Thursday

20th Sep 2018

Opinion

Cyber threats are inevitable, paralysing impact is not

  • Ransomware works by infecting a machine, encrypting its hard drive and then displaying a message that promises functionality will be returned to normal upon payment of a fee. (Photo: Pixabay)

Ten years ago, almost to the day, Estonia came under sustained cyberattacks, which targeted our banks, media and government.

While the attacks themselves ultimately proved merely a nuisance, they raised global awareness of the vulnerabilities networked societies face and put a new, fundamental security challenge on the global agenda.

Read and decide

Join EUobserver today

Support quality EU news

Get instant access to all articles — and 18 year's of archives. 30 days free trial.

... or join as a group

Over 200,000 victims in more than 150 countries across the globe have recently been hit by perhaps the most significant global cyberattack to date. Among them were hospitals in the UK, which had to cancel medical procedures, and large corporations such as Telefonica and Renault-Nissan.

Ransomware attacks like the WannaCry campaign have been a growing problem for several years.

They work by infecting a machine, encrypting its hard drive and then displaying a message that promises functionality will be returned to normal upon payment of a fee – in this case 300-600 dollars per system.

When it hits unprepared organisations, a cyberattack can bring mission-critical operations to a standstill.

While ransomware can sometimes be removed, the only solution is often to wipe the affected machines and revert to a backup, if one exists.

Otherwise, data could be lost forever, as there are still no reliable reports of data recovery from systems encrypted with the WannaCry ransomware.

The events over the past two weeks have highlighted our collective reliance on the digital domain, but they have also shown its vulnerabilities.

In general, a digital way of life does not necessarily carry with it greater risks, but it is different from paper-based bureaucracies.

No victims in Estonia

Yet vulnerability does not inevitably mean compromise. This particular attack could easily have been avoided by basic security practices, such as replacing out-dated software and installing critical updates.

Indeed, some countries were not seriously impacted. In fact, no Estonian computer or system fell victim to this attack. And part of the reason was preparedness.

Estonian authorities have been working for several years to raise awareness of the risks of ransomware – by not updating systems, addressing vulnerabilities and implementing baseline security standards.

The healthcare sector, in particular, has been a focus of improving IT management routines.

Furthermore, the risks and vulnerabilities – and ways of avoiding or mitigating them – must be driven home to anyone who owns or manages an information system or computer network, however small.

The Estonian example is encouraging.

For instance, when Windows XP – the no-longer-supported Microsoft operating system, at the heart of the ransomware attacks – was about to become obsolete in 2013, a well-targeted public awareness campaign almost halved the number of Estonians using it.

Nevertheless, there are still no grounds for complacency. Further cyberattack campaigns may exploit different vulnerabilities, and there is no silver bullet to prevent them.

Any comprehensive approach must address the full range of activities from prevention and awareness to response and recovery, while also ensuring that the malicious actors (“bad guys”) behind a cyberattack are discovered, apprehended and deterred in the future.

Cyber security, simply put, is too fundamental to everyday life to be left up to technology experts or particular national authorities.

A sustainable solution is possible, but only through intense international cooperation: no nation can be truly isolated in cyberspace, therefore going it alone is not an option.

Potential for Europe

We see a major European role in every step along the way.

First of all, Europe can contribute to preventing such attacks from occurring in the future.

Currently being transposed into domestic law, the EU directive on Network and Information Security (NIS) requires providers of essential services – including healthcare and transport – to follow certain best practices and implement baseline security standards on their systems.

A cooperation group of national authorities responsible for cyber security will coordinate national cyber standards and rules, and focus, in particular, on cross-border vulnerabilities and dependencies in vital services.

While awareness about cybercrimes has increased as a result of recent wide-impact incidents, a lack of basic check ups still enables crimes such as ransomware.

The EU agency for law enforcement training (Cepol) already provides education on ransomware for European law enforcement authorities. Awareness campaigns for law enforcement, businesses, and citizens more broadly, have also been quite effective.

When large-scale attacks do occur, the response from public authorities must be swift and coordinated. Timely international and cross-sector sharing of alerts and operational information can slow the spread of such attacks. Joint campaigns and responses are even more effective.

In February of this year, the Maltese rotating EU Council presidency launched the work of the European Computer Security Incident Response Team (CSIRT) network, tasked with ensuring the seamless cooperation of national cyber incident response teams in the EU.

The CSIRT network will reach full operational readiness in 2018, and should facilitate the sharing of information between EU member states.

The WannaCry ransomware case is certainly accelerating the process and provides a first test to the partners.

Identify and capture

After an attack, we must identify and capture the cyber criminals behind it.

The EU's police agency, Europol, already coordinates active cooperation between European law enforcement with partners beyond Europe and, in particular, provides a suite of tools to help victims of ransomware to decrypt their files.

Furthermore, the European Commission is to propose EU-level action for better cooperation on the exchange of electronic evidence, which would reinforce the ability of law enforcement and prosecutors to identify and prosecute criminals.

To enable a smoother transfer of evidence in criminal investigations between the member states, it is also crucial that the European Investigation Order directive is efficiently transposed into national legislation by all countries involved. The deadline for implementing the directive was 22 May 2017.

While the WannaCry attack appears to be criminal in nature, state actors are often involved in the activities of cyber criminals. Where this is the case, the EU should respond appropriately.

Last year, the Dutch EU Council presidency began work on an EU joint-diplomatic response to state-sponsored malicious cyber activity, which could include sanctions.

The EU will also begin several new initiatives this year when Estonia assumes the EU Council presidency for second half of the year.

In the autumn, the EU Commission will update the 2013 EU Cyber Security strategy. The new document should consolidate the work done on European and national levels, and ensure that the whole activity adds up to more than just the sum of its parts.

We also expect a proposal on European cyber security labelling and certification, which should make it easier for consumers and companies to make cyber-aware purchases and put market pressure on businesses to produce and offer more secure services and products.

Along with the updated strategy, we will begin work on revising the mandate of The European Union Agency for Network and Information Security (Enisa) – Europe’s cybersecurity agency.

Playing a central role in the implementation of NIS Directive, the agency is to provide a common threat landscape, coordinate the activities of member states and enhance the platform for information exchange. These, altogether, foster an environment in which all nations are more ready to counter cyber threats.

No choice left

Cyber security is a question of a way of life. Europeans are used to the benefits and advantages of digital services and the availability of electronic networks.

Nations have no choice but to build up robust cyber security measures – reverting to a paper-based system would not be more secure, is as prohibitively expensive as it is impractical, and would rob us of the conveniences we currently enjoy.

The almost-crippling WannaCry campaign highlighted the immediacy of truly international and cross-sector solutions. Cyber security is not simply the prerogative of a narrow range of technical experts or particular agencies.

As said previously, Estonia will hold the rotating presidency of the Council of the EU in the second half of this year.

We believe that the Digital Single Market and the free movement of data within the EU are of existential importance for Europe – we must keep pace with technological chances, and growing markets in America and Asia.

We cannot allow the fear of cyber attacks to slow us down, but we also have to invest the political effort and necessary capital to make sure that Europe can keep its citizens safe and its businesses secure.

Taimar Peterkop is the director general of the Estonian Information System Authority

Investigation

French election faces high cyber threat

French president Francois Hollande has called for "all necessary means" to be used to fend off cyber attacks ahead of the presidential election in April and May. But political parties are still vulnerable.

US neo-Nazis linked to Macron hack

The spread of stolen emails designed to harm Emmanuel Macron was linked to US-based neo-Nazis, according to a French investigation.

Investigation

Lessons for Germany from the Macron hack

The way the Macron team defended itself against hackers contained lessons for other political parties in Europe, but experts do not agree whether Russia did it.

News in Brief

  1. Austria ex-chancellor hints at running for Juncker's job
  2. Greece to move asylum-seekers from overcrowded Lesbos camp
  3. Transatlantic soya trade soars due to trade wars
  4. EU tables strategy for connecting Europe and Asia
  5. Bulgaria backs Hungary in dispute with EU
  6. Trump urged Spain to build Sahara wall to stop migrants
  7. EU-Arab League summit proposed for February in Egypt
  8. Stop 'migration blame-game', Tusk tells EU leaders

Will the centre-right stand up for EU values?

Time for Christian Democrats in the EP to show where they stand on Hungary and on the EU's founding principles, say Human Rights Watch and Amnesty International in a joint text.

Europe needs more modern leadership

If Europe wants to be a global leader, our political leadership has to change dramatically. Power needs a new face in Europe, and it needs to get legitimacy from the people, argues liberal MEP Sophie in 't Veld.

Stakeholders' Highlights

  1. NORDIC COUNCIL OF MINISTERSThe Nordic gender effect goes international
  2. NORDIC COUNCIL OF MINISTERSPaula Lehtomaki from Finland elected as the Council's first female Secretary General
  3. NORDIC COUNCIL OF MINISTERSNordic design sets the stage at COP24, running a competition for sustainable chairs.
  4. Counter BalanceIn Kenya, a motorway funded by the European Investment Bank runs over roadside dwellers
  5. ACCACompany Law Package: Making the Best of Digital and Cross Border Mobility,
  6. IPHRCivil Society Worried About Shortcomings in EU-Kyrgyzstan Human Rights Dialogue
  7. UNESDAThe European Soft Drinks Industry Supports over 1.7 Million Jobs
  8. Mission of China to the EUJointly Building Belt and Road Initiative Leads to a Better Future for All
  9. IPHRCivil society asks PACE to appoint Rapporteur to probe issue of political prisoners in Azerbaijan
  10. ACCASocial Mobility – How Can We Increase Opportunities Through Training and Education?
  11. Nordic Council of MinistersEnergy Solutions for a Greener Tomorrow
  12. UNICEFWhat Kind of Europe Do Children Want? Unicef & Eurochild Launch Survey on the Europe Kids Want

Latest News

  1. EU divisions on menu at Salzburg dinner
  2. EU mulls action to prevent cattle suffering at Turkish border
  3. Safeguarding Schengen at Salzburg
  4. Denmark's image 'damaged' by bank scandal
  5. Real Brexit progress needed by October, Barnier says
  6. Poland to face EU top court on rule of law
  7. Austria's EU presidency: a bridge over troubled water?
  8. EU promotes 'Egypt model' to reduce migrant numbers

Stakeholders' Highlights

  1. Nordic Council of MinistersNordic Countries Take a Stand for Climate-Smart Energy Solutions
  2. Mission of China to the EUChina: Work Together for a Better Globalisation
  3. Nordic Council of MinistersNordics Could Be First Carbon-Negative Region in World
  4. European Federation of Allergy and AirwaysLife Is Possible for Patients with Severe Asthma
  5. PKEE - Polish Energy AssociationCommon-Sense Approach Needed for EU Energy Reform
  6. Nordic Council of MinistersNordic Region to Lead in Developing and Rolling Out 5G Network
  7. Mission of China to the EUChina-EU Economic and Trade Relations Enjoy a Bright Future
  8. ACCAEmpowering Businesses to Engage with Sustainable Finance and the SDGs
  9. Nordic Council of MinistersCooperation in Nordic Electricity Market Considered World Class Model
  10. FIFAGreen Stadiums at the 2018 Fifa World Cup
  11. Mission of China to the EUChina and EU Work Together to Promote Sustainable Development
  12. Counter BalanceEuropean Ombudsman Requests More Lending Transparency from European Investment Bank

Stakeholders' Highlights

  1. FIFARecycling at the FIFA World Cup in Russia
  2. Nordic Council of MinistersOECD Report: Gender Equality Boosts GDP Growth in Nordic Region
  3. Centre Maurits Coppieters“Peace and Reconciliation Is a Process That Takes Decades” Dr. Anthony Soares on #Brexit and Northern Ireland
  4. Mission of China to the EUMEPs Positive on China’s New Measures of Opening Up
  5. Macedonian Human Rights MovementOld White Men are Destroying Macedonia by Romanticizing Greece
  6. Counter BalanceControversial EIB-Backed Project Under Fire at European Parliament
  7. Nordic Council of MinistersIncome Inequality Increasing in Nordic Countries
  8. European Jewish CongressEU Leaders to Cease Contact with Mahmoud Abbas Until He Apologizes for Antisemitic Comments
  9. International Partnership for Human RightsAnnual Report celebrates organization’s tenth anniversary
  10. Nordic Council of MinistersNordic Cooperation Needed on Green Exports and Funding
  11. Mission of China to the EUPremier Li Confirms China Will Continue to Open Up
  12. European Jewish CongressCalls on Brussels University to Revoke Decision to Honour Ken Loach

Join EUobserver

Support quality EU news

Join us