IT security and privacy Ferenc Suba LLM, MA Chairman of the Board, CERT-Hungary Vice-Chair of the Management Board, European Network and Information Security Agency
IT security and privacy Challenge and opportunity for: - Business - Government - Endusers Future: CIIP - Critical - Information Infrastructure - Protection
BUSINESS Challenge: - How to convince users? (incident driven thinking) - How to estimate costs and benefits? (competing risk analysis methods) - How to avoid over-regulation? („autopoesis” of bueurocracy) Opportunity: - Demand growing parallel to IT penetration and emerging incidents - Never ending story (new applications, new fields) - New security economics (every loss that you avoid is a profit + insurance)
GOVERNMENT Challenge: - How to react globally? (global problem) - How to react efficiently? (official channels too slow) - How to keep your manpower? (turnover of qualified staff) - How to react to monoculture? (of course ) Opportunity: - International co-operation (ICAAN, IWWN) - New, flexible, structures + outsourcing (govCERTs) - De minimis regulation (liability of ISPs) - Create checks and balances
END USERS Challenge: - How to protect? (weakest link) - How to educate? (unwilling students) - How to make them liable? (e.g. internetbanking) Opportunity: - IT security as part of national curriculum - End user empowerment (deployment of technology) - Awareness raising (user friendliness) - Balance between outside protection and self responsibility
CIIP Future for IT security, because: - Vital - Ubiquitous (everywhere, affects everyone) - Easy to understand Keyword: co-operation - Between different sectors (not only IT) - Between different players (business, government, academia, endusers) - Between nations (global challenge)
Contacts European Network and Information Security Agency ( Theodore Puskas Foundation ( CERT-Hungary (