Cyberattacks: The Ministry of Digital Resources suggests sharing responsibility between major market players

Tomcat

Professional
Messages
2,656
Reputation
10
Reaction score
646
Points
113
The agency also wants to create a single platform for combating cyber threats.

The Ministry of Digital Development held a meeting with representatives of IT companies, telecom operators and banks, where the idea of creating a single platform for responding to cyber attacks was discussed, Kommersant writes. Market participants had to prepare proposals for the implementation of this initiative.

Telecom operators Tele2, Vimpelcom and MegaFon confirmed their participation in the meeting and their readiness to participate in the development of the new platform concept. Deputy Head of the Ministry of Digital Development Alexander Shoytov said on May 18 that they intend to create a "single digital platform" with businesses, where the "Anti-fraud", "Anti-Phishing" and specialized banking systems will be combined.

Although market participants are generally not against this idea, some consider it still insufficiently developed and incomprehensible in terms of the final goal.

One of the scenarios under consideration involves dividing the response to cyber incidents (fraudulent calls, phishing attacks, etc.) between large market participants. Law enforcement agencies will play a more controlling role, which can be expressed both in checking companies for compliance with cybersecurity requirements,and in making decisions on fines for an incident.

Russia already has a number of systems in place to counter cyber threats, such as GosSOPKA, Antifraud, Anti-Phishing, FinCERT, and internal company services. The new platform can become a development of the Antifraud system.

Financial sector companies participating in the dialogue with the Ministry of Digital Development believe that the new platform should be a development of the "Anti-fraud" system. Representatives of Tinkoff Bank call the project "TelecomCert", explaining that market participants will be able to collect information about fraud and analysis of malicious calls (for example, about gray SIM cards). The bank considers it" logical " to tighten the responsibility of operators for passing fraudulent traffic.

Experts consider the creation of such a platform technically feasible, but note the need for a specialized architecture, multi-level data protection and compatibility with existing systems. The main challenge is to protect the platform itself from vulnerabilities.

At the same time, market participants have concerns about excessive centralization of information security and the transfer of control over banking operations to a single center. "We are critical to ensuring that the system eventually becomes a single center through which all banking operations pass, and it decides which ones to allow",- explained in Tinkoff Bank. They doubt that the system built on this principle will be more effective than current banking products for protection.

The Ministry of Digital Development also said that it is discussing the creation of the platform not only with the industry, but also with all interested departments.
 
Top