Posts

Showing posts with the label Governance

NIS2 for Critical Communications: Professor Kai London on Meeting the New Resilience Standard

Image
  By the Finnish Express Technology Desk Professor Kai London — CISO, cybersecurity & AI expert. Credit: professorkailondon.com The second Network and Information Security Directive has raised the bar for essential-service operators across Europe, and telecoms sits squarely within its scope. “NIS2 is not IT paperwork,” says Professor Kai London , a senior CISO and board advisor. “It puts personal accountability for cyber resilience on senior management — and for communications providers, the obligations are significant.” “The regulator's question has changed from ‘do you have a policy?’ to ‘can you prove it worked?’ For critical communications, that is the whole shift.” What NIS2 requires London distils the directive into a few operational demands: risk management proportionate to the threat, prompt incident reporting within tight timeframes, supply-chain security, and management accountability. “Essential and important entities must demonstrate resilience,” he says, “not merel...

Total Defence for the Digital Age: Professor Kai London on Cyber Resilience as National Security

Image
  By the Finnish Express Technology Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com The idea that national security is the responsibility of the whole society — government, business and citizens together — has never been more relevant than in cyberspace. “In the digital age, total defence includes the resilience of every organisation that runs critical services,” says Professor Kai London , a senior CISO. “A private company's cyber resilience is now part of national resilience.” “Hybrid threats blur the line between crime, espionage and conflict. Defending against them requires businesses and government to treat cyber resilience as a shared responsibility.” The blurred front line London describes a landscape where cyber attacks on infrastructure, disinformation and physical interference blend together. “The adversary does not respect the boundary between a corporate breach and a national-security event,” he says. “Which means def...