On Tuesday at the Espace Namur in Hamm Fedil-ICT and EY Luxembourg jointly hosted a breakfast cyber security report and discussion panel to an audience of continuity and risk managers, IT security professionals and other interested parties.
The event was compered by Brice Lecoustey, Partner at EY, and major author of the report, and backed up by a panel of experts consisting of Karim Sabbagh, President and CEO of SES and Chairman of SES Astra, Cédric Mauny, Risk and Department Manager at Telindus Luxembourg, Wojciech Soltysiak, Director of Technology Services at CHAMP Cargosystems S.A. and François Thill, President of the government agency “Security Made in Luxembourg” (SMILE).
Brice Lecoustey started the proceedings with a presentation of the report, the highlights of which were that both at a private and a corporate level the level of awareness of cyber security has increased enormously since the first report, commissioned back in 2007. More and more companies are creating a specific cyber security role in their organisations, while the biggest perceived threats are phishing, malware attacks and so called zero-day attacks (exploiting a software security vulnerability unknown to the supplier of the software which, once exposed, the supplier must fix immediately, i.e. in zero days).
Moving to the panel, SES’s Karim Sabbagh spoke of the 5 figure number of cyber attacks that SES receives on a daily basis and of some of the tactics that they employ to anticipate and deal with these attacks, reminding the audience that the company’s satellites broadcast to over 1.5 billion people worldwide, as well as its defence related systems, so a successful attack could have huge implications on a global scale. At a national level, he is very keen to see an additional 30 Luxembourg National highly trained cyber security specialists employed. On behalf of the state, François Thill highlighted that they are currently struggling to fill the two vacancies that they are currently advertising. Mr. Sabbagh insisted that the Luxembourgish state needed to exploit its ability to be nimble and flexible and to rapidly increase the level of training through specific courses in cyber security at the University of Luxembourg.
For his part Cédric Mauny revealed the slightly disturbing statistics that an estimated 44% of the computer using population share their passwords with family members or work colleagues, and that one in three of the population suffered some sort of cyber security issue in the last month. Speaking for CHAMP Cargosystems, Wojciech Soltysiak said that as a result of the increased number and variety of the attacks on his company’s systems, they have changed their cyber security policy from a reactive one to a so-called “active defence” policy, but still does not feel fully secure owing to the increasingly sophisticated nature of some of those attacks. He also advised that companies concentrate their efforts on securing the data and systems that matter most to them, and always to have not only a “Plan B”, but preferably plans C, D and E as well.
As Karim Sabbagh pointed out, the more successful the company, the higher the risk of cyber attack, and he also believes that there should be a central national cyber security body.
There was much discussion, some lively, but probably the most important thing to come out of the event was that government and the private sector are at least engaging in dialogue to create the necessary security environments to keep data safe at both a corporate and a national level, and THAT is very important for the economic future of Luxembourg.
Photos by John Chalmers (Top L-R: Karim Sabbagh, President and CEO of SES and Chairman of SES Astra; François Thill President of the government agency “Security Made in Luxembourg” (SMILE); Cédric Mauny, Risk and Department Manager at Telindus Luxembourg; Wojciech Soltysiak, Director of Technology Services at CHAMP Cargosystems S.A. Bottom: Brice Lecoustey, Partner at EY and event moderator)