September has so far seen two very different events in the international telecommunications sector.First, Germany’s Deutsche Telekom hosted its inaugural Cyber Security Summit. About 70 executives from some of the country’s biggest companies had gathered in Bonn to discuss one of the biggest digital threats to their businesses.And at the same time, Chinese telecommunication companies, ZTE and Huawei, were in the US, defending themselves against allegations that they posed a “security threat” at a House Intelligence Committee hearing in Washington.Huawei’s attempts to expand into the American market have been thwarted by the US government.The company is also viewed with suspicion in Australia, where it was blocked from bidding for contracts on a huge broadband network.

Few companies step forward

Huawei, the world’s second largest telecommunications manufacturer, is not unwelcome everywhere. It recently announced plans to invest 2 billion dollars to expand its research and development division in the UK.

But Howard Schmidt, a former cyber security coordinator in the Obama Administration says the onus is telecommunication manufacturers and operators to prove they are not creating software or hardware that can act as “intelligence gathering device.”

Cloud computing may reduce costs significantly, but it represents more security threats

In February, the Cybersecurity Act of 2012 was presented as America’s attempt to force companies that make IT for essential infrastructure, like smart electricity grids and water supplies, to adhere to certain security standards. But the Act failed to pass in the US senate in August.

“One of the concerns that many of us have about regulation is if you have regulation mandating companies do something, then the company is building products around compliance, not doing what they need to do to be innovative to come up with new products for us,” Schmidt told journalists in Bonn.

Most of those who attended the Cyber Security Summit in Bonn prefer self-regulation.

But they say they do also see the need for transparency. Companies can be reluctant to disclose cyber attacks because they fear it will harm their reputation – as was the case for a major financial institute.

“They had been a victim for two months before they found it,” says Schmidt, “they notified the government, and it took more than 102 days to let other companies know what this company had gone through.”

Getting the public on board 

In some industries, companies withholding information that could help prevent others in their industry from suffering potential damage can face prosecution. But the same is not the case with IT security.

Deutsche Telekom CEO, René Obermann, believes the media is to blame.

“Companies that have suffered a cyber attack [...] are punished twice – once through the attack and then through a loss of reputation because they can be strongly criticized by the public,” says Obermann.

 

source:                      http://www.dw.de/dw/article/0,,16245535,00.html