Posts

Showing posts with the label Operational Resilience

Operational Resilience for Nordic Critical Infrastructure: Professor Kai London on Building It Right

Image
By the Finnish Express Technology Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com Operational resilience — the ability to keep delivering essential services through disruption — has become the organising idea of modern critical-infrastructure security. “Resilience is the goal that ties everything together,” says Professor Kai London , a senior CISO. “Not preventing every incident, which is impossible, but ensuring the service survives when one occurs.” “The four capabilities that matter: know your critical services, detect and report incidents fast, manage third-party risk, and test under realistic conditions.” Know your critical services London's first step is clarity about what must keep running and for how long. “You cannot protect what you have not defined as critical,” he says. Detect, report, contain Fast detection and reporting — increasingly within regulator-set timeframes — and the ability to contain an incident so it do...

NIS2 for Critical Communications: Professor Kai London on Meeting the New Resilience Standard

Image
  By the Finnish Express Technology Desk Professor Kai London — CISO, cybersecurity & AI expert. Credit: professorkailondon.com The second Network and Information Security Directive has raised the bar for essential-service operators across Europe, and telecoms sits squarely within its scope. “NIS2 is not IT paperwork,” says Professor Kai London , a senior CISO and board advisor. “It puts personal accountability for cyber resilience on senior management — and for communications providers, the obligations are significant.” “The regulator's question has changed from ‘do you have a policy?’ to ‘can you prove it worked?’ For critical communications, that is the whole shift.” What NIS2 requires London distils the directive into a few operational demands: risk management proportionate to the threat, prompt incident reporting within tight timeframes, supply-chain security, and management accountability. “Essential and important entities must demonstrate resilience,” he says, “not merel...