ASECAP’S COPER III
TASK FORCE ON
CYBERSECURITY
MASSIMILIANO MASI
<mmasi@autostrade
.it>
AUTOSTRADE PER
L’ITALIA
11-10-2023 TASK FORCE CYBERSECURITY 2
THE TASK FORCE
• Cybersecurity is a key aspect of the
everyday life of citizens
Most industrial activities underwent the
digital transformation
• The Road Transportation sector is not
yet mature
No common understanding on what to
protect
No common guidance on how to protect
No common method to respond to
incidents
A Cybersecurity Task Force has been
launched in ASECAP under the COPER
III initially to represent the
stakeholder sector with ENISA
11-10-2023 TASK FORCE CYBERSECURITY 3
THE LEGAL CONTEXT
• The EU commission regulate sectors
with High Criticality with the NIS 2
Directive (EU 2022/2555)
Road Authorities are mentioned in Annex
I
• The NIS 2 directive must be
implemented by each member state
• Other sectors already adopted
cybersecurity countermeasures to
fulfil the NIS requirements
11-10-2023 TASK FORCE CYBERSECURITY 4
THE ASECAP TASK FORCE
QUESTIONNAIRE
Divided in four parts
• Part 1: to discover which
NIS-digital services are
operated and how the
member states regulated
them
• Part 2: to discover the
status of the cybersecurity
governance of the
associates (ISMS, CSMS)
• Part 3: to discover the
cybersecurity organization
of the associates
• Part 4: to discover the
international activities
ongoing
Innovation Activities
• Activity 1:
Stocktaking the
existent MS
regulations and
provide a guideline
• Activity 2: initiate a
standardization
effort to as other
sectors
• Activity 3:
cybersecurity is
scarce. Provide a set
of curricula to have
good candidates
• Part 4: Engagement
international bodies
Received answers from 8 ASECAP members
representing around 40 companies
11-10-2023 TASK FORCE CYBERSECURITY 5
MAIN FINDINGS
• ASECAP members operate services with high
criticality falling under the NIS 2 definition
(e.g., Traffic Management, ITS)
• 2/8 EU member states adopted specific
regulations
• Only 3 companies operates a certified
governance (Information Security
Management System)
• Few companies have a CISO and run a Cyber
Risk Assessment
• 5/9 ASECAP members want to join the task
force to increase their cybersecurity
posture in a harmonized way among the
concessionaries and engaging in
international activities
6
THANK YOU
• Massimiliano Masi -
mmasi@autostrade.it
• +393420001300
• Joint work with Lara
Malfatti and Fabrizio
Paoletti

More Related Content

PDF
European priorities in information security
PDF
Cybersecurity isaca
PPTX
Pecific pac34-Slidedeck-v1-For-Website.pptx
PPTX
NIS 2 and details about implementation - WatchGuard
PPTX
Roberto Reale - Governing Information Security
PPTX
Governing Information Security
PPT
CTO-CybersecurityForum-2010-Andrea Gloriso
PDF
North European Cybersecurity Cluster - an example of the regional trust platf...
European priorities in information security
Cybersecurity isaca
Pecific pac34-Slidedeck-v1-For-Website.pptx
NIS 2 and details about implementation - WatchGuard
Roberto Reale - Governing Information Security
Governing Information Security
CTO-CybersecurityForum-2010-Andrea Gloriso
North European Cybersecurity Cluster - an example of the regional trust platf...

Similar to Cybersecurity Task Force at ASECAP Days 2023 (20)

PPTX
Cybercrime Risks Eu
PDF
Protecting Europe's Network Infrastructure
PPTX
National cyber security policy final
PDF
EU and you - EU and You: Upcoming regulation
PPTX
Presentation on EU Directives Impacting Cyber Security for Information Securi...
PDF
NIS2 Compliance for MSPs: Roadmap, Benefits & Cybersecurity Trends (2025 Guide)
PDF
Cyberwatching - Niccolo Zazzeri
PDF
Scot Secure 2019 Edinburgh (Day 1)
PDF
EUACM Cybersecurity White Paper
PDF
European Cybersecurity Context
PDF
Cyber Security Strategies and Approaches
PDF
PDF
DACHNUG50 BigFix NIS2.pdf
PDF
002-MAVIS - International agreements to combat electronic crimes
PDF
SC7 Workshop 3: Enhancing cyber defence of cyber space systems
PDF
Enterprise Security Architecture for Cyber Security
PDF
Rombit LSEC IoTSecurity IoTSBOM CyberSec Europe 2022
PDF
PPTX
Cybersecurity
PDF
CTO Cybersecurity Forum 2013 Mario Maniewicz
Cybercrime Risks Eu
Protecting Europe's Network Infrastructure
National cyber security policy final
EU and you - EU and You: Upcoming regulation
Presentation on EU Directives Impacting Cyber Security for Information Securi...
NIS2 Compliance for MSPs: Roadmap, Benefits & Cybersecurity Trends (2025 Guide)
Cyberwatching - Niccolo Zazzeri
Scot Secure 2019 Edinburgh (Day 1)
EUACM Cybersecurity White Paper
European Cybersecurity Context
Cyber Security Strategies and Approaches
DACHNUG50 BigFix NIS2.pdf
002-MAVIS - International agreements to combat electronic crimes
SC7 Workshop 3: Enhancing cyber defence of cyber space systems
Enterprise Security Architecture for Cyber Security
Rombit LSEC IoTSecurity IoTSBOM CyberSec Europe 2022
Cybersecurity
CTO Cybersecurity Forum 2013 Mario Maniewicz
Ad

More from Massimiliano Masi (18)

PPTX
Securing Critical Infrastructures with a cybersecurity digital twin
PPTX
A Cybersecurity Digital Twin for Critical Infrastructure Protection
PDF
Enabling a Zero Trust Architecture in Smart Grids through a Digital Twin
PDF
Security and Safety by Design in the Internet of Actors an Architectural Appr...
PDF
Achieving Interoperability Through IHE
PDF
Securing Mobile e-Health Environments by Design: A Holistic Architectural App...
PDF
Enabling Security-by-design in Smart Grids: An architecture-based approach
PPTX
Corso IFTS CyberSecurity Expert - Attacco di Armando e Operazione Black Tulip
PPTX
Corso IFTS CyberSecurity Expert - Creazione di una CA con OpenSSL
PPTX
Corso IFTS CyberSecurity Expert - Cifrai Asimmetrici
PPTX
Corso IFTS CyberSecurity Expert
PPTX
The need for interoperability in blockchain-based initiatives to facilitate c...
PDF
Blockchain Technology - Common Use-Cases
PDF
Automating Smart Grid Solution Architecture Design
PDF
Introduction to Blockchain Technologies
PPTX
eHealth 2018 http://www.ehealth20xx.at/program-blockchain/
PPTX
A governance model for ubiquitous medical devices accessing eHealth data: the...
PPTX
Addressing Security and Provide through IHE Profiles
Securing Critical Infrastructures with a cybersecurity digital twin
A Cybersecurity Digital Twin for Critical Infrastructure Protection
Enabling a Zero Trust Architecture in Smart Grids through a Digital Twin
Security and Safety by Design in the Internet of Actors an Architectural Appr...
Achieving Interoperability Through IHE
Securing Mobile e-Health Environments by Design: A Holistic Architectural App...
Enabling Security-by-design in Smart Grids: An architecture-based approach
Corso IFTS CyberSecurity Expert - Attacco di Armando e Operazione Black Tulip
Corso IFTS CyberSecurity Expert - Creazione di una CA con OpenSSL
Corso IFTS CyberSecurity Expert - Cifrai Asimmetrici
Corso IFTS CyberSecurity Expert
The need for interoperability in blockchain-based initiatives to facilitate c...
Blockchain Technology - Common Use-Cases
Automating Smart Grid Solution Architecture Design
Introduction to Blockchain Technologies
eHealth 2018 http://www.ehealth20xx.at/program-blockchain/
A governance model for ubiquitous medical devices accessing eHealth data: the...
Addressing Security and Provide through IHE Profiles
Ad

Recently uploaded (20)

PPT
250152213-Excitation-SystemWERRT (1).ppt
PPTX
Database Information System - Management Information System
PPTX
Cyber Hygine IN organizations in MSME or
PDF
mera desh ae watn.(a source of motivation and patriotism to the youth of the ...
PPTX
Top Website Bugs That Hurt User Experience – And How Expert Web Design Fixes
PDF
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
PPT
12 Things That Make People Trust a Website Instantly
PPTX
Internet Safety for Seniors presentation
PDF
Alethe Consulting Corporate Profile and Solution Aproach
PDF
Lean-Manufacturing-Tools-Techniques-and-How-To-Use-Them.pdf
PPTX
AI_Cyberattack_Solutions AI AI AI AI .pptx
PPTX
t_and_OpenAI_Combined_two_pressentations
PPT
Ethics in Information System - Management Information System
PDF
simpleintnettestmetiaerl for the simple testint
PPT
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
PDF
The Evolution of Traditional to New Media .pdf
PDF
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf
PPTX
1402_iCSC_-_RESTful_Web_APIs_--_Josef_Hammer.pptx
PPTX
curriculumandpedagogyinearlychildhoodcurriculum-171021103104 - Copy.pptx
DOCX
Powerful Ways AIRCONNECT INFOSYSTEMS Pvt Ltd Enhances IT Infrastructure in In...
250152213-Excitation-SystemWERRT (1).ppt
Database Information System - Management Information System
Cyber Hygine IN organizations in MSME or
mera desh ae watn.(a source of motivation and patriotism to the youth of the ...
Top Website Bugs That Hurt User Experience – And How Expert Web Design Fixes
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
12 Things That Make People Trust a Website Instantly
Internet Safety for Seniors presentation
Alethe Consulting Corporate Profile and Solution Aproach
Lean-Manufacturing-Tools-Techniques-and-How-To-Use-Them.pdf
AI_Cyberattack_Solutions AI AI AI AI .pptx
t_and_OpenAI_Combined_two_pressentations
Ethics in Information System - Management Information System
simpleintnettestmetiaerl for the simple testint
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
The Evolution of Traditional to New Media .pdf
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf
1402_iCSC_-_RESTful_Web_APIs_--_Josef_Hammer.pptx
curriculumandpedagogyinearlychildhoodcurriculum-171021103104 - Copy.pptx
Powerful Ways AIRCONNECT INFOSYSTEMS Pvt Ltd Enhances IT Infrastructure in In...

Cybersecurity Task Force at ASECAP Days 2023

  • 1. ASECAP’S COPER III TASK FORCE ON CYBERSECURITY MASSIMILIANO MASI <mmasi@autostrade .it> AUTOSTRADE PER L’ITALIA
  • 2. 11-10-2023 TASK FORCE CYBERSECURITY 2 THE TASK FORCE • Cybersecurity is a key aspect of the everyday life of citizens Most industrial activities underwent the digital transformation • The Road Transportation sector is not yet mature No common understanding on what to protect No common guidance on how to protect No common method to respond to incidents A Cybersecurity Task Force has been launched in ASECAP under the COPER III initially to represent the stakeholder sector with ENISA
  • 3. 11-10-2023 TASK FORCE CYBERSECURITY 3 THE LEGAL CONTEXT • The EU commission regulate sectors with High Criticality with the NIS 2 Directive (EU 2022/2555) Road Authorities are mentioned in Annex I • The NIS 2 directive must be implemented by each member state • Other sectors already adopted cybersecurity countermeasures to fulfil the NIS requirements
  • 4. 11-10-2023 TASK FORCE CYBERSECURITY 4 THE ASECAP TASK FORCE QUESTIONNAIRE Divided in four parts • Part 1: to discover which NIS-digital services are operated and how the member states regulated them • Part 2: to discover the status of the cybersecurity governance of the associates (ISMS, CSMS) • Part 3: to discover the cybersecurity organization of the associates • Part 4: to discover the international activities ongoing Innovation Activities • Activity 1: Stocktaking the existent MS regulations and provide a guideline • Activity 2: initiate a standardization effort to as other sectors • Activity 3: cybersecurity is scarce. Provide a set of curricula to have good candidates • Part 4: Engagement international bodies Received answers from 8 ASECAP members representing around 40 companies
  • 5. 11-10-2023 TASK FORCE CYBERSECURITY 5 MAIN FINDINGS • ASECAP members operate services with high criticality falling under the NIS 2 definition (e.g., Traffic Management, ITS) • 2/8 EU member states adopted specific regulations • Only 3 companies operates a certified governance (Information Security Management System) • Few companies have a CISO and run a Cyber Risk Assessment • 5/9 ASECAP members want to join the task force to increase their cybersecurity posture in a harmonized way among the concessionaries and engaging in international activities
  • 6. 6 THANK YOU • Massimiliano Masi - mmasi@autostrade.it • +393420001300 • Joint work with Lara Malfatti and Fabrizio Paoletti