Held at KPMG Luxembourg's premises in Luxembourg-Kirchberg, the after-work event on Cyber Security attracted over one hundred interested attendees to address issues of cyber threats and data privacy from the perspectives of technology, legal and insurance aspects.

Magnus Carter introduced the event and mentioned that cyber threats are everywhere, and gave the example of ISIS who are currently preparing for "cyber war" by developing the capabilities to encrypt security and other systems; he also referred to the recent hack at Talk-Talk, a telecomms operator in the UK, that would cost them between €40-€50m, and this is before the share price is affected. Such threats also have implications for the bottom line.

Francois Thill, a senior information security at Luxemburg's Ministry of the Economy and President of Security Made in Luxembourg, delivered a keynote address with the key message of tackling problems together as one can no longer do this alone. He said that Luxembourg promotes itself abroad as safer than other countries.

He said that threats have become mature, with 50% in cyber crime, 40% in cyber espionage and 10% in cyber activism in Luxembourg. He asked how can we trust the security of sub-contractors? Some of the issues involve resources as well as reducing costs and complexity and creating appropriate governance. Adopting a risk management approach will identify priorities and where to invest, to provide reliable results and where regulators can aggregate results.

He stressed that risk management is not a one-off exercise and needs to be repeated on a regular basis. The scope is important, as are probability and vulnerability, as is the need to reduce subjectivity in the planning.

Mark Camillo, Head of Professional Indemnity and Cyber at AIG Insurance, explained that companies now want to insure information and intellectual capital. He explained that they undertook a survey of publicly-traded companies which revealed that many boards do not address cyber threats and many directors do not understand the legal implications of cyber breaches; as a result, they identified a need to train those regarding liability and related issues. He explained that many such claims come from dealing directly with a data breach.

Audrey Bertolotti at CMS Luxembourg (legal) addressed the legal perspective of cyber security related to data protection. She explained that there are laws from both 2002 and 2005 on data protection, with the second expanding it to include cyber security, as well as new laws currently being planned. She stressed that the risk behind data collection is one of data integrity, with duty of security being paramount. She explained that related measures can be split between prior to an attack and post attack.

She said that according to the law of 2002, sanctions can include imprisonment for 8 days to 1 year as well as fines from €251 to €125,000. In addition, the criminal code in Luxembourg differentiates theft, theft with blackmail and IT fraud (2 months to 3 years imprisonment, plus a fine from €500 to €30,000). However, new European rules will add clauses including the right to be forgotten, explicit consent and notification of serious breaches, as well as a single set of rules across the EU on data protection.

She added that companies holding personal data will need to have a Code of Conduct in place. The new EU rules will also increase penalties for serious offences with penalties up to €1m.

Thomas Koch, Senior Manager in Information Risk Management at KPMG, talked about threat assessment. He talked about (1) Perception, based on 4 fundamental strategies of people, partners, customers and stakeholders; (2) Advanced Persistent Threat 1 (APT1) is an enterprise scale and presumably military-funded data theft and espionage operation, which has been active since 2006 and are believed to have stolen hundreds of Terabytes from organisations such as CocaCola, the World Street Journal, Bloomberg and Facebook; (3) KPMG's Feel Free programme, a whole new approach to the cyber security topic comprising 3 essential steps: Acknowledge, Prepare and Resist.

The event concluded with a round-table panel discussion which addressed specific case studies.

Photo by Geoff Thompson