France Joins the Global Cyber War
From: Data Security Weekly
– Jubal McMillan
In recent editions of this publication, we’ve discussed the increasing sophistication, incidence, organization, and funding of hacking groups across the world, and how the crimes being perpetuated online are becoming more and more brazen. Hackers are no longer content to simply peek at emails or upload prank photos; they are now encrypting critical documents and demanding a ransom for the encryption key, or stealing thousands of identities at a time and auctioning them off to the highest bidder.
In the wake of these escalating crimes, we here at DSW have often predicted that law enforcement agencies around the world might be slow to warm up to cyber-threats, but once engaged, will retool to meet them head on.
Meet the newest player in the global war on cyber-crime: the CNIL.
The Commission Nationale de l’informatique et des Libertés, otherwise known as the French Data Protection Authority, the CNIL has recently released an activity report for 2011, showing a dramatic increase in overall manpower, technology, and seriousness. In the report, we find that the French are doubling up on their commitment to cyber security in many ways:
Mission: The overarching authority of the CNIL has expanded to include two key systems that were previously the domain of other law enforcement agencies. First, the CNIL now directly oversees all of the video surveillance systems presently installed on streets and highways throughout France, and second, all data controllers throughout the French telecom industry are obligated to report data breaches directly to the CNIL. This centralization of effort greatly increases the likelihood of swift and decisive action against cyber-criminals.
Workforce: The CNIL has doubled its staff over the last seven years, showing that not only are they experiencing increasing workloads due to higher numbers of intrusions and cyber-threats, but that they are beefing up their security infrastructure in an effort to counter those threats.
Complaint Increases: The CNIL has implemented a detailed online complaint listing tool that allows data controllers and telecom agents to input breach complaints with more accuracy and celerity than the previous system, which essentially involved calling the bureau and waiting on hold for an hour. By gathering data on intrusion more effectively and more completely, the CNIL can track trends far more effectively. It appears to be working: total complaint cases have grown significantly since the introduction of the new system.
Auditing: The CNIL carried out 25% more security audits in 2011 than in any previous year, showing a renewed commitment to security compliance of the private sector with existing data protection laws. Further, the CNIL has, laudably, placed a priority on ensuring that organizations managing health-related data or that regularly transmit data outside the European Union are first on the list for ongoing security checks.
By all measures, the French are taking the global cyber war seriously, and are ramping up the CNIL to engage hacking directly. As policies evolve, and more people are brought in to fight against the mounting tide of cyber-crime, it’s nice to know that the US has a stalwart ally across the pond that is equally dedicated, funded, and committed to manning the towers and defending cyberspace from the loathsome hoard of hackers hell-bent on ransacking the stores.
| Print article |