Whitepaper - Cybersecurity - Miruna Iliescu
Whitepaper - Cybersecurity - Miruna Iliescu
Whitepaper - Cybersecurity - Miruna Iliescu
SEPTEMBER 2020
White Paper, „Cercetător-antreprenor pe piața muncii în domeniile de specializare
inteligentă (CERT-ANTREP)” Cod SMIS 2014+: 124708
Co-financed by the European Social Fund through the Human Capital Operational Program
INTRODUCTION
CONTENTS ABSTRACT
Introduction ....................................2 This white paper provides an
Context .............................................3 analysis on the different
EU Directives and Regulations...5 cybersecurity threats that can be
EUANIS Recommendations .........7 found in SMEs' information
European Best Practices...............8 technology (IT) environment.
Romanian National Initiatives..12 This study points out different
Proposal............................................13 regulations and best practices
Conclusion.......................................14
that helped build a cybersecurity
References........................................15
capacity in different business
environments in Europe.
This is a proposal written by Miruna
Iliescu, PhD student and target group Lastly, this paper provides a
member of CERT-ANTREP, founder perspective on what services are
of inquito, a Romanian SME. The required by Romanian SMEs to
present paper is addressed to the mitigate cyber threats and solve
business communities in Romania. different cyber security issues.
<10% 1.2%
Romanian companies implement is the percentage of female
compulsory training courses or working in ICT field in Romania
viewing compulsory material on of the total female employment
ITC security issues (DESI, 2020) (DESI, 2020)
CONTEXT
Cyber security was identified by the Global Risk Report 2018 as one
of the three risks to global stability over the following 5 years (World
Economic Forum, 2018). As of 2017, there were an estimated 3.9
billion Internet users worldwide and this accounts for more than
half of the global population. As of 2019, there are 4.57 billion people
online and, for the first time in history, more than half of the world's
total population, 3.96 billion, now uses social media (We are Social
& Hootsuite, 2020).
Even more scary should be the fact that 60% of SMEs close within 6
months of being hacked (Galvin, 2018). Despite this context,
according to Digital Economy and Society Index (DESI) 2020 only
24.2% of European enterprises plan compulsory training on
security. There are significant disparities across Member States
regarding training courses, from Estonia, UK and Denmark (above
35%) to Romania, Greece and Hungary (below 10%).
This "It won't happen to me.. Until it does" approach is common due
to lack of education and awareness on cyber security procedures,
industry practices and attacks' risks. Since the COVID-19 pandemic
started, the US FBI reported a 300% increase in reported cyber
crimes and Google has reported a major jump in phishing attacks
when 18 million coronavirus email scams per day were added to the
240 million daily spam messages (Google, 2020). According to
studies conducted by specialised companies, more than 4000 new
sites related to the COVID-19 outbreak were created in the past
months, several of them being false (certSIGN, 2020).
EUROPEAN
DIRECTIVES AND
REGULATIONS
The legislator has the role to create laws and regulations that are
necessary on issues such as definition of minimum security levels,
definition of harmful activities, punishment of harmful activities,
implementation of state policies related to Internet security
etc. Enterprise-level metrics (ELMs) address the security level of an
organisation. In spite of considerable efforts, there is no universally
agreed-upon methodology to address the system security. There are
some initiatives aimed at developing new paradigms for identifying
measures and metrics: Institute for Defense Analyses (IDA) 2006,
Idaho National Laboratory (INL), MIT Lincoln Laboratory etc.
Facilitating implementation
Creating standards specifically targeting SMEs
Developing implementation guidelines
Implementing a phased approach during the adoption process
Promoting security and privacy by design
Increasing capabilities
Creating ownership of the information security function
Providing support for standard adoption
Fostering cooperation
Promoting international, European and national collaboration
Participants:
- 626 SMEs
- Sectors: finance, education, communications and technology,
health, transport, real estate and manufacturing
Activities:
- workshops and lectures
- in-person site visits
- systems review and comprehensive report
Resources
- free services, awareness materials and support
- list of trusted third-party resources and services
EUROPEAN
BEST PRACTICES
CYBER IRELAND
Services:
Cyber Ireland Events & Regional Chapter
Meetings in order to build a network and
make connections
Talent & Skills working group; Cyber Careers
Dashboard
Cyber Ireland Schools Academy programme
Objectives
Stronger Promotion & Supporting cross-industry
collaboration
Ensuring a sustainable pipeline of Cyber Security Talent
Supporting Irish SMEs and startups to grow and export
Enhancing collaborative R&D between industry and
academia
EUROPEAN
BEST PRACTICES
Services:
Startups and SMEs security
assessments
Security focused assessments of
products for investors
Internal product testing
Cybersecurity trainings using gaming
and simulations
Objectives
Increase Luxembourg's competitive
advantage in cybersecurity
Contribute to the development of
emerging ecosystems (IoT, FinTech)
ROMANIAN NATIONAL
INITIATIVES
CONFERENCES &
RESOURCES AND NETWORKING FREE TRAINING
MATERIALS EVENTS AND EDUCATION
The results of the studies and the resources and materials developed
will be disseminated and promoted in conferences on basic
cybersecurity topics. The materials would be presented as well in
networking events where they would be improved through feedback
from both final users and experts in the field.
IBM Security & Ponemon Institute. (2017). Cost of Data Breach Study:
Global Overview. Retrieved on 18th August, 2020 from
https://tinyurl.com/yywyts8d