Cyber Security in EU: ENISA approach



Similar documents
Cyber Security in EU: ENISA approach

Cyber Security in Europe

ENISA What s On? ENISA as facilitator for enhanced Network and Information Security in Europe. CENTR General Assembly, Brussels October 4, 2012

EU Priorities in Cybersecurity. Steve Purser Head of Core Operations Department June 2013

Enhancing Cyber Security in Europe Dr. Cédric LÉVY-BENCHETON NIS Expert Cyber Security Summit 2015 Milan 16 April 2015

Prof. Udo Helmbrecht

Achieving Global Cyber Security Through Collaboration

ENISA: Cybersecurity policy in Energy Dr. Andreas Mitrakas, LL.M., M.Sc., Head of Unit Quality & data mgt

How To Write An Article On The European Cyberspace Policy And Security Strategy

Cooperation in Securing National Critical Infrastructure

NIS Direktive und Europäische sicherheitsrelevante Projekte Udo Helmbrecht Executive Director, ENISA

How To Understand And Understand The European Priorities In Information Security

EU Cybersecurity Strategy and Proposal for Directive on network and information security (NIS) {JOIN(2013) 1 final} {COM(2013) 48 final}

European Union Agency for Network and Information Security ENISA ANNUAL REPORT

Towards defining priorities for cybersecurity research in Horizon 2020's work programme Contributions from the Working Group on Secure ICT

WORK PROGRAMME NOVEMBER 2012

European Distribution System Operators for Smart Grids

The Growth of the European Cybersecurity Market and of a EU Cybersecurity Industry

ICS-SCADA testing and patching: Recommendations for Europe

EU policy on Network and Information Security and Critical Information Infrastructure Protection

Analysis of ICS-SCADA Cyber Security Maturity Levels in Critical Sectors

CYSPA - EC projects supporting NIS

Achieving Global Cyber Security Through Collaboration

Supporting CSIRTs in the EU Marco Thorbruegge Head of Unit Operational Security European Union Agency for Network and Information Security

Cloud and Critical Information Infrastructures

ENISA workshop on Security Certification of ICT products in Europe

CYSPA launch event - Turkey

ENISA Work programme

Cyber security initiatives in European Union and Greece The role of the Regulators

Smart grid security certification in Europe Challenges and recommendations

Best Practices in ICS Security for Device Manufacturers. A Wurldtech White Paper

The State of Industrial Control Systems Security and National Critical Infrastructure Protection

Partnership for Cyber Resilience

Cyber Security for Railway Signalling

National Cyber Security Strategies. Practical Guide on Development and Execution

Stocktaking, Analysis and Recommendations on the Protection of CIIs JANUARY European Union Agency For Network And Information Security

ROADMAP. Proposal on a European Strategy for Internet Security

National Cyber Security Strategy

FFIEC Cybersecurity Assessment Tool Overview for Chief Executive Officers and Boards of Directors

Good Practices on Reporting Security Incidents

Methodologies for the identification of Critical Information Infrastructure assets and services

Cyber Security in Austria

RE: Experience with the Framework for Improving Critical Infrastructure Cybersecurity

NIST Cybersecurity Framework What It Means for Energy Companies

ASEAN Regional Forum Cyber Incident Response Workshop Republic of Singapore 6-7 September Co-Chair s Summary Report

Appropriate security measures for smart grids

Smart grid cyber security certification

EU Cybersecurity: Ensuring Trust in the European Digital Economy

National Cyber Security Strategies

OUTCOME OF PROCEEDINGS

Cyber Security :: Insights & Recommendations for Secure Operations. N-Dimension Solutions, Inc.

Technical Guideline on Security Measures

D 6.4 and D7.4 Draft topics of EEGI Implementation Plan Revision: Definitive

OPEN CALL FOR TENDERS. Supporting Critical Information Infrastructures Protection and ICS-SCADA security activities

Building Blocks of a Cyber Resilience Program. Monika Josi monika.josi@safis.ch

Cybersecurity in the Utilities Sector Best Practices and Implementation 2014 Canadian Utilities IT & Telecom Conference September 24, 2014

April 8, Ms. Diane Honeycutt National Institute of Standards and Technology 100 Bureau Drive, Stop 8930 Gaithersburg, MD 20899

How To Discuss Cybersecurity In European Parliament

How To Write A Cybersecurity Framework

Internet Governance and Cybersecurity Patrick Curry MACCSA

CYBERSECURITY INDEX OF INDICES

Annual Incident Reports 2011

How To Manage Risk On A Scada System

ENCS/NEC RESEARCH MEETING

ANALYSIS OF CYBER SECURITY ASPECTS IN THE MARITIME SECTOR

The Critical Infrastructure: To be or not to be Secure. European Network for Cyber Security. Fred Streefland Director Education & Training

Cyber security in an organization-transcending way

Cybersecurity in the maritime and offshore industry

EU Directive on Network and Information Security SWD(2013) 31 & SWD(2013) 32. A call for views and evidence

Cyber Security key emerging risk Q3 2015

Cyber Security Review

Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Cyber Resilience Implementing the Right Strategy. Grant Brown Security specialist,

Next Steps for the European Electricity Market Infrastructure and Market Design

Making our Cyber Space Safe

Helmut Wacket Head of Oversight Division. Cybersecurity: regulatory framework and central bank initiatives in the EU

Cyber Security and Cyber Warfare: The EU approach and experience Prof. Claudio CILLI CIA, CISA, CISSP, CISM, CSSLP, CRISC, CGEIT, M.Inst.

Smart Grid America: Securing your network and customer data. Michael Assante Vice President and Chief Security Officer March 9, 2010

CYBER SECURITY AND CYBER DEFENCE IN THE EUROPEAN UNION OPPORTUNITIES, SYNERGIES AND CHALLENGES

Managing Cyber Risks to Transportation Systems. Mike Slawski Cyber Security Awareness & Outreach

Safety by trust: British model of cyber security. David Wallace, First Secretary, Head of of the Policy Delivery Group British Embassy in Warsaw

Best Practices in ICS Security for System Operators. A Wurldtech White Paper

Privacy and Security in Healthcare

Transcription:

Cyber Security in EU: ENISA approach Konstantinos Moulinos, Security Expert European Union Network and Information Security Agency Norwegian Energy Days 2015, Oslo European Union Agency for Network and Information Security

Securing Europe s Information Society Operational Office in Athens 2

Positioning ENISA activities 3

Terms and interrelationships Critical Infrastructure Protection* Energy Energy sector (e.g. gas, nuclear) Security & safety Energy sector Cybersecurity Smart grid cybersecurity National Cybersecurity Strategies 4

EU Policy Context Energy and CIIP Directive 114/2008 EU s CIIP action plan Proposal for a NIS Directive EU Cyber Security Strategy (COM Digital Single Market strategy 5

Why cyber? ICS-CERT Year in Review 2014 HP Enterprise Security s 2014 Global Report on the Cost of Cyber Crime by the Ponemon Institute Many incidents but no major disruptions yet Everybody agrees that we have to do something but what? 6

Cyber security management Smart grid dependencies on telcos Smart grid threat landscape Risk assessment Information Security Intelligence Smart grid devices certification ICS SCADA security Governance and roles Appropriate security measures Cost of implementation Security measures Incident Reporting Cyber Security is not only technical but also operational and organisational? Root causes? Assets affected 7

Governance models report- Why? Low participation of public authorities in EG2 ad hoc group on Smart grid security measures Overlapping mandates amongst different national authorities TSOs do not consider smart grid security as their problem Energy regulators usually not empowered with cyber security mandate Smart grids an emerging area sometimes not covered by CIIs 8

Status of existing governance models Legend: Size: Roles and Responsibilities o Small: No roles and responsibilities defined o Medium: Definition ongoing o Large: Roles and responsibilities already defined Color: Smart Grid Cybersecurity Framework o Red: Existing Smart Grid Cybersecurity Framework o Blue: No existing Smart Grid Cybersecurity Framework Sub-quadrants position: Smart Grids and Critical Infrastructure Protection o Right: Smart Grid part of National Cyber Security Strategy (NCSS) o Left: Smart Grid not part of NCSS o Up: Smart Grids part of National Critical Infrastructures (NCIs) o Down: Smart Grids not part of NCIs 9

An example of Incident Reporting: Telecoms Most major outages were caused by software bugs and hardware failures Detailed Causes and Affected Assets (Percentage of all incidents) Most major outages affected base stations and switches 10

ENISA effort in Smart Grids Challenging area, emerging technology Different types of stakeholders Various sizes of organizations Not a clear view of the market Setting baseline cyber security measures for Smart Grids Not an easy task Consensus is needed ENISA aims to reach better harmonisation across the EU this way contributing to the Digital Single Market Strategy Collaboration with the European Commission Smart Grids Task Force (SGTF) Adoption by the SGTF EG2 and CEN/CENELEC/ETSI Smart Grid Coordination Group Practical guide to deploy baseline security measures This year ENISA is developing a study on smart grid dependencies on telcos (expected mid of Nov.) 11

ENISA efforts EuroSCSIE ICS Security Stakeholder Group Protecting Industrial Control Systems. Recommendations for Europe and Member States Can we learn from SCADA security incidents? Window of exposure a real problem for SCADA systems? Good Practices for an EU ICS Testing Coordination Capability Certification of Cyber Security skills of ICS/SCADA professionals This year ENISA is developing a study on ICS SCADA maturity models (expected mid of November) 12

like curling 13

Information Sharing ERNCIP European Reference Network for Critical Infrastructure Protection. TNCEIP Thematic Network on Critical Energy Infrastructure Protection DENSEK European Energy - ISAC NIS platform ENISA SISEC Smart Infrastructures Security Experts Community ENISA ICS Security Stakeholder Group Collaboration with: CEER ACER ENTSO-E Eurelectric 14

Trends Mandatory incident reporting (EU) Information sharing and analysis (EU) Baseline security measures (EU) National risk assessment (MS) Compliance Audits (MS) 15

Key recommendations Governance Model Foster R&D Cybersecurity as a Requirement Identify and Analyze Cost of Cybersecurity Measures Common EU Energy Cybersecurity Framework Trusted Information Sharing Initiatives Increase User Awareness National Risk Assessment National Energy Cybersecurity Framework Incident Response Capabilities and Report Mechanisms Definition of Roles and Responsibilities Join International Forums and WG Collaboration Platform National Forum on Energy Cybersecurity Support Dialogue Among Stakeholders Define Baseline Security Requirements 16

Open issues Next Steps Identification of good practices for Energy Sector incident reporting Certification of smart grid components and systems Definition of EU baseline security requirements A roadmap for more harmonized national certification approaches Certification of smart grid cyber security skills Incident response capability for smart grids and relationships to existing national ICS-CERT/Gov CERTs Bring competent authorities on board 17

Conclusions Cyber Security becomes important for the well functioning of the society and economy Critical Services and Infrastructures (including energy) should be better protected from cyber attacks and threats MS recognize the importance and develop NCSS A more coordinated cybersecurity approach is needed to address cyber security issues for different energy subsectors (e.g. gas, nuclear) ENISA s develop good practices for EU MS and Private Sector to address the emerging issues Sharing experiences and deploying good practices improves the situation quickly When it is necessary additional regulatory measures are introduced to resolve issues More involvement by NRAs is required 18

Konstantinos Moulinos resilience@enisa.europa.eu http://www.enisa.europa.eu/act/res