Home / Blogs

Neelie Kroes, the EU, Cloud Computing, Regulation and Good Ears

Wout de Natris

In her blog EU Commissioner Neelie Kroes blogs on her stance on cloud computing. In short: this is a good development which the EU will embrace and advocate, but may need regulation in order to ensure a safe environment for industry and individuals in the cloud. Here's some thoughts on that.

Risks in the cloud

The cloud is here and to stay. Organisations that outsource IT and data storage are already part of the cloud. They will or at least should be able to ensure their cyber safety and security in the negotiations with the operator providing his services in the cloud. But what if the server in the cloud turns out to physically be in China or another country in which the EU rule of law is not applicable, but was the cheapest your cloud business partner was able to acquire to offer his services? What if this data is harvested or hacked there? What if cyber espionage is inflicted somewhere in the cloud? Doesn't that call the question to mind what sort of data do you want to store out in the cloud and what not? I remember visiting a Ministry in the Netherlands not able to work as all data was inaccessible due to a cable torn somewhere. Nothing was stored locally any more. What are the implications where security and confidential data of an organisation are concerned? This is a question you should have an answer to before moving all out into the cloud. A few dollars savings on IT may prove to be very dear if not handled right.

At least these are business propositions. For consumers there may not be a choice. Their data disappears in the cloud, to where?, how is it protected?, and by which law?

Some problems on regulating the cloud

As most other subjects concerning regulating the Internet a few problems spring to mind:

  • it's cross border, so different jurisdictions;
  • it's commercial, so in fierce competition;
  • sometimes there are perverse incentives to not block cyber crime;
  • regulators/enforcers are national;
  • the EU stops at its last border, the cloud doesn't.
  • Just to name a few.

Two challenges regulating the cloud

1. Cross-border issues – It comes down to daring to tackle the most challenging topic: cross-border jurisdiction. The Internet works with the speed of light, "one finger click", enforcement and regulation proceed slower than a snail. This is in part correct. Investigations need to be thorough and just in order to fine or convict someone. On the other hand investigations need to be aided in a modern way also and not be bogged down by cross-border red tape and hassles. LEAs asking industry to help them avoid MLATs should not be necessary, Mrs. Kroes, but is in fact what happens. A good study of why Microsoft was able to take down the #1 botnet Rustock and LEAs were not, could also be quite revealing.

2. Putting your Good Ears on – The other topic necessary to tackle is learning to listen to what is being said. In public-private partnership meetings industry sometimes gives several reasons why it is hard or impossible to work with LEAs or governments. What is often implied is: we need your help here, governments! Instead of engaging in dialogue, it is often heard said that industry is just putting this front on in order not to act. Well, has this been tested? No, it's usually ignored and things stand as they are. Valuable time is lost. Perhaps even potential partners lost, following the verbal clashes that follow at public events. Listening to industry I hear concerns raised which are not unrealistic or deceitful. With the right ears on they can probably be mitigated. And, should it after all be bogus arguments, it is exposed for what it is.

Public - Private partnership = a partnership

So what I wish Mrs. Kroes and her people, is Good Ears. Undoubtedly this will help change the course of events. After all, a public-private partnership i(mplie)s a partnership, not a one way action on tasks directed at one partner, who takes the brunt, costs and risks involved all in one.

By Wout de Natris, Consultant international cooperation cyber crime + trainer spam enforcement. Visit the blog maintained by Wout de Natris here.

Related topics: Access Providers, Cloud Computing, Cybercrime, Internet Governance, Policy & Regulation, Privacy, Security

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Here's the link to Mrs. Kroes' blog. Wout de Natris  –  Mar 28, 2011 11:52 AM PDT

Here's the link to Mrs. Kroes' blog. Apparently I forget to put it in.

WdN

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Nominum Launches 1st Comprehensive Mobile Security Solution That Protects Both Network and End User

Neustar Names Becky Burr as its Chief Privacy Officer

Frontline and Nominum Deliver Integrated DNS-Based Platform to Enhance Enterprise Security

Nominum Launches Comprehensive Suite of DNS-Based Security Solutions for Russian Service Providers

Nominum Sets New Record for Network Speed and Efficiency

Implementing a Cyber-Security Code of Conduct: Real-Life Lessons From Australia (Webinar)

DDoS Attacks: Top 10 Trends and Truths (Video)

Internet Governance Update: Battle Royale Is Here

DotConnectAfrica Participates at ICANN 43 In Costa Rica, the "Rich Coast"

DDoS Attacks: Top Trends and Truths (Webinar)

Sedari Seeking Certainty in the ICANN TLD Process

"Governments have a role in gTLDs but…" Warns Sophia Bekele

Internet Grows to More Than 225 Million Domain Names in the Fourth Quarter of 2011

Australian ISP iiNet selects ARI Registry Services to Help It Apply for and Operate .iinet TLD

Neustar UltraDNS Basic Launches Add-On Services for Website Monitoring and DNS Server Failover

Neustar And Arbor Networks Cloud Signaling Coalition to Stop Evolving DDoS Threat to Data Centers

Nominum Launches World's First Purpose-Built Suite of DNS‐Based Solutions for Mobile Operators

MarkMonitor Fraud Intelligence Report, Q4 2011

dotMobi And LuxCloud Collaborate on Integration of goMobi Onto LuxCloud SaaS Platform

MarkMonitor to Exhibit at Internet Tech Policy Exhibition and Reception to be Held on Capitol Hill

Hot Topics

Nominum

IPv6

Sponsored by
Nominum
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Afilias

DNS Security

Sponsored by
Afilias
dotMobi

Mobile

Sponsored by
dotMobi
Verisign

Security

Sponsored by
Verisign
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS