ENISA executive director Dr. Udo Helmbrecht
Helmbrecht: "it will take a while to build up a secure, clustered cloud computing environment"

Q&A: European Network and Information Security Agency chief Udo Helmbrecht

EU cyber security agency ENISA pledges to protect EU member states

Written by Dave Bailey

The European Network and Information Security Agency (ENISA) is at the frontline of all the EU's IT security issues.

It was formed in March 2004 and is now based on the Greek island of Crete. Udo Helmbrecht was appointed executive director at the agency on 16 October.

Computing talked to Helmbrecht about ENISA's mandate and how the organsation intends to oversee information security in the EU going forward.

Computing: What is ENISA's mandate?

Helmbrecht: Our basic mission is to improve IT security across the EU. We will achieve this by bringing IT security people together and publishing best practices on different security issues. We recently published a report on resilience.

Different levels of IT security are required across the EU member states, and we have to allow for new member states joining the EU. At a higher level the European Services Directive, which aims to create a free market across Europe for the services sector, poses challenges for us.

The directive has to be implemented thoroughly. For instance, if you fall ill in another country, you will need to be able to use your health card for your country’s health provider to reimburse you.

We're trying to make sure this will work electronically, through interconnected procedures across different governmental departments. On a European level, this needs to be harmonised properly.

Identity cards are another big challenge for us. There are issues around securing your private data and your identity on the internet - there are also security issues around online banking, or just travelling from from one country to another. Again we will need standards to allow interoperability across the EU.

What's your view of IPv6 rollouts, given the stories about IPv4 IP address depletion?

The IPv4 address depletion is the result of the internet's success, and you have to remember that the TCP/IP protocols we are currently using were never designed to deal with the volume of traffic seen by the internet today. IPv6 will be implemented because of it offers more IP addresses and better security.

How will ENISA address the fact that some countries may want to move their public sector services onto a cloud computing platform such as Google's – or clouds that are not located in the EU?

We’ll be publishing detailed views on this later, but for now I’m unsure. Although the IT industry is pushing forward with cloud services, there are EU government institutions that already have big investments in public sector intranet infrastructures. How governments would build links from their infrastructures into any cloud computing rollouts would be critical. Governments would need to be sure of the service features and service levels they would get.

In addition, there are currently lots of security breaches and threats on the internet, and I think it will take a while to build up a secure, clustered cloud computing environment.

What are your views on some of the future services being explored by the EU such as ambient intelligence?

We will be working on a couple of projects around ambient intelligence. First we will co-operate closely with the European framework projects, which are looking into this type of technology. Second, we need to look at how this sort of technology is implemented in our society. An example might be the intelligent house in which IT products are deployed to support elderly people.

We need to consider whether these systems would be accepted by potential users as well as the time it takes to make such systems stable and secure.

What is the biggest problem facing Europe in terms of network security?

I think the big problem here is determining exactly how all the infrastructures in Europe are connected, which would mean working together with the service providers and other stakeholders. We would need data from all EU members that we could look at to provide a resistant network with a capable early warning system that would be used to keep the EU government up and running.

As a comparison, consider electricity companies - they know what’s happening on their electricity grids in real time – what areas have gone down and what they need to do to restore power. We depend on electricity and it is needed around the clock. I think a similar system is needed for the internet in Europe, but we need to exchange information at all levels involving all the stakeholders in European network security.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

Udo HelmbrechtGovernment

Enisa security body appoints new director

European agency names Udo Helmbrecht as Pirotti's successor 16 Oct 2009

 

EU agencies start moving to IPv6

EU security agency ENISA takes lead in IPv6 rollout 13 Oct 2009

EU security agency warns on European network resilience

ENISA says key technologies are suffering from lack of technical experience and operational best practice in EU 28 May 2009

ENISA talks up European security plans

European Agency for European Network and Information Security talks up its cybermoves 27 May 2008

EU agencies start moving to IPv6

EU security agency ENISA takes lead in IPv6 rollout 13 Oct 2009

Enisa security body appoints new director

European agency names Udo Helmbrecht as Pirotti's successor 16 Oct 2009

Security still an issue for cloud computing, says report

But Enisa argues that when done properly, security can be better in the cloud 19 Nov 2009

related whitepapers

today's top stories

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

PaperlinX outsources IT and comms to Bull and BT

Paper company spends €22m on five-year deal for desktop management, helpdesk and datacentre services 05 Feb 2010

Social tools take KM to a new level

Technology expert David Tebbutt explains how – and why – organisations should integrate social networking tools into their knowledge management strategy 02 Feb 2010

EDS court defeat puts vendors on their guard

BSkyB’s victory in a long-running court case against EDS has serious implications for the IT industry 02 Feb 2010

Law firm monitors web traffic violations

Bucks declining global security appliance sales with unified threat management (UTM) platform deployment 01 Feb 2010

Advertisement

Security: The New Face of Intrusion Prevention
An outline of traditional IPS functionality, modern developments and how IPS can be deployed easily.

UK businesses’ attitudes to Cloud Computing revealed

Features results from a survey of over 200 Computing readers.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

Internet Explorer 6

Internet Explorer 6

Following recent concerns about the security of Internet Explorer 6 are you planning to phase it out?

View poll results

Latest audio and video articles

Tony McAlisterVideo

Video Q&A: Tony McAlister, CTO, Betfair - Part one

On changing the skills development strategy at the online gambling firm - part one of a two-part video interview 05 Nov 2009

Video

Nokia shows upcoming handset technologies

Mobile phone features of tomorrow take the stage 21 Oct 2009

Latest in-depth articles

Analysis

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

Businessman with eye patch, dagger and tie round head, sitting at laptopFeatures

Are you sure you're not a pirate?

It is alarmingly easy for an IT leader to unwittingly exceed the scope of a software licence, and the chances of being caught out have never been greater, as technology lawyers Mark Weston and Paul Gershlick explain 09 Feb 2010

Primary Navigation