The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Threat Talks
Threat Talks artwork

Europe Is Losing the Sea Cable Race

Threat Talks · 2026-06-09 · 35 min

0:00--:--

Key moments - from our scoring

Substance score

56 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality10 / 20
Guest Caliber14 / 20
Specificity & Evidence9 / 20
Conversational Craft12 / 20

The conversation between Peter Vessey and Ernst Noorman examines Europe's shifting position in global submarine cable infrastructure and what digital sovereignty actually means in practice. While the classic transatlantic cable architecture is being redrawn - with new cables routing directly from Latin America to Asia and Africa - Noorman cautions against panic. Instead, he frames the challenge as one of deliberate investment and strategic capability-building, pointing to Singapore's disciplined approach (32 active landings, zero cable faults in five years, mandatory green energy integration) as a model. The real issue isn't connectivity itself but autonomy: Europe's ability to choose providers and avoid vendor lock-in from hyperscale cloud providers. Noorman highlights Europe's existing strengths - ASML in chipmaking, Nokia and Ericsson in telecom, emerging cloud consortiums, and the Schwarz Group's cloud investments - while acknowledging the hard truth that digital autonomy comes at higher cost than always choosing the cheapest option. The discussion ties this to regulatory momentum: the Cyber Resilience Act (mandatory security-by-design for hardware and software), NIS2 directive (personal board liability), and government initiatives like SEF funding and IPCEI projects. The conversation stresses that compliance alone is insufficient; boards and CISOs must engage in genuine risk dialogue rather than checkbox ticking.

Key takeaways

  • →Europe's loss of relative position in new submarine cable landings reflects big tech's investment in their own data centers and AI infrastructure rather than Europe's declining importance, and addressing this requires strategic public-private investment rather than panic.
  • →Digital autonomy - the freedom to choose vendors and avoid dependency on any single hyperscaler - is the practical goal, distinct from the protectionist language of sovereignty that China uses, and Europe already controls crucial parts of the technology stack including ASML, Nokia, and Ericsson.
  • →The Cyber Resilience Act will force hardware and software makers to implement security-by-design and bear liability for unsafe products, fundamentally shifting incentives across the industry and potentially becoming a global standard for anyone selling into Europe.
  • →Board-level cybersecurity governance must move beyond compliance checkbox ticking to genuine strategic conversations between CISOs and leadership about real risks, incidents, and solutions, informed by resources like the Dutch Cyber Security Council's manual for CEOs.
  • →Higher cost for autonomy and safety is unavoidable and acceptable - similar to defense spending or product safety in other industries - because cheaper products without security accountability have created the infrastructure vulnerabilities Europe now faces.

Guests

Ernst Noorman

Topics in this episode

ASMLPublic-private partnershipsSubmarine cable infrastructureDigital autonomy and digital sovereigntyITU Advisory Board on Submarine Cable ResilienceCyber Resilience ActNIS2 directiveNokia and EricssonSingapore's cable and data center policyEuropean Commission SEF funding and IPCEI projects

Questions this episode answers

What are the 40 new sea cables launching in 2026 and why do most not land in Europe?

The cables are being built primarily by big tech companies (hyperscalers) routing them to their new data centers and AI factory locations in Asia, Latin America, and Africa - regions that were previously underserved. This reflects investment patterns following where companies need direct connectivity, not declining European importance.

What is Singapore doing differently with submarine cable policy compared to Europe?

Singapore has paused investments to restructure how companies submit proposals; they now require holistic plans including green energy integration, not just data center requests. Singapore has 32 active cable landings, 10 in pipeline, zero faults in five years (cables buried 5-12 meters), strict ship anchor regulations, and a 10-year ambition for 10 more cables.

What does the ITU Advisory Board on Submarine Cable Resilience actually do?

Established in 2024 with a two-year mandate, it focuses on three areas: identifying threats to cable resilience, improving repair efficiency and effectiveness, and ensuring redundancy and connectivity worldwide. It will deliver recommendations to ITU member states.

How does the Cyber Resilience Act change product liability for software and hardware companies?

It mandates security-by-design from product inception and makes companies liable if their products are unsafe - similar to liability for cars, medications, or toys. This shifts from the current 'free for all' approach where software is rarely held accountable.

What is the difference between digital sovereignty and digital autonomy as Ernst Noorman uses the terms?

Autonomy means freedom of choice among vendors and avoiding lock-in, which appeals to market principles and American companies. Sovereignty implies data control and protection from foreign government interference, language Noorman says can sound protectionist; he prefers autonomy to describe Europe's goals.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode covers substantive geopolitical and policy topics (sea cables, digital sovereignty, EU regulatory frameworks) but relies heavily on general statements and strategic abstractions rather than specific, actionable insights. While Ernst Noorman discusses important concepts like the ITU Advisory Board and Cyber Resilience Act, concrete operational insights for B2B practitioners remain limited. The discussion of Singapore's green energy requirement for cable proposals and the Cyber Resilience Act manual for CEOs provide some useful texture, but much of the content is high-level positioning.

40 new sea cables will go live. Most of those will not land in Europe.
Singapore is incredibly connected. They have 32 cable landings. They have ten in the pipeline and have an ambition for another ten in next ten years.

Originality

10 / 20

The framing of Europe's position in sea cable infrastructure and digital autonomy versus sovereignty is competent but conventional. The episode reiterates standard EU policy messaging (digital autonomy, Cyber Resilience Act, public-private partnerships) without offering contrarian takes or first-principles analysis. The comparison to Singapore's governance is somewhat fresh, but the broader thesis - that Europe needs to invest more in digital infrastructure and confidence - is well-established EU discourse. Few genuinely surprising or counterintuitive claims emerge.

Europe doesn't seem to be that hot anymore when it comes to to sea cables.
We have to believe in ourselves. And I think we can create a hell of a lot more than we're doing right now.

Guest Caliber

14 / 20

Ernst Noorman holds relevant institutional roles: cyber ambassador at large for the Netherlands and member of the ITU Advisory Board for subsea cables. He brings direct policymaking exposure and cross-border diplomatic experience. However, he is primarily a policy-level operator rather than a practitioner who has built operational digital infrastructure or managed large-scale cybersecurity programs at a company. His insight is valuable for policy strategy but lacks the ground-truth perspective of someone who has executed at scale in the private sector.

Ernst Noorman, cyber ambassador at large for the Netherlands and member of the ITU Advisory Board for subsea cables
I'm happy we have a deputy minister now for digital sovereignty.

Specificity & Evidence

9 / 20

The episode lacks concrete numbers, timelines, and case studies that would allow a B2B operator to extract actionable specifics. While some data points appear (Singapore's 32 cable landings, the 40 cables launching in 2026, cables buried 5-12m underwater), most claims remain abstract. The discussion of ASML, Mistral, and Schwarz Group investing in cloud is vague, and no financial figures, ROI data, or implementation timelines are provided. The manual for CEOs is mentioned but not detailed.

In 2026, 40 new sea cables will go live.
Singapore has 32 cable landings. They have ten in the pipeline and have an ambition for another ten in next ten years.

Conversational Craft

12 / 20

The host (Peter) demonstrates solid technical knowledge and asks reasonable follow-up questions, pushing on the sovereignty/autonomy distinction and challenging Ernst on whether Europe should offer tax incentives. However, the conversation rarely becomes truly challenging or adversarial. Ernst's responses are frequently long, meandering, and somewhat unchecked by sharp follow-ups. The host misses opportunities to probe deeper into contradictions (e.g., if sea cables are vital, why hasn't the Netherlands secured more?). Questions tend toward confirmatory rather than skeptical.

Would you see that as an option in Europe at all, that the European government and or national governments would give tax cuts
I'm sort of testing a little bit because it's complicated stuff. The technology is really complicated.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

europe34digital18sovereignty18cables17course16netherlands15choice15data14european14cable13cybersecurity11important11infrastructure11connectivity11discussion11sense11

Episode notes

In 2026, 40 new submarine cables go live. Most won't land in Europe. Europe is losing the sea cable race, and most people haven't noticed yet. In this second part of our sea cables conversation, host Peter Ernst sits down with Ernst Noorman, the Netherlands' Cyber Ambassador-at-Large and a member of the ITU Advisory Body on Submarine Cable Resilience, to move from the “how” of sea cables to the “why it matters.” We compare two places that were once called the two hardest spots in the world to build digital infrastructure, Amsterdam and Singapore, and unpack how Singapore solved its crunch with 32 cable landings, five years of zero cable faults, and a green-energy-first tender process, while the Netherlands risks resting on a 30-year-old head start. Along the way: the difference between sovereignty and autonomy, why “always the cheapest option” no longer works, the EU Cyber Resilience Act and security by design, what NIS2 means for boards and CEOs personally, and why Europe needs to stop being modest about Airbus-sized wins.

Full transcript

35 min

Transcribed and scored by The B2B Podcast Index.

In 2026, 40 new sea cables will go live. Most of those will not land in Europe. What does that mean for Europe's digital sovereignty? Welcome to Threat Talks.

Welcome to Threat Talks. Let's delve deep into the dynamic world of cybersecurity. Last time, we covered a lot about the technology of sea cables and why sea cables are important in our infrastructure. This time, we'll go more into why it matters.

What does it matter to Europe? What does it matter to the Netherlands? What about sovereignty? We're here with Ernst Noorman, cyber ambassador at large for the Netherlands and member of the ITU Advisory Board for subsea cables, subsea infrastructure.

Ernst, again just slightly minor towards the last episode. Can you give a one minute speech on what the advisory board does and why it matters? Sure. And great to be again, Peter, in this.

Great to have you. And talk about this interesting topic and indeed deserves more talk about it. But the advisory body on submarine cable resilience touches on three main topics, and that is on the threats. What is, you know, threatening the resilience of the cables, how to repair it more efficiently and more effectively, and how to ensure more redundancy and connectivity around the world.

Okay. And it's relatively new, right? It started in 2024. But it's also- It’s also a limited mandate of only two years.

Okay. And why is that? It's just given the task, okay, come up with recommendations, for the ITU members. the oldest international organization in the world, by the way, give recommendation on this submarine cable resilience and come out with the report.

And once the report is there, it will be a discussion maybe on a future how to give a follow up, how to monitor this report. But the mandate right now is for two years. And it's also about the sense of urgency I guess then because yeah, they want to have that report fast. Okay.

So I think you could argue that the sea cable map is being redrawn almost. So a lot of the infrastructure, if you look at some of the maps, you'll see this sort of classic N shape going up into North America, crossing the Atlantic Europe and then down into Africa or Asia. A lot of that is being redrawn, with infrastructure being put directly from Latin America to Asia, Africa, etc.. So Europe doesn't seem to be that hot anymore when it comes to to sea cables.

What's your view on that? I wouldn't put it that negatively. We still are very well connected as Europe. Of course.

So that's the main point. And of course, what you see is right now that the big tech are investing, are the major investors in new cables, and they decide where the new cables will be laid. And they especially do that to those locations where they have their own new data centers, AI factories where they really need need direct linkages with their cables. So that means we have to really work also to ensure that the connectivity of Europe will be ensured and secured for the future.

And right now, you do see indeed that lots of new cables go to Asia. But it's also, you know, a lot of parts of that world were also underserved before. They’re catching up. So it's not only bad news.

One of the objectives of the advisory body is to ensure better connectivity with those parts of the world which were not connected, or sometimes solely connect to one cable. Yeah, the scope is global. The scope is not Europe or the Atlantic. And another thing, some of the arguments I sometimes have, or when we talk about this, is the leading position we have in Europe and in the Netherlands specifically, is also because of the investments and sort of the visionary view of some people 30 years ago, 25 years ago and starting to invest now.

It seems like that's challenging today. Some other countries in Europe are investing more than the Netherlands maybe, sometimes in data centers. Not all of them have sea cables. Some of them are landlocked.

But there was also an argument 2 or 3 years ago that actually there were two bad places in the world to go to. It was the Netherlands and Singapore, but Singapore seems to have solved that, and the Netherlands maybe not so. So can we talk about so what does that mean for Singapore or what does it mean for the Netherlands? Because on the one hand you say, well, it's actually a good thing some of these countries being a little bit behind, underserved, coming up.

But should I be worried as a Dutch person or European about this development in the digital space? Of course, you are responsible for AMS-IX, I mean, you want to... I’m trying. You're trying hard to be as connected as possible.

So I fully understand. And just looking back at our history, we were of course, within Europe, we were the first connected with the internet- The first email out of the US coming into Amsterdam. Yeah. But also within Europe from CERN, the center in Geneva to Amsterdam.

That was the first connectivity and we built up a strong infrastructure thanks also to internet exchange like AMS-IX strong infrastructure in the Netherlands. And we were leading also in the thinking about the digital ecosystem in cyber. So and also with academics really being involved in thinking about what does it mean, cybersecurity, digital freedoms, how to ensure that, how to keep the internet open, secure and safe. But that doesn't mean we will keep that just automatically.

We have to invest in it. [ ] one you can only lose. You could argue. Absolutely.

And so we have to keep on investing. In that sense. I'm happy we have a deputy minister now for digital sovereignty. And I understand she really understand the topic.

So she will be on the forefront also within Europe and to really promote our agenda on the digital sovereignty and connectivity. But we need investments of course. And I know we as the Netherlands are the great public private partnership in that I'm also really happy with the Subsidy Coalition, a private sector coalition to really promote the interests of the Netherlands economy in the matters of digital connectivity and submarine cables especially. But now, if I jump to Singapore, Singapore told me I just had a meeting with them in January on the submarine cables and data.

Yes, indeed, we had for about half a year that we said, okay, we stop with new investments and then we changed the way the companies can put in, submit their proposals. And now they have to submit a full proposals including green energy. Okay. So it's not that they put in a data centers and then they can ask for connectivity.

They have to come up with a green energy proposal. So it's much more holistic then, Holistic approach in that sense. And Singapore is incredibly connected. I never realized that actually, they have 32 cable landings.

They have ten in the pipeline and have an ambition for another ten in next ten years. Okay. And there is security on cable. Security is incredible.

The past five years, zero cable faults and their cables are 5 to 12m under under the seabed. And ships are not allowed to come close with the anchors. So no faults in that sense. So digital is really important to them.

So it shows what kind of role they want to play in the region. They want to be a hub for the connectivity. Yeah. I also remember I'm not sure which time frame exactly, but I remember many years ago they actually provided tax cuts to companies that would invest in cloud back in the day and come to Singapore, which is one way of them actually becoming a major hub in the region.

They are the hub in Southeast Asia with indeed the most connections and data as well. Would you and this is maybe more as a diplomat maybe diplomatic answer also. But would you see that as an option in Europe at all, that the European government and or national governments would give tax cuts, that it's so important that we actually give tax benefits to companies that would invest in digital, whether it's sea cable or other other digital assets? Well, that's indeed like you said, I'm a diplomat.

I'm not working for the minister- Not that I wanna put you on the spot, but I want to put you on the spot. Minister of finance. But it's more important. I mean, companies will not invest only with the tax cuts.

They want to see what is there. Of course there needs to be a result. What is the future? What do they expect as returns?

And there you see that we are really looking now how to secure our digital sovereignty. I prefer autonomy because the point is we want to have choice and we don't have choice right now. We are dependent also in data centers often on the big techs companies. But you see right now developments we just saw in the news that nine companies in the Netherlands are putting a proposal together for cloud.

As a cloud providers. You see that the family behind Lidl, the Schwarz Group family’s investing in cloud. So suddenly you see a lot of developments, ASML investing in Mistral in France. So we have to believe in ourselves.

And I think we can create a hell of a lot more than we're doing right now. And we already have a very strong ecosystem of small companies who have a strong potential, but we have to see how they can scale up. And then you will see also the connectivity will come, and Europe has put it on the agenda to invest in connectivity. So I think I agree.

So what you're saying is that actually we're too modest. We need to shrug off some of this modesty and be a bit more brazen about the good things we're doing and the wins we're seeing and actually the technology we're developing, etc.. That's what you see in the US. There are absolutely salespersons selling, even though sometimes it's not as big as a they may tell and we should be stronger in being believing in ourselves.

You know the cliche example’s always Airbus. But we created Airbus as Europe which is doing better than Boeing right now. So why not in the other industries. And so the Netherlands is quite known for the public private cooperation.

And I think a lot of other countries are looking at us as well in that sense. So again, from your role, we have the sea cable coalition, you mentioned that, there's something on AI. There's 1 or 2 others. Is this something where we should have more public private cooperation, and then we may be able to get that done in the Netherlands.

But how do you look at Europe? Would we be able to do that on a European scale, to promote more the abilities we have and create maybe the new Airbus, but then on digital sovereignty or autonomy? You already see that happening. A lot more corporation at European level.

I mean, in the AI sector, there already is a lot of initiatives and working together but can be stronger. But the European Commission is also really working hard on that. Also on the submarine cables to include, to involve private sector in strengthening our connectivity through European initiatives. And those are, does that include things like the SEF funding or the IPCEI projects?

Those are the things, the means they put in place to.. And, you know, you can say okay to small or maybe a first step, but, you know, it shows that it's on the agenda and that we really come to realize the importance and again, with more self-confidence, and we can do something. And then if we also tie it back a little bit to our earlier discussion about the sea cable infrastructure and some of the technology related to that. And of course, it's not just the sea cable, as you said last time, it's also the data centers and cloud infrastructure and what have you.

But the words sovereignty and autonomy, those are the words currently. And I think again, you said, at least in my opinion, real... you said it right in that sovereignty is about choice. It's about sort of not being punished if you choose to do something else.

To have that free choice. However, is that, in light of this discussion, is that more a political thing or maybe almost a marketing thing for companies? Because it's not just saying, oh, we want to be sovereign, so we have a choice. There's a lot of technology that sits underneath that we need to quote unquote fix as well or organize.

So, so again, when we work sort of our way up from the sea cable, what needs to happen for companies, for example, to be able to have that choice and not be locked into one particular vendor or one particular hyperscale type cloud? That needs an approach, indeed. First of all, European wide that we want, I prefer the word autonomy and digital autonomy to the [ ] choice. And if I tell this to American companies, big tech.

Recently I was in San Francisco with the RSA, the biggest cybersecurity conference. And if you tell me we want to have choice, they will understand. Of course you want to have choice. And then you say, well, this was why we're going to invest in our own capability.

Yeah. They understand. I mean, it's hard for them to say something else, because that's the market we want to create. So in that sense, you know, we really work on that, on data, you can say more on sovereignty because you want to protect the data and ensure that there's no involvement from other countries in your data.

I mean, we of course have a lot of discussion right now in parliament in civil society in the press, rightly so, because it's so important to protect your own data. Yeah. And before we go on, because we talk about sovereignty and autonomy. So again, sovereignty, we said, well, that's really the freedom of choice almost, almost, that's the freedom of choice.

Yeah. Okay. So you say so if that's autonomy, what's then sovereignty? Sovereignty, that's where you really protect your data and you want to have control over your data and not have the threat that another country can take over the control of your data.

It's funny because I would actually flip that. I would personally say sovereignty is about I have a sovereign choice to make. I'm independent and but it's a.. that's why it's important to have these types of discussions.

So we can agree [ ] I prefer, you know, China always uses the word sovereign. Sovereignty. Yeah. And we say no, we want a more open society and autonomic choice.

It doesn't mean that we want to exclude American vendors, but we want to have a choice also for European ones. Now to one of the things which you mentioned is or referred to is more or less the whole stack of technology. We will never be able, on the short term, on the mid-term to create, to control the whole stack in Europe. But we have crucial parts of the stack already.

ASML, for instance, is a part of the stack, but also Nokia and Ericsson are part of the stack, which the US is really needing, for instance. And they also need ASML. So we already control parts of the stack, but we want to control also other parts to a certain extent at least. And we have to develop that.

So in that sense we have to invest in other parts of the whole stack to at least be stronger in our options towards other market forces. And then, well, we're both Dutch and internationally we're also seen as cheap therefore, we always want the lowest price. Is sovereignty and autonomy, does that come with a different price? And do we need to really start to realize that always choosing the cheaper option has gotten us where we are, but may not be the best choice going forward?

Absolutely. You see that in broad discussion now with the whole geopolitical tensions. You know, we want to have more in that sense sovereignty in Europe, that we want to make sure that we produce a lot of essential critical products, but that comes at a price. Also, to build up a defense industry comes at a price.

It’s not cheap. It's not cheap. But by the way, the US is not cheap right now too, I mean, in that sense, it's good that we also create our own infrastructure. But that means investing.

That means that you especially in the beginning, the cost price will be higher. And the same applies with digital autonomy. We have to be willing to invest and look at quality and not necessarily at first at the price. Of course, it's a balance, price and quality, but not only looking at the price to see what you get.

Yeah, and again in the last episode, we also talked to a little bit about what that means for companies and for company directors and boards. And we talked about NIS2 having an effect and new cyber acts where boards and CEOs are becoming almost personally liable for taking care of this, so that then also applies for companies. So they also need to look at their budgets and not sort of wave it off to the IT guy or girl, but actually realize as a board, I'm now on the hook to make sure that my digital assets are safe.

I understand what I need in terms of digital assets to run my business and protect that. And to add on that, we are also right now implementing the Cyber Resilience Act, and I'm a true believer in the Cyber Resilience Act because that forces companies, digital companies, software developers, hardware developers to implement security by design as a start of your product and you will be liable later on if your product is not safe, which is absolutely normal. I mean, if you buy a car or medication or children’s toys, you trust that the government will take care of it, that the products are safe and otherwise you sue the company.

With software and hardware, that’s still not the case. It’s a free for all yeah. And that's ridiculous. That's really, it will be a game changer, but it also may increase the cost.

Yeah. Because you will have, but you will have finally safe products which are difficult to hack are more trustworthy. So in that sense, true believer in the Cyber Resilience Act. It's a European act, but it could become also world standard.

Yeah. If you want to deliver in Europe, you have to adhere to this standard. Yeah. I often use the example of water for example, or power.

So if the internet is a utility and you could argue it is, because we're using it for everything. Why is it that I can safely take a glass of water from the tap, or plug my phone into charge in the power? But if I go online, I'm a hacked, I'm cracked, I'm free game, basically. And this is what that act is addressing, that as a user, I can actually trust the thing I'm buying because there is quality checks behind it and security by design.

And there's going to be ‘ijkmerken’, what's that in English? There's going to be trademarks for that. Right. Or a certification.

Certification. Yeah. Okay. So as a customer I know how to look at this.

So how do I do that, as a board or as a CEO? So how do I, I'm privileged that I'm in this business, so I know a little bit about the technology. I’ve got a team of people that understand everything and anything about that. If I'm a consultancy company or a bank and I'm a company director in such an organization, how do I go about talking to my security people or my tech people and asking the right questions?

Any view on that? Yeah. This topic we discuss in the Cyber Security Council is our national council on cybersecurity, by the way also public, private and academics in the council there we discuss how the cybersecurity law is advancing the annual progress report on our national cybersecurity policy, but also what to recommend to society or the government on cybersecurity issues. And one of the important publications we have is a manual for CEOs, for the boards, for secretary generals on how to deal with cybersecurity law.

And what should I ask you as a CISO, to know if the CISO is in control or not. Right now, most CEOs do not have a clue what to ask. And of course, you are not the target for this. Well.

You're not the target audience because... I'm not the target audience, but I am a target, given that- You are a target, but you're not target audience for this manual because I believe you know how what are the right questions. I hope so. Yeah, but this is really to help and I’ve heard already a number of companies said this was so useful and they organized a training.

So an external party being involved to give a training to the whole C-suite, how to deal with this new cybersecurity law. And they said that the manual really helped with that. Okay. And then, again, we touched on it a little bit earlier, but so the risk, I think the risk still is that it's becoming a bit of a legal discussion.

Right? It's a little bit like maybe an ISO certification, sort of ticking the box that I'm following the process and I can demonstrate I'm doing that. Would that be enough or is digital different in that it is also technology. And you also need to do your patching and you need to make sure the configuration is done correctly.

And maybe you need companies like ON2IT to help with scanning or defending or etc.. So again it's... I get the manual, but how deep do you need to go as a board member? It's a good point.

It's not just compliance and indeed, I've ticked all the boxes and I asked my CISO every three months, every quarter the questions. And I'm satisfied. No, that doesn't mean you're in control. The control is that you really have a discussion on what's the situation right now?

What kind of risks do we run as organizations? What has happened over the past months? Can you give a bit of details? How did you solve it?

Do you have to right staff? So really, a conversation between the board and a CISO, instead of just ticking the box, because that doesn't help. So it's really about enabling the CISO to actually be in control of the cyber. And if we reverse that, so maybe some people in the audience are actually either reporting to the CISO or working hard to keep the company safe.

What would be an advice you would have for them? What type of questions would they have to raise other than give me more money because it's more important? What type of... do you have any advice for them?

How do you manage this up to your board? How to, for the CISO to discuss with the board? Or people that work for the CISO, or a security engineer or an infosec officer, or how do they manage it up? How do they make sure the board understands this is important?

Well, first of all, I hope and trust that the CISO has regular meetings with its own staff. Of course. And that the priorities are clearly on the table. And you have to be careful that you do not always come up only with, I need more money.

Yeah. Because the marketing department will say I need more money or human resources department, etc. so you have to make very clear what you've done and what is needed for an organization. And you invite also your technical staff, for instance, in a meeting that gives ownership of both sides for the board, but also the technical staff that they can present also how they have been involved in certain cases.

The CISO in big organizations can't do everything, so they have also team members who can much better explain what has happened and what is needed for a solution. What is the quality of the staff being involved. So to have a true conversation, that's important. So if I'm hearing you correctly, you're...

I'm sort of testing a little bit because it's complicated stuff. The technology is really complicated. There's a lot of law and regulation flowing through it as well. There's accountabilities.

And so that's why I think there is a real risk of it becoming more of a legal discussion than actually the technical discussion we need to have. But it's also not just a technical discussion. It's really the nexus of the two actually, that is helping us to make it safe. But I think if I'm hearing you, you're quite positive about the fact that the law, the regulation, the manual, the pressure from the government on boards, personal liability combined with investing in the technology is going to get us there.

It's going to take a while because it's a big topic. But we'll get there, you think. Also security by design, these sorts of things, all of it together is going to really bring us to a higher level. And what I hope, also what we encourage, is also that companies discuss the topic amongst themselves, exchange- Internally or between companies?

Between companies, first of all the CISOs, and be open. And that's not an easy one because I've been giving presentations to rooms with 150, 200 cyber experts. And then I ask, you know, who's been been involved in the company with a hack in the past two years? Well, maybe three hands are going up very hesitantly, and it can't be true.

Many more. I mean, then you get the cliche you're hacked. You know you’re hacked, or you don't know that you’re hacked. Yeah, but it's so important to exchange with each other experiences because you can learn from each other and you can be more open about it.

How do you deal with it? But it also applies to CEOs. And that's why you also have Cyclotron an initiative for mature companies to exchange information on what's happening on the internet, what kind of threats are there and how to deal with that. And this is under the NCSC, right?

Cyclotron? Yeah. Personally I'm in an advisory council of an organization that is specifically doing that, creating roundtables in a confidential setting where CISOs and IT people can actually talk freely about I have been hacked. I need help, rather than doing that publicly.

So it is a difficult topic indeed. Funny enough that this is also what we been advocating also within the UN, but between countries. Yeah. We organize also regional dialogs in the Balkan country, western Balkan, ASEAN, in southern Africa, to ensure that people get to know each other and know how to find each other's help, to get each other's help.

Because also in the country at CERT level, often it helps if you can call your neighbor, can you help? Do you have someone to come over to help me because you had a similar issue? Yeah. So it's not only, it goes up to national level, actually.

That you have to help each other. And is there something we could potentially share with the audience, maybe some links or documents that talk about this and they can get some inspiration from to start thinking about this themselves? Other than the manual. Is there stuff that can yeah, like I said, inspire them?

I will have to think about it because it doesn't come up because these conversations at a regional level are, of course, in a more or less confidential setting [ ] not so much private. It's part of our capacity building in different regions. But you can also look at the UN, where we discuss on the responsible state behavior, that one of the norms is also to help each other in strengthening each other's capacity, but also in case of incidents. Okay.

And similar but different topic. Back to Singapore. So you said Singapore sort of. They solved the problem.

They had a short window of where it was was a crunch. They solved it. Did this, was it all government based or was it also a public private type cooperation where they got new sea cables in, resolved some of the power issues? Is there anything we can learn from that?

Also for the Netherlands or Europe specifically? I can't tell all the details how and when, but it was the government who decided on the new tender procedures, how to submit proposals and put the green energy as a priority and also enforcing the regulation for the sub sea cables, that this makes a real secure infrastructure. That's all done by government. Yeah.

And you can also see Singapore, within the, is a member of the ASEAN, is an example for other countries also how to deal with it. And because they have a lot of experience, they’re small, but the government is strong and they have a lot of capacity. They want to share also with other countries. It's of course a different governance system as well.

It’s different governance, yeah. But it's also, I think an example of regulation actually working in the benefit of the country and therefore also the citizens. Okay. Really nice.

In the preliminary, we talked a little bit about, and also in this call already, but there's actually a lot of good stuff happening in Europe as well right, around there. So we were a bit we're challenged a little bit when we talk about things like sea cable infrastructure and where does it land? And most of those investments going somewhere else, maybe. But when we think about AI, for example, and then we start to think about, again, autonomy and sovereignty, there's a lot good stuff happening.

Are they 1 or 2 examples maybe you want to share to actually demonstrate and prove that good stuff is happening? You know, often other countries, especially US at federal level, they complain about the EU, that's all regulation, etc. but if you see that we create a strong ecosystem with predictable regulation and that also creates an ecosystem which is much better for companies than unpredictability. In the States, you have at state level, all different regulations and some are much stricter than European regulation because they usually come after incidents.

We want to prevent incidents. And you see already that, you know, the challenge in Europe is that all the talent we have, and we have lots of talent and lots of talent also you can find from Europe in the US, but the point is that you have lots of ideas. Young companies starting, but our challenge is to kick the scale ups inside. That's something we all are aware of that we have to look at the capital market and further regulation to harmonize regulation.

But we are aware of that. But at the same time, you see companies like Mistral and for ASML for instance, working together and ASML investing in Mistral, you see at quantum that we have a strong ecosystem as Europe, actually stronger than the US. Okay. So that's also where we see very positive developments and the awareness is really coming up very strongly within the European Commission, but also with member states.

And we really feel the need to work together. So it's a chest out and be proud and, and some of its money, of course. I mean they're talking about financial union and things like that. But it's- And we have money.

I mean you look at the pension funds of Europe it’s so rich. It’s incredible. And the only point we have to invest it, but indeed we should, you know, should have more self-confidence. And a bit more risk appetite, I guess is.

Yeah. There's one thing I always say you never can change overnight is that if you go bankrupt in the US. Yeah, it's a it's a moment of pride almost. And you learn something.

Yeah, exactly. Okay. And in Europe it's still if you go bankrupt, the bank will not be opening its doors. This is not an endorsement for everybody to go bankrupt.

But it's. No, no, no, but it shows the difference in culture. Yeah. For the risk appetite.

Yes. Absolutely. Absolutely. Okay.

Trying to round this up as well. Very interesting. We can talk for days of course about this. Again if so we talked about the situation in Europe, Africa, how we relate sorry Asia and how we relate to others.

What do you see needs to happen in the next 3 to 5 years in Europe to remain that leading, I mean, whether or not we're.. there’s a lot of debate, the US, Europe is passé and everything else, I think we're not so much and listening to you, I think you agree. What needs to happen in the next 3 to 5 years to remain in that leadership position and not keep on sliding down the list? I think you you have already many reports with the agenda, Draghi report, Peter Wennink in the Netherlands, setting out an agenda.

So we are already focusing on that how to strengthen the whole ecosystem in Europe. We still have to work stronger together within the European member states, harmonizing the legislation. In the past it was too much, you know, we should do everything at national level and only what we can't do national level, we should do at a European level and that you see a change that, you know, we can have a look at harmonizing more European level to facilitate doing business within Europe and make it also for citizens actually easier in that sense.

But I think we have had a reality check over the past year at least, but also longer already. The Draghi report was from before. Yeah. So the reality check is there, and we are now working together, and we should work together to make ourselves stronger.

So it's not easy. It's a lot of hard work, but all the components are there. It's really for all of us to pick it up and start executing. And Europe is still a believer in working together also with other countries around the world.

It's part of our strength, actually, that community. We've always been a community. It's not the United States of Europe and we’re good at that. Okay.

Well, again, Ernst, thank you very much for this very pleasant discussion again. This was Threat Talks. If you have any questions, please reach out to us. We'll put some additional information in the show notes and we hope to see you soon.

Goodbye. Thank you for listening to Threat Talks, a podcast by ON2IT cybersecurity and AMS-IX. Did you like what you heard? Do you want to learn more?

Follow Threat Talks to stay up to date on the topic of cybersecurity.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Why Hardware-Software Co-Design Is AI's Real 100x: Dylan Patel of SemiAnalysisTraining Data · on ASML95 / 100
  • NIS2 and the Cyber Resilience Act (CRA) [The Industrial Security Podcast]The Industrial Security Podcast · on NIS2 directive80 / 100
  • 065: BUILDING IOT TOGETHER: From Hype to RealityTechBurst Talks · on Cyber Resilience Act78 / 100
  • Serving Up Talent: Workforce Development and the Future of Hospitality HiringDine & Dish · on Public-private partnerships74 / 100
  • 71. How Europe can fight back!The Difference Engine · on ASML74 / 100
  • Intel Capital with Jen Ard E 37ImpacTV · on ASML69 / 100

More from Threat Talks

All episodes →
  • Why Do You Trust Your AI Agent?61 / 100
  • Mythos is not the AI Apocalypse80 / 100
  • What about Iran? One Word Document, Three Backdoors76 / 100
  • Russia Cutting Cables?87 / 100
  • Hero Culture and a $1 Million Mistake85 / 100
Explore the best B2B Engineering & DevTools podcasts →
All Threat Talks episodes →