Cybersecurity & AI

Cybersecurity & Artificial Intelligence

A winning collaboration.

Author: Cédric Mauny
15/03/2022
Cybersecurity

A Winning Collaboration?

It is now widely recognized that synergies, information sharing, and collaboration are essential in ICT in general and in cybersecurity in particular. This is necessary both to face increasingly organized attackers and to contribute to reducing cybersecurity costs by leveraging existing initiatives.

 

An organization addressing a dual challenge

Increasing protection against increasingly organized and professional attackers while reducing costs brings undeniable benefits, but requires an appropriate organizational structure.

Protecting against attacks requires reducing the time gap between the execution of an attack and its detection.

Attackers operate in stages. They establish contact with their targets well in advance and increase the number of potential victims within the same sector to maximize their chances of success. It is therefore essential to build the widest possible monitoring network in order to detect all existing signals.

Indeed, weak signals that, when considered individually, may not have any particular meaning, can take on a completely different significance when analyzed collectively within an ecosystem. They can then reveal coordinated attempts that are the early stages of a broader attack.

Reducing cybersecurity costs requires the pooling of best practices and information.

It is widely acknowledged that independently developing new security measures in isolation is a waste of valuable resources. Conversely, sharing information and processes, and expressing security needs within a business ecosystem, creates significant opportunities for cost reduction.

The key therefore lies in pooling data and expertise. This requires increased information sharing, which can be achieved by leveraging these two elements.

 

Connecting knowledge through networks

In March 2020, at the beginning of the Covid crisis, early signs of coordinated attacks targeting the healthcare sector raised serious concerns. Such a scenario can no longer be ruled out, and it is today that we must prepare for a potential widespread attack affecting the entire economy or an entire industry sector.

In order to obtain a comprehensive view of the preparatory stages of such an attack, it is necessary to pool and share information at both global and sectoral levels.

When we refer to connecting knowledge through networks, in the form of data and expertise sharing, we inevitably think of sharing information collected, managed, and generated by Security Operation Centers (SOCs).

This model must now evolve, and we must consider that the future of SOCs lies in establishing networks of detection sensors and information-sharing mechanisms regarding attacks.

This could take the form of “Sector-Specific SOCs”, enabling bidirectional information exchanges, whether through information reporting or the triggering of alerts.

The success of such “Sector-Specific SOCs” can only be based on trust and the voluntary nature of information sharing. This structure must remain neutral and rely on secure communication protocols that protect both the integrity of exchanged information and the confidentiality of stakeholders, while complying with applicable laws and regulations such as GDPR, CSSF, or ILR requirements.

 

Establishing information-sharing networks

Still relatively unknown, Information Sharing and Analysis Centers (ISACs) nevertheless represent an effective and efficient tool for encouraging information sharing within economic sectors.

ISACs have already been implemented in Luxembourg. To mention one example, the ISAC for the manufacturing sector, supported by the Ministry of the Economy and organized within FEDIL.

The advantage of ISACs lies in their inherently sector-based approach, enabling them to capture the opportunities described above. By sharing best practices, risk scenarios, and lessons learned, organizations within the same sector allow the entire community to protect itself against specific and targeted threats.

It is within such circles that the principle of “not reinventing the wheel” truly makes sense: organizations can improve their security posture through optimized resource consumption while simultaneously contributing to the protection of the entire ecosystem.

It is through sharing that we can address the challenges ahead. Large organizations learning from the pragmatism of smaller ones, and smaller organizations benefiting from the maturity of larger ones. Based on this same principle of interdependence, the private sector, the public sector, and the State can all benefit from specific exchanges, particularly when addressing the fight against cybercrime.

 

Coordination against cybercrime

Today, it is no longer possible to exclude cyberspace as a weapon, just as espionage between states and/or state-sponsored espionage can no longer be ruled out.

In this context, it is increasingly recognized that economic sectors can also contribute to national protection. Considering the specific requirements of national security, we can therefore envisage that the “Sector-Specific SOC” model could be complemented by the establishment of a “National Security Operations Center” (NSOC) responsible for monitoring critical infrastructures.

Such an entity could be placed under the responsibility of a state body, as suggested by Xavier Bettel in his State of the Nation address and within the framework of the National Cybersecurity Strategy IV.

What would be the objective? To develop a global and sector-based vision of exposure to threats in order to identify the early warning signs and weak signals mentioned above — no longer only at a sectoral level, but at a national level.

It is through collaboration between the public and private sectors, and through information exchange, that we will be able to prevent the worst and prepare for the best.


J’ai conservé un style professionnel / institutionnel, adapté à un livre blanc, une conférence cybersécurité, une publication stratégique ou un document gouvernemental. J’ai aussi légèrement adapté certaines expressions françaises (“mutualisation”, “mise en réseau de la connaissance”, “ne pas réinventer la roue”) pour qu’elles sonnent naturelles dans un contexte anglophone de cybersécurité.

 

Have a question?
By submitting this form, I accept the Proximus NXT personal data protection
*required fields