Thursday

1st Dec 2022

Opinion

Lessons for EU to protect against next cyber attack

As the latest ransomeware attack 'Bad Rabbit' spreads through Europe, it is again clear that there are few degrees of separation between malware targets and global information technology networks.

Initially aimed at Ukraine's Ministry of Infrastructure and Kiev's public transportation system, the current ransomware blitz has now spread to Turkey and Germany, compromising a growing list of international businesses, government interests and thousands of personal computers.

Read and decide

Join EUobserver today

Become an expert on Europe

Get instant access to all articles — and 20 years of archives. 14-day free trial.

... or subscribe as a group

The explosive growth of cloud-based and on-demand data systems has pushed vital sectors such as business, banking, and healthcare into risky relationships with IT infrastructure that exposes them to unexpected threats. But governments have even more at stake. Their need to house sensitive citizen data and protect national security has made them ideal targets for cyber-attacks.

Many countries are actively developing e-governance strategies — digital initiatives centred on citizen needs that are meant to promote service efficiency, productivity, transparency, and technological innovation. But these actions have also introduced a range of potential security risks, which need to be met with coordinated cybersecurity frameworks.

High-profile government hacking incidents, such as the 2015 breach of more than 22 million employee profiles in the US Office of Personnel Management database (including extensive security clearance files and personal backgrounds) are alarming examples of the holes being exploited by cyber criminals and state-sponsored hackers.

What can governments do to safeguard their data systems and citizens, and to reduce the spread of global 'e-pidemics'?

Three steps

First, they must shift to holistic approaches that progress beyond suites of technical tools such as firewalls, intrusion detection systems and spam filters. They must embrace organisational and behavioural change. By integrating a 'prevention is better than cure' strategy, governments can create interagency knowledge networks and focus on training computer users to be aware of cyber risks, how to avoid them, and how to be first responders when attacks strike.

One such example is the Australian Cyber Security Centre (ACSC) — a government "hub for private and public sector collaboration and information-sharing to combat cyber security threats". The centre aggregates cybersecurity and cyberdefence capabilities from a wide range of government departments, police units, crime commissions, the private sector, academia, local government, and international partners.

ACSC plays a pivotal role in raising awareness of cybersecurity issues, reporting incidents, analysing and investigating attacks and threats, and coordinating national security operations to respond to cyber-attacks.

Second, governments must have a clear cybersecurity strategy and make a deliberate investment in building capacity to deal with cybercrime. This begins with a broad assessment of government organisations to fully understand all aspects of their operations in cyberspace (e.g. open doors, levels of data-sensitivity, user authentication, encryption of sensitive data, etc.). Only then can comprehensive security policies and best practice guidelines be developed to ensure that overarching cybersecurity defences are effectively scaled to protect critical information and infrastructure.

But strategies must also be built on a reliable foundation of focal points in relevant government agencies, authorities and civil society. These human resources are crucial links to wider detection of, and recovery from, cyber-attacks.

Third, while the responsibility to develop strong legislation that discourages cyber-attacks falls on the shoulders of governments, they should look to impartial advisors and international organisations such as the United Nations, who are dedicated to enhancing cybersecurity culture and building awareness at policy levels.

UN research centres, like those of the United Nations University, are well positioned to bring partners to the table to find solutions. For example, development of an internet governance model and an international treaty harmonising national laws against cybercrime such as copyright infringement, fraud, child pornography, hate crimes, and cybersecurity breaches with supervision of related UN agencies would be welcome by member states.

Effective cybersecurity is a complex transnational challenge that requires strategy and cooperation at all levels and among states. There is a long way to go to build a coordinated response to computer crimes, but with new exploits being developed every day, there is no time to wait. Our short-term solutions must be devised as building blocks of a collaborative effort to fight global cyber-attacks.

Nuno Lopes and Jose Faria are researchers at the United Nations University operating unit on policy-driven electronic governance.

Disclaimer

The views expressed in this opinion piece are the author's, not those of EUobserver.

EU unsure how to 'make most' of AI

Whoever controls AI, 'will become the ruler of the world', according to Russian president Vladimir Putin. EU leaders want to move quickly to harness the opportunities of the technology.

On cybersecurity, Europe must act now

Some governments have closed their eyes, hoping that the menace will go away. It will not - it will only become stronger, according to the former prime minister of Estonia, one of the EU's leading digital states.

A missed opportunity in Kazakhstan

Tokayev received congratulations on his election victory from presidents Xi, Putin, Erdogan, and Lukashenko. However, the phone in the Akorda, Kazakhstan's presidential palace, did not ring with congratulatory calls from Berlin, Paris, London, or Washington.

Stakeholders' Highlights

  1. Nordic Council of MinistersCOP27: Food systems transformation for climate action
  2. Nordic Council of MinistersThe Nordic Region and the African Union urge the COP27 to talk about gender equality
  3. International Sustainable Finance CentreJoin CEE Sustainable Finance Summit, 15 – 19 May 2023, high-level event for finance & business
  4. Friedrich Naumann Foundation European DialogueGender x Geopolitics: Shaping an Inclusive Foreign Security Policy for Europe
  5. Obama FoundationThe Obama Foundation Opens Applications for its Leaders Program in Europe
  6. EFBWW – EFBH – FETBBA lot more needs to be done to better protect construction workers from asbestos

Latest News

  1. Belarus dictator's family loves EU luxuries, flight data shows
  2. How Berlin and Paris sold-out the EU corporate due diligence law
  3. Turkey's EU-funded detention centres ripe with abuse: NGO
  4. In green subsidy race, EU should not imitate US
  5. EU Commission proposes suspending billions to Hungary
  6. EU: Russian assets to be returned in case of peace treaty
  7. Frontex leadership candidates grilled by MEPs
  8. Portugal was poised to scrap 'Golden Visas' - why didn't it?

Stakeholders' Highlights

  1. European Committee of the RegionsRe-Watch EURegions Week 2022
  2. UNESDA - Soft Drinks EuropeCall for EU action – SMEs in the beverage industry call for fairer access to recycled material
  3. Nordic Council of MinistersNordic prime ministers: “We will deepen co-operation on defence”
  4. EFBWW – EFBH – FETBBConstruction workers can check wages and working conditions in 36 countries
  5. Nordic Council of MinistersNordic and Canadian ministers join forces to combat harmful content online
  6. European Centre for Press and Media FreedomEuropean Anti-SLAPP Conference 2022

Join EUobserver

Support quality EU news

Join us