun-Selec
Change Log
Date Reason for change
2023-05-31 Release for validation
2023-07-10 Initial Release
2024-01-08 Including feedback users
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 7.5 30 90 127.5
Score CyFun Level
255 ESSENTIAL
Version: 2024-01-08
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 37.5 60 90 67.5
Score CyFun Level
255 ESSENTIAL
Version: 2024-01-08
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 37.5 60 60 60
Score CyFun Level
217.5 ESSENTIAL
Version: 2024-01-08
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 30 75 22.5 75
Score CyFun Level
202.5 ESSENTIAL
Version: 2024-01-08
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 30 75 22.5 75
Score CyFun Level
202.5 ESSENTIAL
Version: 2024-01-08
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 37.5 30 90 127.5
Score CyFun Level
285 ESSENTIAL
Version: 2024-01-08
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 60 60 120 135
Score CyFun Level
375 ESSENTIAL
Version: 2024-01-08
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 15 30 90 127.5
Score CyFun Level
262.5 ESSENTIAL
Version: 2024-01-08
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 30 30 60 45
Score CyFun Level
165 IMPORTANT
Version: 2024-01-08
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 0 15 15 15
Score CyFun Level
45 BASIC
Version: 2024-01-08
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 15 45 45 75
Score CyFun Level
180 IMPORTANT
Version: 2024-01-08
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 15 30 15 67.5
Score CyFun Level
127.5 IMPORTANT
Version: 2024-01-08
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
75 0 0 45 52.5
Score CyFun Level
172.5 IMPORTANT
Version: 2024-01-08
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
0 52.5 30 30 52.5
Score CyFun Level
165 IMPORTANT
Version: 2024-01-08
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob
Total Total
Common skills Common skills Common skills Extended Skills Extended Skills
Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score
30 7.5 30 60 60
Score CyFun Level
187.5 IMPORTANT
Version:
Low 0
High 1
Low 0
Impact Med 5
High 10
0 99
CyFun Level 100 199
200 10000
Low
Med
2024-01-08
This type of treat actor is not known to have executed this kind of attack in this secto
Probability LOW indications that this might be the case in the near future.
Risk evaluation: Risk is acceptable as is - The risk can be accepted without further ac
This type of treat actor is known to have executed this kind of attack globally. It is re
this might be the case in this sector in the near future.
Probability MEDIUM
Risk evaluation: Risk is tolerable under control - A follow-up in terms of risk manage
conducted and actions shall be set up in the context of medium- and long-term conti
This type of treat actor is known to have executed this kind of attack in this sector. It
assume that this will reoccur in this sector in the near future.
Probability HIGH
Risk evaluation: Risk is unacceptable - Measures for reducing the risk shall absolutel
term. Otherwise, all or a portion of the activity should be discontinued.
BASIC
IMPORTANT
ESSENTIAL
In global or un-targeted attacks (value 1), attackers indiscriminately target as many devices, ser
possible. They do not care about who the victim is as there will be a number of machines or ser
vulnerabilities.
Targeted attacks refer to a type of threat in which threat actors actively pursue and compromis
infrastructure. Typically these threat actors have a certain level of expertise and have sufficient
their schemes over a long-term period. For this reason, a greater degree of protection is require
(value 2).
d this kind of attack in this sector. There are no
ure.
be accepted without further action.
MPACT%20LEVELS_v2023-07-10.pdf
PROB
HIGH 1
LOW 0
MED 0.5
IMP
HIGH 10
LOW 0
MED 5
Sector
Annex I: Sectors of high criti
I.1. Energy
I.2 Transport
Banking
I.3
Included in I.4 for the purpose of this application
I.4 Financial Market Infrastructure
I.5. Healthcare
I.11. Space
Annex II: other critical sec
II.1. Postal and courier services
II.2. Waste Management
II.3. Manufacture, production and distribution of chemicals
II.4. Production, processing and distribution of food
II.5. Manufacturing
II.6. Digital providers
II.7. Research
Undertakings collecting, disposing of or treating urban waste water, domestic waste water or industrial waste water, excludin
collecting, disposing of or treating urban waste water, domestic waste water or industrial waste water is a non-essential part o