0% found this document useful (0 votes)
119 views

BE NIS2 RA v20240108

This tool conducts a risk assessment to determine the appropriate Cyber Fundamentals Assurance Level for an organization. It provides instructions, criteria used, and applicable versions. The document also includes a change log detailing updates.
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
119 views

BE NIS2 RA v20240108

This tool conducts a risk assessment to determine the appropriate Cyber Fundamentals Assurance Level for an organization. It provides instructions, criteria used, and applicable versions. The document also includes a change log detailing updates.
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
You are on page 1/ 58

CHOOSING THE RIGHT CYBER FUNDAMENT

ORGANIZAT
CyFun-Selec

This tool is developed by the Centre for Cybersecurity Belgium to Date


conduct an easy risk assessment resulting in a well-informed 2023-05-31
selection of the appropriate Cyber Fundamentals Assurance Level in 2023-07-10
the context of NIS2. 2024-01-08
This tool does not impose a specific methodology regarding risk
analysis used by an organisation in its day-to-day management.

User Instructions Criteria used in the model Applicable ve


Sectors identified in NIS2 Version
Version
(*) Conformity Assess
R FUNDAMENTALS ASSURANCE LEVEL FOR YOUR
ORGANIZATION
CyFun-Selection

Change Log
Date Reason for change
2023-05-31 Release for validation
2023-07-10 Initial Release
2024-01-08 Including feedback users

Applicable version of the CyberFundamentels framework


requirements Latest version published on www.cyfun.be
CAS (*) Latest version published on www.cyfun.be
(*) Conformity Assessment Scheme
Version: 2024-01-08

Energy Common skills

Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 High Low

Crime (Ransom attacks) 1 High Low

Hactivism (Subversion, defacement…) 1 Med Low

Disinformation (political influencing) 1 Low Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Low 0 Med 30 Med 30 High 60

0 Low 0 Low 0 High 60 High 60

0 Low 0 Low 0 High 30 Low 0

0 Med 7.5 Low 0 Low 0 Med 7.5

0 Med 0 Low 0 Low 0 Low 0

0 7.5 30 120 127.5


Score CyFun Level
285 ESSENTIAL
Version: 2024-01-08

Transport Common skills

Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 High Low

Crime (Ransom attacks) 1 High Low

Hactivism (Subversion, defacement…) 1 Med Low

Disinformation (political influencing) 1 Low Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Low 0 Med 30 Low 0 High 60

0 Low 0 Low 0 High 60 High 60

0 Low 0 Low 0 High 30 Low 0

0 Med 7.5 Low 0 Low 0 Med 7.5

0 Med 0 Low 0 Low 0 Low 0

0 7.5 30 90 127.5
Score CyFun Level
255 ESSENTIAL
Version: 2024-01-08

Financial market infrastructures Common skills


Banking
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 High Low

Crime (Ransom attacks) 1 High Low

Hactivism (Subversion, defacement…) 1 Med Low

Disinformation (political influencing) 1 Low Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Med 30 Med 30 Low 0 Med 30

0 Low 0 Med 30 High 60 Med 30

0 Low 0 Low 0 High 30 Low 0

0 Med 7.5 Low 0 Low 0 Med 7.5

0 Med 0 Low 0 Low 0 Low 0

0 37.5 60 90 67.5
Score CyFun Level
255 ESSENTIAL
Version: 2024-01-08

Healthcare Common skills

Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 High Low

Crime (Ransom attacks) 1 High Low

Hactivism (Subversion, defacement…) 1 Low Low

Disinformation (political influencing) 1 Med Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Med 30 Med 30 Low 0 Med 30

0 Low 0 Med 30 Med 30 Med 30

0 Low 0 Low 0 High 30 Low 0

0 Low 0 Low 0 Low 0 Low 0

0 Med 7.5 Low 0 Low 0 Low 0

0 37.5 60 60 60
Score CyFun Level
217.5 ESSENTIAL
Version: 2024-01-08

Drinking water Common skills

Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 Med Low

Crime (Ransom attacks) 1 Med Low

Hactivism (Subversion, defacement…) 1 Low Low

Disinformation (political influencing) 1 Low Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Med 30 High 60 Low 0 High 60

0 Low 0 Med 15 Med 15 Med 15

0 Low 0 Low 0 Med 7.5 Low 0

0 Low 0 Low 0 Low 0 Low 0

0 Low 0 Low 0 Low 0 Low 0

0 30 75 22.5 75
Score CyFun Level
202.5 ESSENTIAL
Version: 2024-01-08

Waste water Common skills

Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 Med Low

Crime (Ransom attacks) 1 Med Low

Hactivism (Subversion, defacement…) 1 Low Low

Disinformation (political influencing) 1 Low Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Med 30 High 60 Low 0 High 60

0 Low 0 Med 15 Med 15 Med 15

0 Low 0 Low 0 Med 7.5 Low 0

0 Low 0 Low 0 Low 0 Low 0

0 Low 0 Low 0 Low 0 Low 0

0 30 75 22.5 75
Score CyFun Level
202.5 ESSENTIAL
Version: 2024-01-08

Digital infrastructure Common skills


B2B ICT service management
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 High Low

Crime (Ransom attacks) 1 High Low

Hactivism (Subversion, defacement…) 1 Med Low

Disinformation (political influencing) 1 Low Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Med 30 Med 30 Low 0 High 60

0 Low 0 Low 0 High 60 High 60

0 Low 0 Low 0 High 30 Low 0

0 Med 7.5 Low 0 Low 0 Med 7.5

0 Med 0 Low 0 Low 0 Low 0

0 37.5 30 90 127.5
Score CyFun Level
285 ESSENTIAL
Version: 2024-01-08

Public Administration Common skills

Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 High Low

Crime (Ransom attacks) 1 High Low

Hactivism (Subversion, defacement…) 1 High Low

Disinformation (political influencing) 1 High Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Med 30 Med 30 Med 30 High 60

0 Low 0 Med 30 High 60 High 60

0 Low 0 Low 0 High 30 Low 0

0 Med 15 Low 0 Low 0 Med 15

0 Med 15 Low 0 Low 0 Low 0

0 60 60 120 135
Score CyFun Level
375 ESSENTIAL
Version: 2024-01-08

Space Common skills

Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 High Low

Crime (Ransom attacks) 1 High Low

Hactivism (Subversion, defacement…) 1 Med Low

Disinformation (political influencing) 1 Med Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Low 0 Med 30 Low 0 High 60

0 Low 0 Low 0 High 60 High 60

0 Low 0 Low 0 High 30 Low 0

0 Med 7.5 Low 0 Low 0 Med 7.5

0 Med 7.5 Low 0 Low 0 Low 0

0 15 30 90 127.5
Score CyFun Level
262.5 ESSENTIAL
Version: 2024-01-08

Postal and courier services Common skills

Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 Med Low

Crime (Ransom attacks) 1 High Low

Hactivism (Subversion, defacement…) 1 Low Low

Disinformation (political influencing) 1 Low Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Med 30 Med 30 Med 30 Med 30

0 Low 0 Low 0 Low 0 Med 15

0 Low 0 Low 0 High 30 Low 0

0 Low 0 Low 0 Low 0 Low 0

0 Med 0 Low 0 Low 0 Low 0

0 30 30 60 45
Score CyFun Level
165 IMPORTANT
Version: 2024-01-08

Waste management Common skills

Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 Med Low

Information Theft (espionage, …) 2 Low Low

Crime (Ransom attacks) 1 Med Low

Hactivism (Subversion, defacement…) 1 Med Low

Disinformation (political influencing) 1 Low Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Low 0 Med 15 Low 0 Med 15

0 Med 0 Med 0 Med 0 Med 0

0 Low 0 Low 0 High 15 Low 0

0 Low 0 Low 0 Low 0 Low 0

0 Med 0 Low 0 Low 0 Low 0

0 0 15 15 15
Score CyFun Level
45 BASIC
Version: 2024-01-08

Manufacture, production and Common skills


distribution of chemicals
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 Med Low

Crime (Ransom attacks) 1 High Low

Hactivism (Subversion, defacement…) 1 Med Low

Disinformation (political influencing) 1 Low Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Low 0 Med 30 Low 0 High 60

0 Med 15 Med 15 Med 15 Med 15

0 Low 0 Low 0 High 30 Low 0

0 Low 0 Low 0 Low 0 Low 0

0 Med 0 Low 0 Low 0 Low 0

0 15 45 45 75
Score CyFun Level
180 IMPORTANT
Version: 2024-01-08

Production, processing and Common skills


distribution of food
Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 Low Low

Crime (Ransom attacks) 1 High Low

Hactivism (Subversion, defacement…) 1 Med Low

Disinformation (political influencing) 1 Med Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Low 0 Med 30 Low 0 High 60

0 Low 0 Low 0 Low 0 Med 0

0 Low 0 Low 0 Med 15 Low 0

0 Med 7.5 Low 0 Low 0 Med 7.5

0 Med 7.5 Low 0 Low 0 Low 0

0 15 30 15 67.5
Score CyFun Level
127.5 IMPORTANT
Version: 2024-01-08

Manufacturing Common skills

Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 Med Med

Information Theft (espionage, …) 2 High High

Crime (Ransom attacks) 1 Med Low

Hactivism (Subversion, defacement…) 1 Low Low

Disinformation (political influencing) 1 Low Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

15 Low 0 Low 0 Low 0 Med 15

60 Low 0 Low 0 Med 30 Med 30

0 Low 0 Low 0 High 15 Med 7.5

0 Med 0 Low 0 Low 0 Low 0

0 Low 0 Low 0 Low 0 Low 0

75 0 0 45 52.5
Score CyFun Level
172.5 IMPORTANT
Version: 2024-01-08

Digital providers Common skills

Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 High Low

Information Theft (espionage, …) 2 Med Low

Crime (Ransom attacks) 1 Med Low

Hactivism (Subversion, defacement…) 1 Low Low

Disinformation (political influencing) 1 Med Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Med 30 Med 30 Low 0 Med 30

0 Med 15 Low 0 Med 15 Med 15

0 Low 0 Low 0 High 15 Low 0

0 Low 0 Low 0 Low 0 Low 0

0 Med 7.5 Low 0 Low 0 Med 7.5

0 52.5 30 30 52.5
Score CyFun Level
165 IMPORTANT
Version: 2024-01-08

Research Common skills

Threat Actor
Organization Size (L/M/S = 3/2/1) 3 Competitors
Type
Global or
Cyber Attack Category Targetted Impact Prob

Sabotage/ Disruption (DDOS,…) 2 Med Low

Information Theft (espionage, …) 2 High Med

Crime (Ransom attacks) 1 High Low

Hactivism (Subversion, defacement…) 1 Med Low

Disinformation (political influencing) 1 Low Low

Total Total
Common skills Common skills Common skills Extended Skills Extended Skills

Ideologues Nation State


Competitors Hactivists Terrorist Cyber Criminals actor

Risk Score Prob Risk Score Prob Risk Score Prob Risk Score Prob Risk Score

0 Low 0 Low 0 Low 0 Low 0

30 Low 0 Med 30 Med 30 High 60

0 Low 0 Low 0 High 30 Low 0

0 Med 7.5 Low 0 Low 0 Low 0

0 Low 0 Low 0 Low 0 Med 0

30 7.5 30 60 60
Score CyFun Level
187.5 IMPORTANT
Version:

Low 0

Probability Med 0.5

High 1

Low 0
Impact Med 5
High 10

0 99
CyFun Level 100 199
200 10000

Type of attack Required protection


value
Global 1
Targetted 2

Low
Med
2024-01-08

This type of treat actor is not known to have executed this kind of attack in this secto
Probability LOW indications that this might be the case in the near future.
Risk evaluation: Risk is acceptable as is - The risk can be accepted without further ac

This type of treat actor is known to have executed this kind of attack globally. It is re
this might be the case in this sector in the near future.
Probability MEDIUM
Risk evaluation: Risk is tolerable under control - A follow-up in terms of risk manage
conducted and actions shall be set up in the context of medium- and long-term conti

This type of treat actor is known to have executed this kind of attack in this sector. It
assume that this will reoccur in this sector in the near future.
Probability HIGH
Risk evaluation: Risk is unacceptable - Measures for reducing the risk shall absolutel
term. Otherwise, all or a portion of the activity should be discontinued.

Impactlevels are explained in


https://ccb.belgium.be/sites/default/files/cyberfundamentals/IMPACT%20LEVELS_v2023-07-10

BASIC
IMPORTANT
ESSENTIAL

In global or un-targeted attacks (value 1), attackers indiscriminately target as many devices, ser
possible. They do not care about who the victim is as there will be a number of machines or ser
vulnerabilities.
Targeted attacks refer to a type of threat in which threat actors actively pursue and compromis
infrastructure. Typically these threat actors have a certain level of expertise and have sufficient
their schemes over a long-term period. For this reason, a greater degree of protection is require
(value 2).
d this kind of attack in this sector. There are no
ure.
be accepted without further action.

is kind of attack globally. It is reasonable to accept that


e.
low-up in terms of risk management shall be
of medium- and long-term continuous improvement.

is kind of attack in this sector. It is reasonable to


r future.
reducing the risk shall absolutely be taken in the short-
d be discontinued.

MPACT%20LEVELS_v2023-07-10.pdf

tely target as many devices, services or users as


be a number of machines or services with

actively pursue and compromise a target entity’s


of expertise and have sufficient resources to conduct
r degree of protection is required

PROB
HIGH 1
LOW 0
MED 0.5
IMP
HIGH 10
LOW 0
MED 5
Sector
Annex I: Sectors of high criti
I.1. Energy

I.2 Transport

Banking
I.3
Included in I.4 for the purpose of this application
I.4 Financial Market Infrastructure

I.5. Healthcare

I.6. Drinking Water

I.7. Waste Water

I.8. Digital Infrastructure

ICT-service management (B2B)


I.9.
Included in I.8 for the purpose of this application

I.10. Public Administration entities

I.11. Space
Annex II: other critical sec
II.1. Postal and courier services
II.2. Waste Management
II.3. Manufacture, production and distribution of chemicals
II.4. Production, processing and distribution of food
II.5. Manufacturing
II.6. Digital providers
II.7. Research

Entities providing domain name regis


Subsector
Annex I: Sectors of high criticality
Electricity, district Heating &cooling, Oil, Gas, Hydrogen
Air (commercial carriers; airports; traffic); Rail (infra and undertakings); Water (transport companies; ports; traffic services); Ro
Special case: Public Transport: only if identified as CER

Credit institutions (attention: DORA lex specialis)

Trading venues, central counterparties (attention: DORA lex specialis)


Healthcare providers; EU reference laboratories; R&D of medicinal products; manufacturing basic pharma products and prepa
medical devices critical during public health emergency
Special case: entities holding a distribution authorization for medicinal products: only if identified as CER
Suppliers and distributors of water intended for human consumption, excluding distributors for which distribution of water fo
non- essential part of their general activity of distributing other commodities and goods.

Undertakings collecting, disposing of or treating urban waste water, domestic waste water or industrial waste water, excludin
collecting, disposing of or treating urban waste water, domestic waste water or industrial waste water is a non-essential part o

Qualified trust service providers


DNS service providers (excluding root name servers)
TLD name registries
Providers of public electronic communications networks
Non-qualified trust service providers
Internet Exchange Point providers
Cloud computing service providers
Data centre service providers
Content delivery network providers
Managed Service Providers, Managed Security Service Providers
Of central governments (excluding judiciary, parliaments, central banks; defence, national or public security).
Of regional governments: risk based.
(Optional for Member States: of local governments)
Operators of ground-based infrastructure (by MS)
Annex II: other critical sectors
Postal service providers, including providers of courier services.
Undertakings carrying out waste management, excluding undertakings for whom waste management is not their principal eco
Manufacture, production, distribution
Production, processing and distribution
Manufacture of medical devices and in vitro diagnostic medical devices; computer, electronic and optical products; electrica
equipment; motor vehicles, trailers and semi-trailers; other transport equipment (NACE C 26-30).
Providers of online marketplaces, online search engines and social networking services platforms.
Research organisations (excluding education institutions)
(Optional for Member States: education institutions)
Entities providing domain name registration services

You might also like