We all feel that we are entering in an “Era of Insecurity”.
The complex international geopolitical context, most countries focusing on their own protection and economy, closing many of their boundaries and reactivating visas, happens at the detriment of multiple alliances, associations, joint efforts, works, thinktanks and standards established between countries.
I recommend reading the following great article from IISS organization which summarizes it all :
https://www.iiss.org/publications/the-military-balance/2024/chapter-1-era-of-insecurity/
Whether this is natural and could have been expected or it’s a preliminary signal of extreme tough times to come, or both at the same time, there is a need for all of “us” to ensure “our” own protection and prepare for resilience.
When I say “us”, it could be Europe, France or other countries, one or several business verticals, and even at personal (and family) level.
I believe you all know this quote :
โHard times create strong men. Strong men create good times. Good times create weak men. And, weak men create hard times.โ
G. Michael Hopf (Those who remain)
Well, I very strongly believe in it. And what we currently observe in Europe is, I believe, resulting from the good times that all of us have welcomed.
A couple of years ago, I heard the Head of an Intelligence Service state the following :
“Happy times between the 2 wars, when we could travel, live, invest, work everywhere is now over. And I’m not talking about WW1 and WW2โฆ”
This second article also describes the evolution of the European Cyber Defense, mainly through:
- Sharing of intelligence data
- Securing communications
- Increasing investment in Signal Intelligence (SIGINT)
- Increasing investment in electronic warfare
So, what does it mean for us, and particularly for Cyber warfare ?
It means that regulations at country and european levels will continue to evolve, drastically. It means that the established trust between countries and organizations will be even more at stake. It means that we must not consider that security is at no cost, that we must educate, train, test the level of prepareness of our kids, students, employees and partners.
It also means that it’s time to consider that all countries, all people, all verticals are concerned. Not just some of them that are involved in legacy warfare. We must be vigilant as if our country was already in the state of war. To avoid attacks and impacts.
Remaining alliances (even between countries) will need to agree on some common rules – and enforce them for real. Those alliances will require their members to trust each other, up to a point that has hardly been reached before. And avoid contradictory rules or inconsistent levels of controls / audits. Piling up different layers of “sovereignty” or trust will inevitably impact the performance at the worst possible time (the need for competition is extreme during tough timesโฆ). To say it differently, living close to a powerful neighbour requires to have common interests, ideology, culture and fears.
I have the feeling that NIS2 and DORA are only the emerging parts of such upcoming regulations. However, the difficulty is that it defines both “a target” level of protection and a minimum one, leaving up to the various companies how to apply the so-called “proportionality principle” and how to harmonize the resulting policies and controls.
In such context, the introduction of Governance, Risk & Compliance (GRC) solutions will also become critical, for various reasons:
- Document how organizations manage the various risks and what are the critical systems to consider
- Ensure consistency within a vertical
- Cover the entire supply chain, whatever the size and level of maturity of suppliers
- Automate continuous monitoring to demonstrate that the controls described in the policies are effectively enforced
- Break the silos between various departments, to ensure maximum efficiency and effectiveness
- Publish, via a “Trust Center” the most tangible evidences that companies consider their protection and resilience with due care
- Add other frameworks of compliance in the future, without having to rebuild everything from scratch and disrupt the ongoing strategies and tactics.
I have invested a lot of my time in studying those solutions, as well as how to transform companies’ cybersecurity mindset, decision-making processes. And I have the feeling that above all the technologies engaged, strong leadership, governance, prepareness and anticipation will remain at the heart of our effective resilience.
To conclude, I have the feeling that we are making decisions now that will strongly impact our future and hopefully our ability to return to “happy times” as soon as possible. Educating our children, with proper values and despite what we all hear at the news remains critical. I strongly adhere to the statement that we should start by caring for the mindset of the people that will leave in tomorrow’s world if we care for the world they’ll leave in.
In other words:
“Many will not understand, but we have to raise warriors”
Aaron McKie, John Chaney
We could also recap by saying :
“Prepare for the worst, hope for the best”
Maya Angelou






























You must be logged in to post a comment.