Buckle up in cyberspace
No one has a complete overview of total internet usage and the associated risks – not the three billion users and not the highest authorities and smartest think tanks. It is therefore time for us to start taking the risks of cyberspace seriously and to develop a structural approach for addressing them, argues Jan van den Berg, Professor of Cyber Security at TU Delft in his inaugural address on 13 December.
Ad hoc approach
Cyber security incidents are the order of the day. These incidents can take the form of threats to the privacy of our citizens (as evidenced in Edward Snowden's revelations concerning the activities of such intelligence services as the NSA), as well as the form of government attacks on industrial processes (Stuxnet), credit card fraud, DDOS attacks on banks and government agencies, energy blackouts, cyberbullying and child pornography. To date, however, responses to such incidents have been ad hoc. According to Van den Berg, we are living from one wake-up call to the next. End users – three billion in all – do not know how the internet works. Experts do know how it works, but they know much too little about the risks.
Integral risk management
Van den Berg argues that it is time for all parties involved to start taking cyber security seriously and to develop a structured approach, comparable to the Delta Plan. We should view the problem of cyber security as a problem of integral risk management, with the ultimate challenge of reducing existing risks within a wide range of cyber sub-domains (e.g. critical infrastructures) to acceptable levels. This is both a technological and a social problem. Knowledge and awareness-raising are needed at all levels, and political agreements must be made regarding what we consider acceptable risks.
Democratic control
In light of these circumstances it is indispensable to specify what the cyber security problems are in various sub-domains of cyberspace: at the local, regional, national and international level, with regard to such matters as transport, financial services and the energy supply. Van den Berg is of the opinion that, in this process, it is essential to maintain transparency and build democratic control into the system. Reasons for doing so include the need to preserve or restore confidence in the government. End users should also learn to realise that security software should be installed on laptops, just as seat belts should be installed in cars.
Mathematician
Van den Berg entered the field of cyber security as a mathematician. Given the breadth and complexity of the field, however, he is now employed in two faculties: the faculty of Technology, Policy and Management and the faculty of Electrical Engineering, Mathematics and Computer Science. His mission is to collaborate with scientists from a wide range of disciplines and universities, as well as from the fields of education, government, business and NGOs, to chart the safety risks of cyberspace and to transform cyberspace into a safe domain for living and working.
Beginning in 2014, Professor Van den Berg will also be working as the director of the Cyber Security Academy in The Hague, a new initiative of the University of Leiden, TU Delft and The Hague University of Applied Sciences. He also plays a leading role in the Center for Safety & Security, which is part of the strategic partnership between Leiden University, TU Delft and Erasmus University Rotterdam.
Provided by Delft University of Technology