Feeds

Hackers v defenders in pan-Euro cyber security exercise

Critical online service stress tested by simulated assault

Beginner's guide to SSL certificates

Early results from the first European cybersecurity exercise have highlighted the need to improve communication and improve procedures to better combat future cyber attacks.

Cyber Europe 2010 brought together 150 experts from 70 public bodies in 22 countries around Europe to deal with 320 simulated cyber-security incidents. These incidents involved simulated attempts by hackers to take out critical online services or to degrade overall internet availability.

Participants included Computer Emergency Response Teams, ministries, national regulatory authorities and others. Representatives of a further eight member states acted as observers.

Mission control for the exercise was run from Athens, Greece, with around 50 people attending.

European Union security agency ENISA said the exercise offered an opportunity to develop improved procedures for protecting critical infrastructure systems.

Dr Udo Helmbrecht, executive director of ENISA, commented: "This was a first key step for strengthening Europe’s cyber protection. Each mistake and error made were useful ‘lessons-learnt’; that is what exercises are for.

"Now, the challenge is for the Member States to analyse and properly implement these findings, of how to improve the communication channels and procedures. Both internally within a Member State, and in between Member States, across Europe, [so] to strengthen our common cooperation."

The exercise, modelled on earlier US cyber-preparedness exercises such as Cyber Storm, aimed to establish trust between security incident handlers with countries and their counterparts across Europe. It also sought to test the effectiveness of communication channels and to "increase mutual support procedures" during cyber attacks or other security incidents.

A media briefing by ENISA in Berlin on 10 November will provide more information and draft conclusions about the outcome of the exercise. A full report is expected early next year.

ENISA reckons EU member states would benefit from running their own national cyber-security exercise.

Participants in the exercise included UK information security agencies. In a statement, the Cabinet Office the European cyber security exercise went together with an earlier exercise involving cyber security incident handlers in the US and other countries.

“The UK is an active participant in the first pan-European emergency cyber security exercise that is taking place today with involvement from BIS, CPNI and CSOC, the Cyber Security Operations Centre," it said.

"We place a huge importance on collaboration with our European and international partners and exercises such as this help to ensure that we have the right processes and procedures in place to deal with such events. Indeed we were also involved in a similar exercise coordinated by the Department of Homeland Security last month involving a number of nations." ®

Intelligent flash storage arrays

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.