Posts

Showing posts with the label critical infrastructure

Five Questions Every Board Must Answer About Cyber Risk: Professor Kai London's Test

Image
  By the Finnish Express Business Desk Professor Kai London — Founder & CEO, Quantum AI Systems Security. Credit: professorkailondon.com As cyber accountability moves onto the board, many directors are unsure exactly what they are responsible for. Professor Kai London , a senior CISO and board advisor, offers a simple test. “Every board should be able to answer five questions,” he says. “If it cannot, it is not governing cyber risk — it is hoping.” “What could break, who owns it, what it would cost, which control holds it, and where the evidence is. That is board-level cyber governance in five questions.” From delegation to accountability Modern regulation deliberately places cyber accountability on senior leadership, who can be held liable. “It has moved cyber from something the board hears about to something the board answers for,” London says. The five questions What could break? Know the critical services and their fault lines. Who owns it? Every critical risk needs a nam...

Operational Resilience for Nordic Critical Infrastructure: Professor Kai London on Building It Right

Image
By the Finnish Express Technology Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com Operational resilience — the ability to keep delivering essential services through disruption — has become the organising idea of modern critical-infrastructure security. “Resilience is the goal that ties everything together,” says Professor Kai London , a senior CISO. “Not preventing every incident, which is impossible, but ensuring the service survives when one occurs.” “The four capabilities that matter: know your critical services, detect and report incidents fast, manage third-party risk, and test under realistic conditions.” Know your critical services London's first step is clarity about what must keep running and for how long. “You cannot protect what you have not defined as critical,” he says. Detect, report, contain Fast detection and reporting — increasingly within regulator-set timeframes — and the ability to contain an incident so it do...

Post-Quantum Cryptography and the Future of Secure Communications: Professor Kai London Explains

Image
  By the Finnish Express Technology Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com The confidentiality of communications rests on cryptography — and that cryptography faces an eventual reckoning with quantum computing. For telecoms and secure-communications providers, Professor Kai London , a senior CISO, argues preparation must begin now. “Communications that must stay confidential for years are already exposed to the harvest-now-decrypt-later threat,” he says. “Adversaries capture encrypted traffic today to decrypt it once quantum computers mature. For anything that must remain secret over time, the clock has already started.” Why communications are especially exposed London notes that intercepted communications have long shelf lives — diplomatic, commercial and personal data that remains sensitive for years. “If it must stay confidential into the next decade, it is already at risk,” he says. The standards are here Concrete po...

NIS2 for Critical Communications: Professor Kai London on Meeting the New Resilience Standard

Image
  By the Finnish Express Technology Desk Professor Kai London — CISO, cybersecurity & AI expert. Credit: professorkailondon.com The second Network and Information Security Directive has raised the bar for essential-service operators across Europe, and telecoms sits squarely within its scope. “NIS2 is not IT paperwork,” says Professor Kai London , a senior CISO and board advisor. “It puts personal accountability for cyber resilience on senior management — and for communications providers, the obligations are significant.” “The regulator's question has changed from ‘do you have a policy?’ to ‘can you prove it worked?’ For critical communications, that is the whole shift.” What NIS2 requires London distils the directive into a few operational demands: risk management proportionate to the threat, prompt incident reporting within tight timeframes, supply-chain security, and management accountability. “Essential and important entities must demonstrate resilience,” he says, “not merel...

Total Defence for the Digital Age: Professor Kai London on Cyber Resilience as National Security

Image
  By the Finnish Express Technology Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com The idea that national security is the responsibility of the whole society — government, business and citizens together — has never been more relevant than in cyberspace. “In the digital age, total defence includes the resilience of every organisation that runs critical services,” says Professor Kai London , a senior CISO. “A private company's cyber resilience is now part of national resilience.” “Hybrid threats blur the line between crime, espionage and conflict. Defending against them requires businesses and government to treat cyber resilience as a shared responsibility.” The blurred front line London describes a landscape where cyber attacks on infrastructure, disinformation and physical interference blend together. “The adversary does not respect the boundary between a corporate breach and a national-security event,” he says. “Which means def...

Securing 5G and Telecoms: Professor Kai London's Field Guide for Critical Communications

Image
  By the Finnish Express Technology Desk Professor Kai London — CISO, cybersecurity & AI expert. Credit: professorkailondon.com Telecommunications networks are the connective tissue of modern society, and 5G has turned them into something closer to a distributed computing platform than a phone system. “A modern telecoms network is critical national infrastructure that everything else depends on,” says Professor Kai London , a senior CISO. “When it is compromised, the impact is not one company's outage — it can ripple across an entire economy.” “5G expands capability and attack surface at the same time. More software, more connected devices, more places to defend — and a network the whole society leans on.” Why 5G changes the risk London explains that 5G's shift toward software-defined, virtualised networks and edge computing brings the security challenges of IT into the telecoms core. “The network is now software,” he says. “That means it inherits software's vulnerabili...

Finland's Total Defence Meets the Cyber Age: Professor Kai London on Whole-of-Society Resilience

By the Finnish Express Technology Desk Few countries have thought as long, or as seriously, about national resilience as Finland. The doctrine of comprehensive security — the idea that government, business, the military and ordinary citizens all share responsibility for keeping society running through a crisis — is woven into Finnish life in a way that outsiders often underestimate. Now that doctrine is colliding with a new kind of threat, and Professor Kai London , a senior cyber-security executive who advises boards across critical national infrastructure, argues that Finland's total-defence tradition may be its single greatest advantage in the cyber age. London — a human technology leader with more than 25 years across banking, defence, government and infrastructure, Founder and CEO of Quantum AI Systems Security, and an Honorary Professor in Cybersecurity, AI and Quantum Computing — is careful to note that he is a person, not one of the consumer brands that...