23
EMM @ CERT-EU Freddy Dezeure Head of CERT-EU

EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Embed Size (px)

Citation preview

Page 1: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

EMM @ CERT-EU

Freddy DezeureHead of CERT-EU

Page 2: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Agenda

• About CERT-EU

• EMM @ CERT-EU

• Use cases

Page 3: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

About CERT-EU

• EU Institutions’ own CERT• Supporting all EU institutions, bodies and agencies• Defence against sophisticated, targeted cyber threats• Hub of information and skills in prevention, detection and

response

3

Page 4: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Peers - Partners

Page 5: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

EMM @ CERT-EU

https://cert.europa.eu/

5

IOSAndroid

Page 6: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

• Public Portal (https://cert.europa.eu) – 1800+ Sources– Automatic gathering of information on cyber threats– Clustering of breaking news– RSS enabled on all screens– 3000 daily users

• Private Portal (https://emmp.cert.europa.eu)– 3000+ Sources– Additional filters– Editorial interface for high power users (clients and partners)– 30 daily users

Web Portals

Page 7: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Public Portal

Page 8: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Commissioner

• What are the questions and answers?

Before lunchtime please

• Detect stories on which the Commission(er) may have an interest

• Validate and peer review them• Collect more information and write a brief• Obtain agreement before SPP meets the press

Page 9: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Breaking News

Page 10: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Monthly Security Brief

10

•Open source information, hand-picked and commented

•Distribution:– 300 people on

technical, managerial and political level

– CSIRT network

Page 11: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats
Page 12: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

CERT-EU

• How can we push critical guidance to the community?

• Write White Papers / Critical Advisories• Validate internally and with peers• Release publicly• Amplify with Tweets

Page 13: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

CERT-EU Guidance

13

Page 14: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats
Page 15: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Responsible Hackers

• What will you give me if I inform you about a problem in your constituency ?

• Validate the responsible disclosures• Alert constituents and follow up• Publish the name of the discloser in the Hall of Fame

Page 16: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Hall of Fame

Page 17: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Hall of Fame

Page 18: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Peers & Partners

• We want this too!

Internet

EMM Frontend Server EMMP Frontend Server

All internet users

EMM Backend Server

EMMP Backend Server

Partners

Internet Servers

Page 19: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

19

EMM Newsdesk

19

Page 20: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Peers - Partners

Page 21: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Efficient Set Up

Public Website•First contact with JRC 3 July 2011•First set of keywords and themes end July 2011•First version portal on test server 16 August 2011•Web portal live 22 September 2011•Continuous improvement

Private Website•Currently 25 peers & partners•Setting up a new group: 30’

Page 22: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Take Aways

• Additional, in-house, capacity for development• Essential tools in CERT-EU’s work• World-wide impact• Supports our networking with Peers & Partners• We want more:

– Social media monitoring– Twitter in/out

Page 23: EMM @ CERT-EU · PDF fileAbout CERT-EU • EU Institutions’ own CERT • Supporting all EU institutions, bodies and agencies • Defence against sophisticated, targeted cyber threats

Thank You

https://cert.europa.eu/ App