THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


What?
Ardie Kleijn, CISO Chief Information Security Officer at Transavia
If there is an emergency(a burglary, an accident, a fire, etc.) in the physical world,you can call for help an ambulance, firemenor the police via 112 (England 999 and US 911). This is a foundation of our rule of law, so that in principle no one has tobe his or her own judge and jury. In case of emergency, help is available, free of charge and fast.
Cyber 911 would be the digital counterpart of the physical emergency service. It offers the possibility to call for help in case of an emergency in a cyber incident. This service is provided for companies, governments, NGO’s and citizens alike. The help offered would be virtual during the emergency and could be followed up by on-site support, if necessary.
As in the physical world, in Cyber 911 pressing charges (in advance or afterwards) would not be a prerequisite for help. The assistance is free to all. Of course this is not a helpdesk which provides services on how to protect oneself in the cyberworld. Callers that try to use Cyber 911 as a helpdesk or call center will kindly be referred to other available services. Though if negligence might be the cause of a cyber incident, this should not intervene with the emergency service, it might have an effect on claiming expenses on the caller.
Why?
Today’s digital world lacks an entry point for free emergency assistance and support. Everyone tries to protect him- or herself from the ever-increasingcyber threats with the help of commercial parties. When an emergency service is needed, commercial companies are willing to offer assistance for substantial amounts of money. For the normal private citizen this is unfeasible. Of course, in the event of damage caused by a plundered bank account, the citizen can turn to the bank. And yes, in many cases the damage is compensated. However, this only provides a financial recovery of the bank account and not the collateral damage such as loss of equipment, and more importantly, of the loss of information, such as photos and documents.
Cyber 911 fills a gap in emergency services. Once someone calls for help, support is provided to mitigate and, if possible, even repair the damage. Think about ransomware situations in which the descriptionkeys are known.
Now cyber centers are often organized centrally by the government with a focus on critical infrastructure and often a mandatory notification for organizations in that critical infrastructure in case of cyber incidents. With Cyber 911 the entire society can get help.
Specific results?
For the rule of law, an improvement in image takes place. You can access support regardless of money. A reliable government offers a helping hand. Through Cyber 911, there is no guarantee that the incident will be fixed, but everyone feels that the rule of law supports everyone as best as it can.
A second benefit is that the information position of the government,i.e. the police, can improve. Pressing charges of cyber incidents are low. In particular,citizens will turn now to their banks or other financial institutions, where so far motivation to report cybercrime was not found. This happened to the point that most citizens had the feeling that the police could not understand their problems, let alone help them.
However, as soon as everyone reports incidents via Cyber 911 asking for emergency help, an overview of the spread and severity of certain cybercrimes can be offered on a different scale. In this way,through early detection, citizens, companies, and governments can also be warned of cyber dangers.
A third benefit of Cyber 911 isthat damage can be alsolimited. The earlier someone gets help, the smaller damageis producedand, in this way,earlier warning ispossible for others.
How can we achieve it?
In previous discussions I had in 2016 with various banking institutions, commercial cyber companies, and the police, it seemed that the business case was endorsed. The willingness to make this cyber emergency service availablefor everyone was supportedunder the condition that all information on cyber threats was transparently available to the participants.
Unfortunately,a political discussion emerged within the government regardingwho would be in charge of its implementation and realization. My position on this point is that the police should take the lead. This is an emergency response facility similar to physical burglary, etc. And the police as a public organization hascyber specialists on pay-roll. The free of charge support from private parties can be embedded by implementing individual screening of the participants for reliability. They can even get the status of a volunteer police officer with limited investigative powers. This can only be possible after the completion of the corresponding specializedtraining. Every participant needs to have a minimum level of cyber knowledge to enable true emergency assistance rather than a helpdesk function.
In Europe the emergency number 112 would offer four categories of help: ambulance, fire department, police, and cyber security. In the case of cyber threats, the emergency call would be redirected to a virtual call center in which public and private parties provide 24/7 support. Full recovery of all damage is not covered by Cyber 911. Just as in the physical world, a person would need a locksmith come to repair the broken doors themselves. By analogy, Cyber 911 will stop providing support once there is no longer an emergency. By the way, in the cyber world the emergency situation may take longer to solve than we are used to in the physical world.