Tag: regulation

Welcome New Member – Dale Connell from Trinidad!

Welcome New Member – Dale Connell from Trinidad!

Please welcome our newest member from Trinidad, Dale Connell! Dale Connell is a seasoned Cyber Risk and Technology Lead within Deloitte’s Consulting service line at the Trinidad and Tobago office. With extensive expertise in information security strategy and implementation, Dale supports organizations across various industries 

Weekly Digest Issue #90 – August 29, 2024

CyAN’s weekly digest of cybersecurity news from around the globe. Find the links to the full articles below. LinkedIn version and discussion available here. If there is a topic you would like to see more of, do not hesitate to get in touch!

Weekly Digest Issue #87 – August 8, 2024

CyAN’s weekly digest of cybersecurity news from around the globe. Find the links to the full articles below.

LinkedIn version and discussion available here.

If there is a topic you would like to see more of, do not hesitate to get in touch!

Cybersecurity News

  1. Cyberattack knocks Mobile Guardian MDM offline and wipes thousands of student devices
    https://techcrunch.com/2024/08/06/cyberattack-knocks-mobile-guardian-mdm-offline-and-wipes-thousands-of-student-devices/
  2. Microsoft punches back at Delta Air Lines and its legal threats
    https://www.theregister.com/2024/08/07/microsoft_delta_fight/
  3. Every Microsoft employee is now being judged on their security work
    https://www.theverge.com/2024/8/5/24213774/microsoft-security-performance-reviews-employees-top-priority
  4. Keir Starmer says facial recognition tech is the answer to far-right riots
    https://www.theregister.com/2024/08/05/keir_starmer_facial_recognition
  5. Google Patches Android Zero-Day Exploited in Targeted Attacks
    https://www.securityweek.com/google-patches-android-zero-day-exploited-in-targeted-attacks/
  6. The Loper Bright Decision: How it Impacts Cybersecurity Law
    https://thehackernews.com/2024/08/the-loper-bright-decision-how-it.html
  7. Release of Russian hackers believed to be first U.S. prisoner swap to include international cybercriminal
    https://www.nbcnews.com/tech/security/us-releases-russian-hackers-evan-gershkovich-prisoner-swap-rcna164746
  8. Kazakh Organizations Targeted by ‘Bloody Wolf’ Cyber Attacks
    https://thehackernews.com/2024/08/kazakh-organizations-targeted-by-bloody.html

CyAN’s Position on the Proposed EU “Chat Control” Regulation

CyAN’s Position on the Proposed EU “Chat Control” Regulation

The draft European Union Regulation to Prevent and Combat Child Sexual Abuse would be ineffective at protecting children, violates fundamental rights, creates information security challenges, and bears numerous other risks to European digital society.

Weekly Digest Issue #75 – May 16, 2024

CyAN’s weekly digest of cybersecurity news from around the globe. Find the links to the full articles below. LinkedIn version and discussion available here. If there is a topic you would like to see more of, do not hesitate to get in touch! Part 1 Cybersecurity News Part 2: Analysis 

Striking a Balance between Values and Laws, Innovation and Regulation – Artificial Intelligence

The blog “The Tale of Two Approaches to Artificial Intelligence – EU AI Act & U.S. Executive Order on Safe, Secure, and Trustworthy AI” was a balanced look at the similarities and difference in approaches to AI.  The divergence of approach is a manifestation of our different legal systems, political cultures, and strategic priorities. This opinion piece is an extension of that blog focusing on the EU AI Act.  How might we strike a balance between innovation and regulation for both the big tech and the Small and Medium Sized Enterprise (SME)? Indeed there is a race to govern AI. Are we focusing on the real transformative power of this technology?

The European Union’s AI Act highlights its commitment to setting a global standard for the deployment of ethical AI. The delay is a natural by-product of our democratic values and character. It is a complex and impactful legislation that is attempting to delicately balance regulation and innovation with an aim to ensure the safety of AI systems that respect our values and laws, and yet, it must also avoid curbing the innovation that is critical to our economic vitality and technological progress.

The trilogue talks will commence and from a policy perspective perhaps creating a more nuanced category of AI applications which allow for a tiered approach to regulation is the way forward. Not all AI applications would need to be subjected to the same level of scrutiny, which reduces the burden on less risky AI activities. However, it still leans towards a protective regulatory regime. The compliance costs associated with it could disproportionately impact SMEs. The core of the challenge is ensuring this regulatory framework is robust to protect citizens and their rights without placing an undue burden on the smaller industry players.

To ensure that SMEs are not hindered by the Act, exemptions or tiered compliance requirements based on enterprise size or AI application scope would be prudent. Government funded programs or incentives for compliance could also relieve some of the financial weight on SMEs along side having a clear and accessible framework for compliance through the use of online portals or dedicated support teams to help SMEs navigate the regulatory landscape efficiently and effectively.

Innovation is not only the purview of big tech firms, it is in fact, the engines of breakthroughs and novel applications are often the SMEs. Therefore, the policy should be shaped in a manner that nurtures the innovative spirit inherent in these smaller enterprises.

Reflecting on the potential impact of the EU AI Act on the global stage, it is clear that the way we govern AI today will have an acute implication for the competitive dynamics of tomorrow.  

How could we address the concerns of the potential impact of the Act towards SMEs? the notion of big tech – big responsibility which echoes the principles of proportionality and fairness, recognizing that the giants of the tech industry have the resources to bear a greater share of the regulatory burden is compelling and interesting to explore. It is an approach that could be helpful in fostering a more equitable innovation ecosystem where SMEs can thrive without the overshadowing burden of compliance costs. The stakes are high in regards to foundation models and their applications that have an immense potential to alter industries and societies. It is incumbent upon the larger players, who have the capacity to develop and deploy AI at scale, ensuring their innovations do not cause negative societal impacts. They should be the ones primarily responsible for the rigorous testing, robust quality management and the ethical considerations that come with AI deployment.

For the SMEs whose AI applications are specialized and limited in scope, a big tech – big responsibility model would allow them to continue to innovate within their niche without the disproportionate burden of compliance. I am not advocating that SMEs should be exempt from regulation, rather the regulatory framework should be scalable and adaptable, reflecting the size of the company and the potential impact of the AI tool. A regulatory environment that is responsive to the scale and scope of the AI application encourages innovation across the board.

Artificial Intelligence is indeed a transformative technology. The transformation I am referring to is a paradigm shift from a culture of proprietary dominance to one of collaborative stewardship. Collaboration is not without its challenges, but it is key. Monetization is a significant hurdle. Big tech companies are beholden to their shareholders and operate within an economic model that awards intellectual property and competitive advantage. The willingness to share foundational models  and tools is contingent upon a business model that can reconcile the open dissemination of technology with the need to generate profits.

This is a challenge that requires the exploration of novel business models that incentivize collaboration without compromising financial sustainability of big tech firms. A tiered access model or a form of a revenue-sharing agreement where SMEs contribute to development and refinement of AI models in exchange for access to the technology could be one way. It is a complex issue that needs a multifaceted approach, which includes policy incentives, industry standards and most importantly perhaps, a cultural shift within the tech industry towards a more cooperative and socially responsible ethos.

The evolution of technology which can impact society in a profound way must not only prioritize innovation and market dominance but also social responsibility and ethical considerations. This is a pivotal cultural shift that requires a significant realignment of values and incentives, encouraging big tech to view their role through a lens of stewardship and societal benefit, rather than solely through the lens of profit maximization. Practically, this compels a rethinking of corporate governance structures to reward long-term, socially responsible innovation. Measuring success metrics would need to be recalibrated, moving away from short term financial gain to include long term impacts on society and environment.

This is not just about the willingness of big tech to share but also the mechanism by which they might do so in a manner that promotes sustainable, inclusive growth. Licensing agreements that allow SMEs to use AI technologies at a reduced cost, or collaborative research initiatives that pool resources and share findings, could also be transformative.

The role of government and international bodies in fostering this cultural shift through policies that incentivize ethical practices, such as tax breaks for companies that engage in responsible AI development, or grants for collaborative projects between big tech and SMEs could be an instrument to facilitate this cultural shift.

What novel business models can you think about that incentivizes collaboration without compromising financial sustainability? 

Does the big tech companies have a larger share of the moral and social obligation to ensure AI systems are ethical, fair, accountable and transparent?

The EU Cyber Resilience Act – A Brief-ish and Sloppy Overview

The EU Cyber Resilience Act – A Brief-ish and Sloppy Overview

The EU’s Cyber Resilience Act (CRA) recently gained political agreement, and is in the process of being adopted by the parliament. This expansive regulation will deeply affect how ICT products are designed, sold, and maintained in a more secure manner throughout the EU.

🔍 Exploring the Nexus: NIST Framework vs. DORA Regulation in the Financial Sector 🌐💼

CyAN member Gilles Chevillon shares an analysis of the Digital Operational Resilience Act, the European Union’s flagship regulation governing cybersecurity in the financial sector.

Video/Podcast – The Paradoxes of Personalization, Regulation, and Trust

Video/Podcast – The Paradoxes of Personalization, Regulation, and Trust

Kojo Osei Amoyaw-Osei Presents his Thesis

Kojo Osei Amoyaw-Osei is a master’s candidate at EM-Lyon Business School. He joins us today to discuss his thesis project for the MSc programme in Cybersecurity and Defence Management.

Businesses face a growing set of challenges when building their information security maturity – specifically, Kojo has identified three core paradoxes in his research:

1) Personalisation – delivering personalised experiences while respecting privacy preferences
2) Regulation – balancing regulatory compliance with data-driven strategies and innovation
3) Trust – earning and maintaining trust by adopting transparent data practices, implementing robust data security measures, and demonstrating responsible data use

This episode of the CyAN Secure-in-Mind video and podcast series turns our usual format around, as Kojo interviews John Salomon, the usual host of these sessions, based on his extensive experience in the industry, as part of his thesis research.

EM Lyon MsC in Cybersecurity and Defence Management: https://em-lyon.com/en/news/who-will-you-learn-msc-cybersecurity-defense-management-program

Kojo on LinkedIn: https://www.linkedin.com/in/kojooseiamoyawosei/

Check out the rest of CyAN’s media channels on https://cybersecurityadvisors.network/media – and visit us at https://cybersecurityadvisors.network

Intro/outro music courtesy of Studio Kolomna via Pixabay: https://pixabay.com/users/studiokolomna-2073170/

Enhancing Resilience: The Role of DORA in Business Continuity and Operational Resilience

Enhancing Resilience: The Role of DORA in Business Continuity and Operational Resilience

In today’s regulatory landscape, navigating various regulations related to risk management can be a daunting challenge for financial institutions. However, the Digital Operational Resilience Act (DORA) offers a unique perspective. DORA not only aligns with existing best practices and regulations but also presents opportunities for