Organised by EuroCloud Luxembourg in collaboration with the High Commissioner for national protection (HCPN) and the European Network and Information Security Agency (ENISA), the Cyber Europe 2016 event on Luxembourg participation was held at the premises of FEDIL last week.

The event was held for Luxembourg to test its ability to respond to a possible cyber-attack on a European scale and participation in "Cyber Europe 2016" exercises.

An expert in network security and information from ENISA opened the conference by saying that "the lack of tools to address the consequences of a major international crisis invites a European approach". He said the objective of the exercise is to simulate spot or phased cyber attacks ("hacks", "malware Windows, Linux," specific cloud incidents) at national and international levels. This year, thirty member states participating in the exercise through national planners, including government organisations - such as HCPN for Luxembourg - and "players" of the private sector, namely cloud operators and ICT stakeholders and the Computer Emergency Response Team (CERT) / Computer Security Incident Response Team (CSIRT).

The exercise aims not only to evaluate the co-ordination at European and national levels, but also to assess the response capacity of different actors. It is also an exercise in "building trust", i.e. a crisis management test including test reactivity, time delays and communication between stakeholders in case of attack. This will identify the right partners and good practices for the companies concerned and be prepared in the event that such a crisis would happen in reality.

The conduct of the exercise will be in two consecutive stages without obligation to participate in both:

- The 1st phase will last from April to October. ENISA will launch 1-2 challenges / incidents per month to familiarise the "players" with the platform set up for the occasion and the types of incidents for the year. It is for each business to participate in challenges / incidents if it wants and when it wants, the information remains accessible for the 1st phase, however, it is necessary to respect the chronology of the challenges / problems.

- The second phase will take place in October. All the "players" will collectively participate in the simulation of a Europe-wide crisis. This exercise will provide an opportunity for participants to use communication channels with government organisations and employees, either nationally or internationally.

Finally, ENISA stressed that the goal is to collect "players" motivated ready to play the game. Subsequently, a speaker of HCPN clarified the advantage of the benefits that can be derived by Luxembourg companies and Luxembourg as an ICT centre of excellence this year, namely improving business resilience and, more generally, improving the resilience of the ICT sector in Luxembourg.

He also said that the added value of the exercise leads to a good realism comes from the ability to tailor the attack scenarios at the national level to simulate the environment of the participating company based of the local ecosystem.

The exercise is open to participation. companies interested in particpating may contact Paul Rhein at email: paul.rhein@hcpn.etat.lu. For further information see http://cyber-europe.eu/.