Today, a lot of communication channels are routed via the internet, services are offered online and applications are only working with access to the internet. What happens if the link to the net is unavailable or at least unreliable? Will Austria come to an immediate stop? Can and should we be prepared for a situation like this? How would this impact the work of the National Crisis- and Catastrophe-Management?
In our private day-to-day life almost all communication uses the internet. A lot of B2B communication is transmitted via the internet as well. An increasing number of applications is hosted in remote data centres instead of local servers. Data is stored in the cloud. Sites and headquarters, production facilities, web shops and logistics, they are all linked via the internet.
The internet has become a critical infrastructure for our society. Due to its network structure, it seems relatively crisis-proof; there have rarely been any long-lasting, large-scale failures so far. This gives the impression of a certain reliability, which has led to more and more connections via the internet. Redundancies or leased lines were often abandoned in favour of increased efficiency. This created a dependence on this network. The consequences of a long-lasting, large-scale unreliability or even a total outage are currently difficult to assess and are being investigated in the new security research project "ISIDOR – Consequences of a long-lasting and large-scale failure of internet-based services and infrastructures" by the Institute of Technology Assessment (ITA) of the Austrian Academy of Sciences (ÖAW) together with the other project partners.
In contrast to studies from the perspective of cybersecurity, which often focus on the period before the occurrence of a damaging event, ISIDOR looks at the period starting after such an event, and therefore deals with the topic in the context of cyber resilience. The aim is to explore which interdependencies and cascading effects one would have to expect in the event of an incident: What happens if all emergency plans are put into effect simultaneously? Will there be supply bottlenecks, and if so, when? In addition, the project tries to answer how the National Crisis- and Catastrophe-Management can prepare for such a situation.
-> In nearly all industries, we depend on the Internet and a operational IT infrastructure for essential work processes.
-> Operators of critical infrastructures must be prepared to deliver their services even when the Internet is unavailable. This includes communication within the organisation and with the state crisis and disaster management authorities.
-> If damage occurs to critical infrastructure, it is called a networked crisis. Among other things, it is characterised by a high level of dynamism, which makes it hard to make reliable predictions about the future course of the crisis. In this case, communication skills and crisis management are clearly more important than strict checklists...
-> In so gut wie allen Branchen sind wir bei wesentlichen
Arbeitsvorgängen auf das Internet, und auf eine funktionierende
IT-Infrastruktur, angewiesen.
-> Die Betreiber Kritischer
Infrastrukturen müssen darauf vorbereitet sein, dass ihre Dienste auch
ohne Internet erbracht werden können. Das schließt Kommunikation
innerhalb der Organisation sowie mit dem Staatlichen Krisen- und
Katastrophenschutzmanagement ein.
-> Kommt es bei der Kritischen
Infrastruktur zu einem Schadensfall spricht man von einer vernetzte
Krise. Sie zeichnet sich u.a. durch eine hohe Dynamik aus, die es
erschwert, seriöse Aussagen über den weiteren Verlauf der Krise zu
treffen. Wichtiger als starre Checklisten sind in diesem Fall eindeutig
Kommunikationsfähigkeit und Krisenmanagement.
Das Forschungsprojekt ISIDOR beschäftigte sich mit der Frage, was passiert, wenndas Internet in Österreich großflächig und für einen längeren Zeitraum ausfällt. Dabeiwurden verschiedene Szenarien betrachtet, von Ausfällen bestimmter Internetdienste, bis hin zu einem Totalausfall. Dem „All Hazards”-Ansatz des Austrian Programme for Critical Infrastructure Protection (APCIP) folgend, standen nicht die Ursachen eines derartigen Ausfalls und deren Vermeidung im Fokus des Projekts, sondern das Augenmerk wurde auf den Bereich Cyber-Resilience gerichtet. Dabei galtes herauszufinden, wie sich die Lage nach einem Schadensfall entwickeln könnte,und wie die dadurch ausgelöste Krise bestmöglich gelöst werden könnte.
Krieger-Lamina, J. (Speaker)
Krieger-Lamina, J. (Speaker)
Konicar, G. (Speaker) & Krieger-Lamina, J. (Speaker)
Krieger-Lamina, J. (Speaker)