Cyber security

IDA has eight recommendations for improving cyber security and proposes the establishment of a civil cyber security council. Furthermore, IDA is a member of the Business Partnership for Enhanced IT Security in the Business Sector.

Denmark is one of the most digitised countries in the world, which in itself makes us particularly vulnerable unless we are also the most IT-secure country. And, unfortunately, we are not.

According to the UN’s Global Cybersecurity Index 2017, Denmark ranks only 34th out of 193 countries in terms of cyber and information security. This is highly problematic and very worrying.

Public confidence and trust in digitalisation are at serious risk if we cannot assure citizens and consumers that cyber and information security in Denmark is of the very highest standard.

Without that trust and confidence, the potential of technology and digitalisation will never be realised.

Eight recommendations from IDA

IDA believes that cyber and information security – including knowledge, skills, preparedness, legislation, etc. – should be a top priority for our elected representatives, public authorities and private companies alike. Specifically, IDA recommends that Denmark should:

  • Establish a definition of Denmark’s critical infrastructure
  • Introduce legislation governing software manufacturers’ product requirements
  • Impose penalties on private companies for ‘negligent handling of data’
  • Establish an accident investigation commission for cyber and information security incidents
  • Significantly strengthen the Danish Data Protection Agency – and equip it with technical expertise
  • Ensure training in the field of cyber and information security – and make this lifelong
  • Improve email security
  • Explore the possibility of replacing CPR numbers with a better and more secure means of identifying citizens

IDA participates in a business partnership

IDA is a member of the Business Partnership for Enhanced IT Security in the Danish Business Sector, under the Danish Business Authority.

The Business Partnership is a new partnership, formed on the basis of the national strategy for cyber and information security from May 2018, which states that a Business Partnership for enhanced IT security in the Danish business sector is to be established.

The Business Partnership is intended to provide a framework for a joint effort to promote IT security and responsible data management, particularly in small and medium-sized enterprises, and to develop joint solutions to cross-cutting issues.

Among other things, the Business Partnership has helped to launch sikkerdigital.dk and will launch further projects during 2019 to build bridges between businesses, public authorities and experts in IT and cyber security.

Establish a cyber security council

IDA believes that Denmark should establish a civilian cyber security council based on the Dutch model. 

In Denmark, responsibility for the country’s cyber security is fragmented. The Centre for Cyber Security under the Ministry of Defence handles part of the task.

PET, under the Ministry of Justice, handles other aspects. The Danish Data Protection Agency deals with yet another aspect. And private companies and citizens/consumers do what they can to protect themselves.

The Centre for Cyber Security has some bodies for cooperation and coordination across ministries and private companies, but these are far from sufficient.

Firstly, these bodies do not meet nearly often enough; and secondly, they lack a genuine mandate and therefore have no significant influence. 

In the Netherlands, it has been recognised that the cyber security threat must not be tackled in silos. It must be tackled through a binding collaboration between public authorities, private companies and the research community.

Consequently, the so-called Cyber Security Raad has been established; this is a national, independent advisory body on cyber security that assists both the Dutch government and Dutch private companies.

The Council comprises a total of 18 ‘high-ranking’ individuals, including seven from the public sector, seven from the private sector and four from the research community.

They meet weekly to, amongst other things:

  • provide strategic advice to the government and private companies
  • monitor trends and new technologies with a view to highlighting their potential for reducing the cyber security threat
  • initiate and accelerate various initiatives in both the Netherlands and the EU that can improve the Netherlands’ cyber security defences.