Cyber security initiatives in European Union and Greece The role of the Regulators



Similar documents
ENISA What s On? ENISA as facilitator for enhanced Network and Information Security in Europe. CENTR General Assembly, Brussels October 4, 2012

Thresholds for annual reporting

EU Priorities in Cybersecurity. Steve Purser Head of Core Operations Department June 2013

Cybersecurity Strategy of the Republic of Cyprus

Hacks, apps and espionage - how protected are you against cyber crime? Top 10 Legal Need-to-Knows

Prof. Udo Helmbrecht

EU Cybersecurity Strategy and Proposal for Directive on network and information security (NIS) {JOIN(2013) 1 final} {COM(2013) 48 final}

Cloud and Critical Information Infrastructures

Towards defining priorities for cybersecurity research in Horizon 2020's work programme Contributions from the Working Group on Secure ICT

Enhancing Cyber Security in Europe Dr. Cédric LÉVY-BENCHETON NIS Expert Cyber Security Summit 2015 Milan 16 April 2015

How To Understand And Understand The European Priorities In Information Security

Annual Incident Reports 2011

How To Write An Article On The European Cyberspace Policy And Security Strategy

Cyber Security : preventing and mitigating incidents. Alexander Brown Robert Allen

Achieving Global Cyber Security Through Collaboration

Annual Incident Reports 2013

Cooperation in Securing National Critical Infrastructure

EU Directive on Network and Information Security SWD(2013) 31 & SWD(2013) 32. A call for views and evidence

National Cyber Security Strategy

Network and Information Security Legislation in the EU

Cyber Security in EU: ENISA approach

CYSPA - EC projects supporting NIS

Cyber Security in EU: ENISA approach

Cyberspace Situational Awarness in National Security System

Cybersecurity and the Romanian business environment in the regional and European context

The EU approach to Cybersecurity and Cybercrime

Regulatory Framework for Communications Security and Privacy in Greece

Council of the European Union Brussels, 5 March 2015 (OR. en)

Data breach notifications in the EU

By: Gerald Gagne. Community Bank Auditors Group Cybersecurity What you need to do now. June 9, 2015

UK Networks & Security An Overview. Dr Andrew Powell, ENISA Workshops on CERTs in Europe, 29 May 2008

Information Security Risks when going cloud. How to deal with data security: an EU perspective.

aecert Roadmap Eng. Mohammed Gheyath Director, Technical Affairs TRA

Annual Incident Reports 2012

Cyber Security in Europe

Data Breach Notification Duty. Dr. Elisabeth Thole 31 October 2015 UIA Valencia

Ofcom guidance on security requirements in sections 105A to D of the Communications Act 2003

Internet Governance and Cybersecurity Patrick Curry MACCSA

The European Response to the rising Cyber Threat

Cyber security in an organization-transcending way

Network security policy issues. Ilias Chantzos, Director EMEA & APJ NIS Summer School 2008, Crete, Greece

Follow the trainer s instructions and explanations to complete the planned tasks.

Supporting CSIRTs in the EU Marco Thorbruegge Head of Unit Operational Security European Union Agency for Network and Information Security

GLOBAL BUSINESS DIALOGUE ON ELECTRONIC COMMERCE CYBER SECURITY AND CYBER CRIME SEPTEMBER 26, CEO EDS Corporation

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 16 thereof,

Digital Agenda for Europe Cartagena de Indias, September 1, 2015

NIS Direktive und Europäische sicherheitsrelevante Projekte Udo Helmbrecht Executive Director, ENISA

Research Topics in the National Cyber Security Research Agenda

EU policy on Network and Information Security and Critical Information Infrastructure Protection

20. Exercise: CERT participation in incident handling related to Article 4 obligations

Technical Guideline on Security Measures

Technical Guideline on Security Measures

Cyber security Country Experience: Establishment of Information Security Projects.

Public Private Partnerships and National Input to International Cyber Security

TUSKEGEE CYBER SECURITY PATH FORWARD

What is Management Responsible For?

Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

The internet and digital technologies play an integral part

Incentives and barriers for the cyber insurance market in Europe

National Cyber Security Policy -2013

Review of the regulatory framework for VoIP in Ireland

The EU s approach to Cyber Security and Defence

Romanian National Computer Security Incident Response Team CERT-RO.

Government Decision No. 1139/2013 (21 March) on the National Cyber Security Strategy of Hungary

Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Speech on Cyber Risks & Security Seminar, The EU Digital Agenda and the Cyber-security proposed Directive: A legal and a contextual approach,

Cyber Europe Key Findings and Recommendations

Cyber Diplomacy A New Component of Foreign Policy 6

Cyber Security - What Would a Breach Really Mean for your Business?

OUTCOME OF PROCEEDINGS

Dr. Vangelis OUZOUNIS Senior Expert Security Policies ENISA.

GOVERNMENT OF THE REPUBLIC OF LITHUANIA

Seamus Reilly Director EY Information Security Cyber Security

19. Exercise: CERT participation in incident handling related to the Article 13a obligations

HOW WILL FRANCHISORS IN EUROPE MEET THE CHALLENGES EU PROPOSED CYBERCRIME DIRECTIVE

The era of hacks and cyber regulation

Implementation of eidas through Member States Supervisory Bodies

National Cyber Security Strategy of Afghanistan (NCSA)

CYBER SECURITY STRATEGY OF THE CZECH REPUBLIC FOR THE PERIOD

Cyber Security for Railway Signalling

Data Processing Agreement for Oracle Cloud Services

Helmut Wacket Head of Oversight Division. Cybersecurity: regulatory framework and central bank initiatives in the EU

Regulation on Management and Assignment of.gr Domain Names. THE HELLENIC TELECOMMUNICATIONS & POST COMMISSION (EETT)

2 Gabi Siboni, 1 Senior Research Fellow and Director,

The Regulatory framework and VoIP. Merijn Schik, DG INFOSOC

National Cyber Security Strategies. Practical Guide on Development and Execution

Safety by trust: British model of cyber security. David Wallace, First Secretary, Head of of the Policy Delivery Group British Embassy in Warsaw

Mitigating and managing cyber risk: ten issues to consider

Making our Cyber Space Safe

005ASubmission to the Serious Data Breach Notification Consultation

How To Defend Yourself Against Cyber Attacks

New challenges in Data privacy.

Government Decision No. 1139/2013 (21 March) on the National Cyber Security Strategy of Hungary

Cyber Security Issues - Brief Business Report

Microsoft s cybersecurity commitment

On the European experience in critical infrastructure protection

Notification of data security breaches to the Information Commissioner s

Exercising Your Enterprise Cyber Response Crisis Management Capabilities

Cyber Insurance Presentation

September 20, 2013 Senior IT Examiner Gene Lilienthal

Transcription:

Cyber security initiatives in European Union and Greece The role of the Regulators Constantinos Louropoulos President of Hellemic Telecoms and Post Commission

Agenda Cyberspace challenges EU security initiatives EU strategic priorities Achieving cyber resilience in European Union ENISA An Agency for pan-european cooperation Greece Authorities and Responsibilities

Cyberspace has an impact on all parts of society and key sectors of economy should remain open, free and safe, protected by incidents and misuse it is vulnerable; cyber security incidents can disrupt the supply of essential services (water, healthcare, electricity, mobile services, government services, bank transactions, etc.) Cyber security involves practically everyone: governments, private companies, organisations, banks, institutions, citizens and many other organised groups of interest.

Cyber security initiatives in EU The strategy of the EU: An Open, Safe and Secure Cyberspace The EU s vision and the actions required to make the EU s online environment the safest in the world: defines principles for cyber security Suggests strategic priorities and actions addresses international cooperation as a key priority

EU Strategic priorities Achieve cyber resilience Drastically reduce cybercrime Establish a cyberspace policy within the EU. Develop the industrial and technology resources for cyber security Develop cyber defense capabilities

EU initiatives Achieving cyber resilience Proposal for a Directive on a common high level of Network and Information Security (NIS) Establish common minimum requirements for NIS at national level. The Member States will be obliged to: designate national competent authorities for NIS set up a well functioning CERT (Computer Emergency Response Team) adopt a national NIS strategy and a national NIS cooperation plan. Enable information sharing and mutual assistance among the national NIS competent authorities

EU initiatives Achieving cyber resilience Proposal for a Directive on a common high level of network and Information Security (NIS) Players in a number of key areas (energy, transport, banking, stock exchanges etc) Assess cyber security risks, ensure n/w and information systems are reliable and resilient via appropriate risk management Report incidents to the national NIS authorities, incidents with significant impact on the continuity of core services and supply of goods, relying on n/w and information systems

EU initiatives Achieving cyber resilience Framework Directive Article 13a and b of Directive 2002/21/EC (as amended by 2009/140 Directive) Member States shall ensure that providers of Networks: Take measures and manage risks posed to security of networks and services. Guarantee the integrity of their networks,& ensure continuity of supply of services Notify the competent National Regulatory Authority of a breach of security or loss of integrity Implementation by the Member States Transposition in national law Issuance of specific regulation Implementation of art 13 facilitated by ENISA

ENISA Achieving cyber resilience ENISA: European Union Agency for Network and Information Security The Agency's Mission is essential to achieve a high and effective level of Network and Information Security within the European Union. Together with the EU-institutions and the Member States, ENISA seeks to develop a culture of Network and Information Security for the benefit of citizens, consumers, business and public sector organisations in the European Union. ENISA is helping the European Commission, the Member States and the business community to address, respond and especially to prevent Network & Information Security problems.

ENISA Achieving cyber resilience Framework Directive Article 13a and b of Directive 2002/21/EC Publishes an annual report to provide industry and government bodies in the EU with data about significant incidents. Once a year, NRAs submit to the Commission and ENISA a summary report of the breach notifications received. Reports are submitted according to ENISA s guidelines Technical Guidelines for Incident Reporting.

ENISA - Annual Incident Reports 2012 Mobile networks (mobile telephony or mobile Internet) most affected: about 50 % of the incidents respectively. Mobile network outages affect many users (around 1,8 million users per incident). Emergency Services are affected by incidents: In 37 % of the incidents there was impact on emergency calls using the emergency number 112. Source: ENISA - Annual Incident Reports 2012 Analysis of Article 13a annual incident reports August 2013

ENISA - Annual Incident Reports 2012 76 % System failures. Assets most affected were switches (e.g. routers and local exchange points) and home location registers. Incidents categorized with root cause third party failures, mostly power supply failures, affected around 2.8 Million user connections on average. Natural phenomena cause long lasting incidents: Incidents caused by natural phenomena (mainly storms and heavy snowfall) lasted around 36 hours on average. Overload and power failures have most impact in terms of number of users and time duration. Source: ENISA - Annual Incident Reports 2012 Analysis of Article 13a annual incident reports August 2013

Cyber Security Management in Greece CERT name NCERT-GR Date of establishment Constituency Additional information National / Governmental www.cert.gov.gr AUTH-CERT Q2 2004 Research and Education www.auth.gr FORTHcert Q3 2007 Service Provider www.forth.gr/forthcert GRNET-CERT Q2 2000 Research and Education http://cert.grnet.gr Organization Responsibilities Additional information ADAE Privacy EETT Telecoms DPA Data Hellenic Police Assurance of wired, wireless and mobile communications privacy Regulation and supervision of telecommunications and postal market Protection of personal data Prevention, investigation and repression of crimes that are committed through means of electronic communication www.adae.gr www.eett.gr www.dpa.gr http://www.astynomia.gr/index.ph p?option=ozo_content&perform=vi ew&id=8194&itemid=378&lang=

Implementation of Article 13 in Greece Hellenic Authority for Communication Security and Privacy (ADAE) Issues regulation related to the security measures according to art 13 Performs audits related to conformity with aforementioned regulation Forwards audit reports to EETT

Implementation of Article 13 in Greece Hellenic Telecommunications and Post Commission (EETT) Receives significant incident reports from providers in the context of art 13a and forwards them to ADAE Submits to ENISA the annual report May issue binding instructions related to the security measures of art. 13 May ask from operators related data in order to assess conformity with security Moreover: measures of art.13 Produces regulation according to Directive 2002/22 related to the availability of telephone services in cases of force majeure and catastrophic network breakdown Performs audits related to conformity with regulation

EETT in more detail EETT is responsible for the management and assignment of the.gr Domain Names If a law enforcement agency detects webpages with illegal content, EETT can order the hosting provider to remove this webpage If the hosting provider cannot be located and the domain name of the web page is a.gr domain name, the law enforcement agency can order EETT at first to temporarily deactivate the assigned domain name and secondarily to delete the assigned domain name. In cases where the webpage is not hosted in Greece and the domain name is not.gr domain name, access of users in Greece to this webpage via the ISPs can be blocked.

Greece: Police Cybercrime Division A Division of Hellenic Police. Mission: to prevent, investigate and repress crimes that are committed through the internet or other means of electronic communication. The cybercrime unit, among others, deals with: crimes against juveniles, illegal penetration in computer systems, theft, destruction or illegal transport of software, digital data or audiovisual material, crimes against the privacy of electronic communications Source: Cybercrime unit webpage

Thank you for your attention Costas Louropoulos President of EETT