Netherlands Cyber Security Strategy. Michel van Leeuwen Head of Cyber Security Policy Ministry of Security and Justice

Similar documents
Cyber Security in Europe

EU policy on Network and Information Security & Critical Information Infrastructures Protection

Cybersecurity governance in Europe. Sokratis K. Katsikas Systems Security Laboratory Dept. of Digital Systems University of Piraeus

ENISA EU Threat Landscape

Commonwealth Cyber Declaration

NATIONAL CYBER SECURITY STRATEGY. - Version 2.0 -

NEW INNOVATIONS NEED FOR NEW LAW ENFORCEMENT CAPABILITIES

The challenges of the NIS directive from the viewpoint of the Vienna Hospital Association

13967/16 MK/mj 1 DG D 2B

Electronic payments in the Netherlands

Cyber Security Strategy

RESOLUTION 45 (Rev. Hyderabad, 2010)

Brussels, 19 May 2011 COUNCIL THE EUROPEAN UNION 10299/11 TELECOM 71 DATAPROTECT 55 JAI 332 PROCIV 66. NOTE From : COREPER

INDEPENDENT COMMUNICATIONS AUTHORITY OF SOUTH AFRICA(ICASA) CYBERSECURITY PRESENTATION AT SAIGF. 28 th November 2018

Centre for cybersecurity Belgium : Role, Missions et future capacities

RESOLUTION 130 (REV. BUSAN, 2014)

UN General Assembly Resolution 68/243 GEORGIA. General appreciation of the issues of information security

Rohana Palliyaguru Director -Operations Sri Lanka CERT CC APCERT AGM and Conference, 24 th October 2018 Shanghai, China MINISTRY OF TELECOMMUNICATION

Society, the economy and the state depend on information and communications technology (ICT).

Promoting Global Cybersecurity

International cyber strategy for Norway

Policy recommendations. Technology fraud and online exploitation

H2020 WP Cybersecurity PPP topics

FSOR. Cyber security in the financial sector VISION 2020 FINANCIAL SECTOR FORUM FOR OPERATIONAL RESILIENCE

European Union Agency for Network and Information Security

RESOLUTION 130 (Rev. Antalya, 2006)

The cost of cybercrime the benefits of cooperation

Cyber Security Roadmap

Global cybersecurity and international standards

Cyber Security Strategy

ECOWAS Cyber security Agenda

December 10, Statement of the Securities Industry and Financial Markets Association. Senate Committee on Banking, Housing, and Urban Development

Cybersecurity Strategy of the Republic of Cyprus

Cybersecurity in Asia-Pacific State of play, key issues for trade and e-commerce

Cyber Security Issues and Responses. Andrew Rogoyski Head of Cyber Security Services CGI UK

Protecting Critical Information Infrastructure in times of increasing cyber conflict

Cybersecurity & Digital Privacy in the Energy sector

UNCLASSIFIED. National and Cyber Security Branch. Presentation for Gridseccon. Quebec City, October 18-21

Itu regional workshop

Cyber Security Development. Ghana in Perspective

ENISA & Cybersecurity. Dr. Udo Helmbrecht Executive Director, European Network & Information Security Agency (ENISA) 25 October 2010

ENISA Cooperation in the EU / NIS Directive

Global Alliance Against Child Sexual Abuse Online 2014 Reporting Form

COUNCIL OF THE EUROPEAN UNION. Brussels, 24 May /13. Interinstitutional File: 2013/0027 (COD)

Resolution adopted by the General Assembly on 21 December [on the report of the Second Committee (A/64/422/Add.3)]

The Republic of Korea. economic and social benefits. However, on account of its open, anonymous and borderless

COMESA CYBER SECURITY PROGRAM KHARTOUM, SUDAN

Legal and Regulatory Developments for Privacy and Security

A Strategy for a secure Information Society Dialogue, Partnership and empowerment

COUNCIL OF THE EUROPEAN UNION. Brussels, 28 January 2003 (OR. en) 15723/02 TELECOM 78 JAI 307 PESC 593

About Issues in Building the National Strategy for Cybersecurity in Vietnam

1 History of CyberSecurity in the Philippines 2 3

OUTCOME DOCUMENT OF THE INTERNATIONAL CONFERENCE ON CYBERLAW, CYBERCRIME & CYBERSECURITY

Building Digital Bridges

Security and resilience in Information Society: the European approach

Directive on security of network and information systems (NIS): State of Play

GLobal Action on CYbercrime (GLACY) Assessing the Threat of Cybercrime in Mauritius

INFORMATION SECURITY NO MORE THE CINDERELLA?

G8 Lyon-Roma Group High Tech Crime Subgroup

G7 Bar Associations and Councils

Released by the Minister of Broadcasting, Communications and Digital Media

China and International Governance of Cybercrime

Caribbean Cyber Security: Not Only Government s Responsibility

Implementing Executive Order and Presidential Policy Directive 21

National Cybersecurity preparation to deal with Cyber Attacks

'Cybersecurity' Threat or Opportunity. Saikat Datta Policy Director Centre for Internet & Society, India

10496/18 MC/sl 1 DGD 2

Thailand Initiatives and Challenges in Cyber Terrorism

Germany: Report on Developments in the Field of Information and Telecommunications in the Context of International Security (RES 68/243),

The European Policy on Critical Information Infrastructure Protection (CIIP) Andrea SERVIDA European Commission DG INFSO.A3

BRIEFING COMBATING CYBERCRIME: TOOLS AND CAPACITY BUILDING FOR EMERGING ECONOMIES. Geneva 18 April David Satola

National Policy and Guiding Principles

M a d. Take control of your digital security. Advisory & Audit Security Testing Certification Services Training & Awareness

Angela McKay Director, Government Security Policy and Strategy Microsoft

Project III Public/private cooperation

ISACA National Cyber Security Conference 8 December 2017, National Bank of Romania

Implementation Strategy for Cybersecurity Workshop ITU 2016

CYBER INCIDENT REPORTING GUIDANCE. Industry Reporting Arrangements for Incident Response

Cybersecurity for ALL

THE CYBER SECURITY ENVIRONMENT IN LITHUANIA

COMMISSION RECOMMENDATION. of on Coordinated Response to Large Scale Cybersecurity Incidents and Crises

Resilience, Deterrence and Defence: Building strong cybersecurity for the EU

GLOBAL AGENDA FOR CYBER CAPACITY BUILDING

Dr. Emadeldin Helmy Cyber Risk & Resilience Bus. Continuity Exec. Director, NTRA. The African Internet Governance Forum - AfIGF Dec 2017, Egypt

Security Aspects of Trust Services Providers

New cybersecurity landscape in the EU Sławek Górniak 9. CA-Day, Berlin, 28th November 2017

Systemic Analyser in Network Threats

Security Awareness Training Courses

How the Board Should Take Care of Cyber Security. ICS Conference 2012, October 31 Denmark

Mozilla position paper on the legislative proposal for an EU Cybersecurity Act

Hybrid Cyber Warfare, dual risks?

EISAS Enhanced Roadmap 2012

Ms. Izumi Nakamitsu High Representative for Disarmament Affairs United Nations

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium

Vademecum of Speakers

Achieving Global Cyber Security Through Collaboration

PROJECT RESULTS Summary

Package of initiatives on Cybersecurity

The commission communication "towards a general policy on the fight against cyber crime"

Cyber Resilience. Think18. Felicity March IBM Corporation

Transcription:

Netherlands Cyber Security Strategy Michel van Leeuwen Head of Cyber Security Policy Ministry of Security and Justice 1

Netherlands: small country, big time vulnerable #1 80% online banking 95% youth uses sociale media #2 94% > 1 pc per family #4 62% shops on internet (4th in EU) #3 After VS en UK on internet

Internet ocean cable connects Europe through Amsterdam IX 3

Cyberthreat is substantial Hacking as much as bicycle theft in NL Risk e-fraude is 3,5% -> pickpockets 1,7% (politieacademie, 2013) 13% van de Nederlanders slachtoffer van cyber crime (Veiligheidsmonitor CBS, 2014)

Diginotar Hold Security The Netherlands: wake up calls (2011-now) Leaktober Pobelka Dorifel DDOS-attacks 5

6 Cyber Security Assessment Netherlands 4

7 Cyber Security Assessment Netherlands 4

Legislative framework Law - Security breach notification in progress Law Computer criminality III in progress Budapest Convention EU Directive Network and Information Security Law Intelligence and Security Services Law code of criminal procedure Guideline responsible disclosure Laws, directives and regulations on privacy, child abuse, financial sector, telecom... 8

National cyber governance framework NETWORK & INFOSECURITY PROSECUTION INTELLIGENCE CONFLICT NCSC POLICE AIVD MOD DEFCERT Public Prosecution Service MIVD Military NATO Business-CERTs 9

Network & Infosecurity in the Netherlands Ministry of Security and Justice policy coördination Ministry Authorities NCSC Law Regulation and oversight Assistance and coöperation Government and businesses in critical infrastructure 10

Cyber security beeld: 4 belangrijke trends Hyperconnectivity Legacy Crime & state sponsored Privacy 11

Vision The Netherlands, together with partners, are committed to create a secure digital domain in which the opportunities of digitalisation are used, threats are confronted an fundemental rights are protected. 12

Cyber Security: The state of the art in the Netherlands Knowledge Crisis management Awareness Prosecution Respons Prevention Security measures Advise Threat Analysis Situational Awareness Detection Training Identification/Interests 13

National Cyber Security Strategy I - 2011 Public Private Partnership First action programme: 1. Setting up CS Council and National CS Centre 2. Setting up CS Threat Assessment 3. Increasing the resilience of critical infrastructure 4. Increasing response capacity on attacks/disruptions 5. Intensifying investigation and prosecution of cybercrime 6. Encouraging research and education 14

15 l

NCSS - 2011 NCSSII - 2013 Public Private Cooperation Public Private Participation Focus on structures Focus on networks / strategic coalitions Capacity building national oriented Capacity building national as well as international Do what you think is right (intuition) Balance (as a result of knowledge / experience): - Measures throughout cyber chain - Threats, assets and controls. Defining principles (for example, multistakeholder model, international cooperation). Defining a vision: for example on governance General approach Risk based approach Unaware Aware Aware Skilled

Developments Crime Security Space Broad approach to space means triangle of: - Security - Freedom - Economic/social benefits A more international approach and increased number of actors Need for a comprehensive governance model 17

National Cyber Security Strategy II 18

19

Private party Citizen Government 20

The Dutch Approach Doctrine: public private cooperation & private public participation Private private Public - private Public -public 21

Relevant PPP cyber security fora Strategic-policy level Cyber Security Council Committee Critical Infrastructure NCSC Council Tactical-operational level ISAC s Liaisons Incident Response Board Operational level Operational Incident Response Team forum International CERT community 22

NL Cyber security resilient against cyberattacks and able to protect its critical infrastructure Fight cybercrime invest in secure ICT products and services taking into consideration the promotion of privacy build coalitions for freedom, security and peace in the digital domain invest in innovation and adequate knowledge levels 23

Action programme; some successes in 37 actions Trusted Network Initiative National detection and respons network Strengthening analysis capabilities Strengthening Military Cyber Defence capabilities Global conference on cyberspace 2015/GFCE Tender for the National Cyber Security Research agenda Public-Private taskforce cybersecurity education Fusion Cell Economic Crimes Taskforce Engaging ethical hackers 24

Challenges for a secure Netherlands digital gateway to Europe - Third Strategy? -> Netherlands Cyber Space Strategy - The harder things: - from awareness to responsible behavior - e-skills, e-government, e-bussiness - measuring effectiveness - getting private sector involved financially - responsible zero day usage - encryption/decryption - international standards - secure hard- and software - international norms - internetgovernance - future opportunities/threats Big Data, Internet of Things 25

26