
Threat Talks · 2026-06-02 · 33 min
Key moments - from our scoring
Substance score
67 / 100
Five dimensions, 20 points each
Ernst Noorman brings diplomatic and cybersecurity expertise to an emerging infrastructure challenge: submarine cable resilience. The conversation separates myth from reality, revealing that despite headlines about Russian sabotage and geopolitical threats, the actual data shows roughly 150 - 200 cable faults annually - mostly from fishing nets, anchors, and natural disasters like landslides near the Congo River, not deliberate sabotage. The ITU's 42-member advisory body (governments, regulators, and industry) launched in November 2024 tackles three interconnected issues: threat monitoring, repair capacity bottlenecks (cable ships are aging; permits for repairs can take years), and redundancy gaps in underserved regions like Tonga, which sat offline for 61 days after a single cable cut. Noorman emphasizes that 99% of data flows via subsea cables, making them critical infrastructure alongside the data centers and landing stations where espionage is actually easier than seabed tampering. The conversation addresses digital sovereignty concerns - particularly Europe's growing reliance on tech giants (Google, Meta, Amazon) to fund new cables - and why satellite alternatives like Starlink, while useful for disaster response, cannot match fiber capacity or independence.
99% of all internet traffic crosses submarine cables, making them critical for global connectivity and essential to any nation's digital infrastructure.
Roughly 150 - 200 cable faults occur per year globally. The majority are caused by fishing nets, ship anchors, earthquakes, and natural events like landslides near river deltas - not sabotage.
Repair bottlenecks stem from aging cable ships, complex permitting processes (permits can take 2+ years), cabotage rules requiring national vessels, import duties, and bureaucratic hurdles that vary by country.
Experts agree espionage on subsea cables is impractical because intercepting data would require deploying data centers underwater; landing stations on shore are far easier targets.
No. Starlink is useful for disaster recovery and isolated regions, but the data volume that flows through subsea fibers is orders of magnitude larger and cannot be matched by satellite bandwidth.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers solid, fact-based information about submarine cable infrastructure, disruption causes, and repair challenges that most B2B operators wouldn't encounter in standard reading. Key insights include the distinction between cable cuts vs. shunt damage, the 150-200 annual faults baseline despite 1.7M km of cable, and repair permitting barriers - however, substantial portions consist of definitional explanation and geopolitical framing that, while relevant, doesn't pack novel operational density throughout.
99% of the data flows over the subsea cables
throughout the years, it's only about 150 to 200 cable faults a year. At the same time, the number of kilometers on cables increasing tremendously
The episode distinguishes itself by reframing sabotage concerns with data (most faults are anchors, fishing, natural causes, not state actors) and highlighting repair capacity/permitting as the real vulnerability - contrarian to typical media narratives. However, the core frameworks (redundancy, geopolitical risk, satellite vs. fiber tradeoffs) and the emphasis on sovereignty are well-trodden themes in infrastructure discussion. The perspective is grounded and corrective rather than deeply original.
there's still hardly any evidence of any sabotage on the submarine cables
What stood out especially, is the difference between what you read in the media and hear from politicians. And on the other side, if you look at the facts
Ernst Noorman is a practitioner-diplomat with direct operational involvement - he sits on the newly formed ITU Advisory Board on Submarine Cable Resilience (42 members, established Nov 2024), advises governments on cybersecurity law implementation (Netherlands Cybersecurity Council), and has on-the-ground experience in multiple countries and conflict zones. He represents substantive policy-making, not punditry. However, he is primarily a policy/diplomatic voice rather than a cable operator or engineer executing at scale, which limits top-tier caliber.
Ernst is also a diplomat who used to serve in Burkina Faso, Afghanistan, Colombia and Surinam. He now represents the Netherlands in an ITU Advisory board on subsea cable infrastructure
It's the advisory body on submarine cable resilience created in November 2024. It's a 42 membership, 42 members indeed like you said, governments, regulators and industry together
The episode anchors claims in concrete data: 150-200 annual faults, 1M km cables (2014) vs. 1.7M km (2024), Tonga's 61-day disconnection (2022), 18mm cable diameter, 80km repeater spacing, examples of 2+ year repair delays, and specific regional cases (Congo River landslides, North Sea congestion). However, many geopolitical assertions (Russia shadow fleet, spying) lack specifics - no named ships, dates, or incidents. Overall mix of strong data on infrastructure with vaguer claims on threat actors.
throughout the years, it's only about 150 to 200 cable faults a year. At the same time, the number of kilometers on cables increasing tremendously just give you one figure in 2014 there were a million kilometers of cable. Oh. Ten years later, it was 1.7 million kilometers
Tonga was in 2022, for 61 days disconnected from the internet because they had only one cable connection
The host (Peter) asks competent, structured follow-up questions (explaining advisory body mandate, drilling into threats vs. repair vs. redundancy, probing espionage risk, asking about real-world business impact for CEOs) and demonstrates product knowledge (references AMS-IX involvement, NIS2, geopolitical context). However, questioning is largely confirmatory rather than challenging; the host rarely pushes back on claims, probes contradictions, or demands tighter evidence. The flow is conversational but somewhat deferential - Ernst controls the frame throughout without meaningful adversarial engagement.
Can you explain what this advisory body is and what you do?
But then again, if most of my data is flowing over these sea cables and my business is depending on that data, can you talk about that a bit more? Why should I or companies be worried about these sea cables?
Computed from the transcript - who did the talking, and the words that came up most.
The headlines say Russia’s shadow fleet is cutting cables. The experts say most faults come from clumsy ship anchors. Ninety-nine percent of global internet traffic runs across the ocean floor, and the conversation about what threatens it is mostly wrong. In this episode of Threat Talks, Peter van Burgel, CEO of AMS-IX, sits down with Ernst Noorman, Cyber Ambassador at Large for the Netherlands and member of the ITU Advisory Board on Submarine Cable Resilience, to separate geopolitical noise from engineering reality, and explain what actually puts global internet connectivity at risk.
Transcribed and scored by The B2B Podcast Index.
Submarine cables are under fire. Is the real threat under the surface? 99% of all internet traffic is traversing the seabed. We see a lot of geopolitical attention.
Cable cuts in the Baltic Sea, cable cuts around Africa. Is it as dramatic as the headlines say? Welcome to Threat Talks. Welcome to Threat Talks.
Let's delve deep into the dynamic world of cybersecurity. Our guest today is Ernst Noorman, cyber ambassador at large for the Netherlands. Ernst is also a diplomat who used to serve in Burkina Faso, Afghanistan, Colombia and Surinam. He now represents the Netherlands in an ITU Advisory board on subsea cable infrastructure.
Ernst. Welcome to Threat Talks. Thank you very much, Peter, for having us. Having me.
Can you explain what this advisory body is and what you do? Yeah. It’s the advisory body on submarine cable resilience created in November 2024. It's a 42 membership, 42 members indeed like you said, governments, regulators and industry together.
So people are really working also before on the ships. They know how it works in practice. And we are sitting together and discuss how to make the submarine cable ecosystem more resilient, looking at threats, looking at the repair capacity and looking at the redundancy connecting parts of the world, which are not good connected yet. Okay.
And you say it is established in 2024. So that's relatively new. So can you explain why this was needed. As you mentioned in your introduction it's a lot in the news these days on the cables it becomes more and more prominent and people understand the importance of the submarine cables.
It's still increasing, the number of cables worldwide. And at the same time, as you know, 99% of the traffic is crossing. And it's also you read a lot in the news, which is not really fact based, a lot about sabotage. Is that really the issue?
What is really happening on the net and how to create more resilience because that's needed also for the future to stay connected around the world. So it becomes more pressing. And that's why it was decided by the ITU and its members to say, okay, let's create this body for with a limited mandate only for two years to see how we can increase resilience. Okay.
And you said it's resilience threat and repair. So you could maybe argue it's almost the same but it isn't. Can you maybe talk a little bit about what's the difference between the three. Well, first of all, I mean, if you look at the figures and that's really one of the important topics also, that's why ICPC's included, the International Cable Protection Committee, because they have the data on cable since 1958 when they were created.
And so if you look at at the facts, then you see actually throughout the years, it's only about 150 to 200 cable faults a year. At the same time, the number of kilometers on cables increasing tremendously just give you one figure in 2014 there were a million kilometers of cable. Oh. Ten years later, it was 1.
7 million kilometers. And still we have the same number of cable faults. But it doesn't mean we have to look at it and see how can we ensure that this doesn't increase, that we still limit as much as possible the cable faults? So that's a very important topic.
And on repair, that's more a concern actually to many parts of the world because the cable ships are getting old. There's also a lot of hurdles for companies, private sector companies to repair in different waters from different territories. There are all kinds of legal barriers. There's the reason for cabotage, which means that the ship should actually be national while there is no national capacity.
So you get all the permitting and all the difficulties, and it can take a hell of a long time to repair a cable, which is a pity, because then you mean that means that the capacity in those countries is less than it should be. So you have different parts in a discussion which addresses the main concerns around the world on cables. And then still, if we go back to the why and try and explain also to the audience why. what has changed?
Because you say it's growing. There's more capacity, actually more miles, but roughly equal the number of cuts or breaks. So that would mean that actually you could argue the quality is actually improving. So why do we then need this committee or why should we be worried about sea cables at all?
And these cuts? It’s you know it's getting more busy on the seabed. It's not only the data cables, but if you look at all the wind parks, the gas pipes on the seabed. So it's getting pretty busy, especially also in the North Sea.
It's quite crowded. And there's of course, for geopolitical reasons, a lot of concerns is what's happening, for instance, with the shadow fleet from Russia. What are these ships doing? So in that sense, you see a lot more attention in the news.
A lot more politicians talk about it, journalists talk about it, but it's not always fact based when they bring it up. And so in that sense, it's good that we have this advisory body to really look at what's really happening and how to improve the situation. And is it also.. you mentioned geopolitics and of course, we live in a time of geopolitical unstability.
You could say. We ourselves as AMS-IX have seen some of that with the recent Middle East conflict, AWS data centers being attacked and going offline and attracting traffic. So is it also that therefore infrastructure has become quote unquote a legitimate target? So is there also in that sense, a geopolitical threat to it?
Is that an additional reason to look at this? Well, first of all, it's nothing new on this one. If you look at the First World War, UK, the United Kingdom cut one of the telex cables from Germany to make sure they had to use radio. So it was easier to listen to the communication of Germany.
So that's already in the First World War. But fortunately we have so much, so many cables around the world that the redundancy’s already pretty big. If we have a cable cutting [ ], you wouldn't notice it. I mean, 2024, we had one cable cut in a whole year.
No one knew about it. We knew, but then again, we're in that business. [ ] as a user... The citizens or the companies wouldn't have noticed it.
If you look indeed on the cable structure in the Gulf region, for instance, the Strait of Hormuz is full with cables, loads, I mean, they’re connected also to your infrastructure also you have there in Oman, probably. So it is really a concern how to protect the cables and the digital infrastructure. And that is also why if we have international discussions in the UN, then we say the internet, we count as part of the critical infrastructure and critical infrastructure should not be attacked.
And the countries have a responsibility to protect it. And still it's happening. We're seeing. There's nothing new, you say, it already happened in the First World War.
I also remember example of Radio Katwijk, which was actually established because, again, we couldn't connect with the overseas areas. But is it also.. is there an element of espionage? Maybe?
There's other podcasts and books about listening in and all of that. So is that something you're worried about? No. It's first of all, also coming back to the cables itself, there's still hardly any evidence of any sabotage on the submarine cables.
Okay. I always tell people, you know, you better attacked, attack the energy infrastructure underwater because it's much more costly to repair. And the users really know it immediately if there's an electricity cable cut. Well, data cable, if you cut it, the traffic, the data traffic immediately follows another route.
Now I forgot what your question was. So espionage. So we talk about, blockages etc. but ...
With regard to espionage, I've discussed with many experts to see what is the threat in espionage. And until now, the experts tell me, if you want to really do espionage, you go to the landing stations because it's much easier if you do it on the seabed, you have to put a data center on the seabed, which is still a challenge. Complicated. Maybe in the future you never know what happens in the future, how you can deal with it.
But right now, to add to, to try to do espionage on the sea is quite complicated. And when you say cable landing stations, for people that may not necessarily understand how cable systems work, what is a cable landing station and why would it be easier to do espionage there? Well, because the cable, if it goes under sea it first leaves the country. And there you have a station, both.
it's called a landing station, but it’s also a departure station. You could say. It leaves, it goes under the water, under the seabed, across to another country, and there it lands again. So that’s on, there you have a lot of connections to internet exchanges, for instance, but then it's much easier to see how you can connect there and do some espionage.
It's literally the station where the cables land. Literally when they come out - On the beachhead where they come in and okay, okay. Switching maybe to a slightly different topic. So again, also, now we've talked a lot about cable cuts or breaks and disruptions.
And I want to talk a little bit about the effect of it in a minute. But before we go there, there's also something like shunts rather than cuts. Can you maybe talk about that a little and why that's important too? It's important to understand what's really happening on the seabed.
Because if we talk, we talk mainly about cable faults, not cuts. Because then you say really it's a cut. If you say cable faults, it means cable is not functioning anymore. And the cable most people, if I give presentations, I ask people, okay, tell me what's the diameter of the cable?
And well, you can, I can say it in front of a camera. They put a hands wide, because they think the cable’s like this. Well, the cable on the ocean bed is only 18mm in diameter, very tiny, but the outside is silicon. And you can imagine that through the years.
And also with fishing nets or anchors or the chains of anchors, you will damage slowly the outside protection of the cable. And then there will be a shortcut. And that means that the repeaters you have every so, more or less 80km, they will have an electricity shortcut and won't function anymore. And that's called a shunt damage.
A shunt, okay. And that means also the cable has to be repaired. Yeah. Because it’s still [ ].
And that’s counted as one of the 150 to 200 cable faults a year. And we didn't really touch on it. But you also said in when we were preparing that actually most of those sort of roughly 200 cuts, the majority of that is still fishermen, anchors, earthquakes maybe, etc.. Oh yeah.
For instance, in Africa, in front of the Congo River, it's a very difficult geographical point, especially after the raining season. Loads of water and sediments flow into the ocean. Landslides. Landslides.
And there you have cables and sometimes a couple of these cables. They just break, through the pressure. So you could argue maybe in the design they should have put it somewhere else. But now that they're there, it's not sabotage.
It's actually natural. Yeah. That it’s happening. Okay.
So again if we switch gears and so we talked a lot about sort of the technology of the cables and the shunts and the breaks and or the faults, all of that. But why does it actually matter? Why should we be worried about it? Because on the one hand you say there's enough redundancy.
So if one breaks or is damaged then there is enough redundancy. But then again, if most of my data is flowing over these sea cables and my business is depending on that data, can you talk about that a bit more? Why should I or companies be worried about these sea cables? Well, it's good to realize the importance of the sea cables.
99% of the data flows over the the subsea cables. So that means for our connectivity as Europe, as the Netherlands, it's really important to keep that connectivity. It's also important to note that now the majority of the new cables are laid by the big tech companies. So also if you talk about the data autonomy, sovereignty, depending on which word you use, it's really crucial to also not only look on the digital infrastructure in your country, but also the connectivity to it, because the big tech, they will only put new cables if they can put a new data center.
So in that sense, it's really important to understand it's a holistic infrastructure cables, the data centers up to your phone and they're all connected. And you have to understand that for digital autonomy, digital sovereignty, you have to look at the whole infrastructure. So that's one of the crucial points. Okay.
But also if you do business, you have a multinational company and you have important also parts of your business in countries which are not well connected, maybe in the Pacific or in the Caribbean. And there you have a cable fault, that can mean that your connection is at risk and won't function as well. I mean, not many multinationals have business in Tonga, but Tonga was in 2022, for 61 days disconnected from the internet because they had only one cable connection. So this was why we look at how to improve the connectivity of all parts of the world.
And is that... It's maybe too big a topic for now, but that's, at the Netherlands we're having a lot of them, but a lot of them are also getting end of life. So if we need to invest in this, every country should invest in it. But also in the Netherlands, we specifically also need to take care of this, right?
We really need to step up our game. Yeah, yeah we have about if I'm correct, ten landings of cables and two are a bit out of date, not really functioning anymore. And as the Netherlands, but also as Europe as a whole, we have to look at the connectivity of the continent. Yeah.
That's crucial. I mean, of course we are in a fortunate situation that we also have connectivity with Germany, with Belgium. So it's not only through the seabed, but that's also why we see that Europe is also now looking at investments in more connectivity through submarine cables. Okay.
And then a lot of people are talking about there’s satellite now and Starlink. And so it's all fixed. Why do we need these cables. But, not so much.
And maybe you can explain better or why is satellite not a replacement? Why is it maybe an alternative, but not. Can you talk about the difference between capacity maybe or availability of satellite versus sea cables? Now first of all, I mean, what's happening now on satellites, Starlink is crucial, for instance, on the battlefield in Ukraine, but also for civilians, especially if there's so much damage in the civilian infrastructure.
For Tonga, it could have played an important role as well, just to give, you know, to be connected and communicate on the cable repair. But the data flow can never match what's happening on the fibers.. In terms of volume. In volume.
I mean, the volume is so enormous what can pass through the submarine cables. And that has been increasing over the years. The number of fibers per cable has increased. So that never can match.
But for isolated parts of the world, of course, Starlink or other solutions are wonders for the connectivity for that part. And again, you touched on it a little bit, the sovereignty and autonomy. And we also have the examples where Starlink was switched on and off, depending on the, sort of the will or the mood of a particular person. So again, looking at your role as the also the cyber ambassador, maybe in this ITU advisory body as well, what are your concerns as an advisory body or what are you doing to address some of that dependency and therefore also hopefully the sovereignty as a result?
Well, of course, the advisory body is with 42 members from around the world, and the sovereignty is especially a topic also in Europe right now. Dependency, like I mentioned before on the big tech for new cables. So we have to find our own solutions for that. We are laying out also European cables between in the Mediterranean, for the connectivity with Africa.
So these are really on top of the list now also for Europe. But what you just gave an example of what happened with Starlink. In our view, it is unacceptable that one person decides on where the geopolitical priorities are. So it didn't happen that often anymore afterwards.
But that's a crucial point. Of course, in the political discussions, we have also with other countries that it's not in the hand, should not be in the hands of a private company to determine who is connected or not. But this right now for, you know, the investments you see right now, it's all done by private sector. Yeah.
And I think it should be really public private cooperation to strengthen the connectivity around the world and not only in the hands of private sector. And is that something that so it's a political topic very much. And again, given the geopolitical instability, it's understandable. So it's sort of a rude wake up call.
You could argue. In my talks to also other companies and other CEOs or executive team members. I'm not entirely sure they see it as such as well. Right.
It's because it's so easy to use. It always works. So why would we be worried? What’s your view on ...
Is it a real problem, truly? Or is it... Well, you know, now because we have a little bit of a of a quarrel with the US maybe temporary or should boards be really worried about this on a company level as well? Or is it a pure political thing or what’s your view on that?
You know, for the small medium sized companies, I mean they don't have to worry. I mean they for them the connectivity is given. They won't be able to influence it much. But for, you know, the governments and bigger companies, multinational companies, they should be aware that the connectivity through submarine cables is crucial for them.
And the fact that it works now doesn't mean it always will be working. No. That you will not come into a situation we're discussing a lot now with the influence of the big tech companies in Europe. Do they have a kill switch, for instance?
I mean, can they disconnect a cable if there would be, for political reasons, we as the Netherlands have always been defending an open, free and secure internet around the world. Because and not to disconnect if you have a war or an argument with the country. Yeah. Because you also want to keep it open free for the Medical Center, for Human Rights Defenders, for journalists.
And that also applies for submarine cables, because without that you don't have that connectivity. No. Okay. So in that, so thank you for that.
So earlier we also talked about the fact that the advisory body is relatively new, but the topic as such is already around since I think 1958 or the ICPC... The ICPC is already around since 1958. And so when you look back at your tenure within that committee, what is the one or two things that really stood out or surprised you, which... Well, I didn't know or oh my God, what's something that really stood out in the time that you've now spent on that advisory body?
Well, what stood out especially, is the difference between what you read in the media and hear from politicians. And on the other side, if you look at the facts. Okay. And ICPC is very strong in the facts, but also in the industry, they know the reality.
And to really sit there with experts together and talk about fact based policies, and that's one of the recommendations also, if you look at threats base it on facts, your policy should be developed and based on facts and not on worries. And of course, you can have legitimate concerns. You have to look at it. For instance, monitoring what's happening on the seabed is excellent.
I mean, it's good. But not only for data cables, also for the energy infrastructure. So but that's the difference between, you know, the gossip and what you read in the press. And the reality.
That was... Surprising Positive surprise actually. And some of that, of course, I think we have in general right where influencers and ... So it's maybe not just on this topic, but it's nice to hear actually that the facts..
it's comforting that the facts are, it's not 200 times sabotage. It's actually a lot of it is just natural and clumsy captains of ships dragging anchors rather than... So that's sort of a small comfort maybe in this topic. Just to give one example because from the industry it came, they said those ships who lose an anchor once in a port and there's an inspection usually have 200 other issues on the ship.
Okay. And they make a list and the captain has to sign for it that they will repair it and they are allowed to go. So the recommendation from the industry was also keep them in the port until they have fixed everything and then they won't do it again, including where they lost their anchor. So maybe we could trace it back to which cable they cut.
Okay, okay. Interesting. Hey. And, another topic around sea cables, which may be complicated, I don't know, is that there's the sort of the 12 mile zone of the borders of countries outside of that 12 mile zone there's not a lot of law, there's a little bit of piracy, and there are some global..
The economic zone. The economic zone is there. But from a, it's difficult for the Dutch navy, for example, to act if it's outside that national law or any navy for that matter. Do you talk about that as well?
And is there policy or how do we protect the sea cable in the area that is not within the 12 or the economic mile zone? Because there's a lot of ocean, so there's a lot of areas where there's no policing or the law is difficult. Yeah. And at the same time, I mean, the main worry right now is, is not the lack of policing, etc..
I mean, we are monitoring what's happening and we talk about sensors putting on the cables to see to follow what's happening in the ocean or the North Sea for that matter. That's good for security reasons, but also environmental reasons, for instance, the fishery monitoring for many reasons you can do that. But the real concern is also the difficulty in repairing. I mentioned at the beginning that it can be so difficult for repair ships to enter waters to repair.
Because of the permits.. For the permits for, you know, sometimes you have to pay an import duty for your ship and you don't get the import duty back. Okay. And then they complain it’s very expensive to repair the cable.
And these are private cables. So the private companies have to take care also of the repair. But sometimes it can take months. And there are extreme examples of more than two years before they got a permit to repair the cable.
Wow. And that's I think, more the issue we try to tackle. That is more harmonization. And the Netherlands is often mentioned together with the UK and also with South Africa as good examples how to do it.
We have an open permit, a permit for the repair ship to repair ships to come into our waters and immediately repair them. They don't have to apply for a permit. They can immediately repair. And that's an example for other parts of the world to see how you can do it.
And then you don't even notice that you have a cable cut. And do you see other countries interested in that or potentially following that when you look at this advisory body, or is it... Well, period. Do you see that?
Yeah. Yeah. Yeah, absolutely. I mean, we had attended two in-person conferences and I had to sit also in a panel to explain our policy because they took it as an example of a good practice.
And the audience were very interested. And they also came afterwards to learn more about our practice on having such an open permit. Yeah. So no, this is one of the objectives of this advisory body.
How to improve that. Okay. And slightly back to you as a person. So the fact you mean, you've spent time in Afghanistan, maybe not an easy country, Colombia, I'm not sure when, but also a troubled past, Surinam.
So how did that shape you as a person but also as a diplomat? And how how does that help or give you certain perspectives in the role you have today as an ambassador, but also specifically again in this advisory board? Yeah. Well, Afghanistan doesn't have any connection with submarine cables.
It's a landlocked country. And it was curious to learn that actually there within the connection with the generals from the Afghan army and for instance, the advisors also from the US, is that it was all through WhatsApp. Okay. Because that was the only way they could always reach the generals.
That showed also the limited connectivity of the country. Interesting. Yeah. So submarine cables and connectivity, it wasn't, connectivity was an issue, but it was very limited.
Colombia is different in that sense. But it was also still that they have to grow more mature in creating a for instance national cybersecurity center. They don't have a CERT yet in Colombia. While they all realize the importance of a CERT, but it's for political reasons, it's finding it hard to come together.
What you learn is to act as a diplomat and how to communicate with all the different countries. And they have different angles, different views, different interests. So how do deal with that? That's, of course, the core business of a diplomat, to communicate with different cultures, but also to further our own interests and our own values in those countries.
And it's also what the internet is all about. It is open. It's connecting the whole world. So we need to figure out how to work together across these different, across these differences, even in time of conflict as today.
Okay. So so trying to sort of, I think we'll do a second one of these because there's still a lot to talk about, but maybe trying to round this one up. Sort of a final question. So if you look at again at your role in the ITU advisory body, your role as cybersecurity ambassador, your experience as a diplomat in different countries, looking at subsea cables specifically and then maybe for the audience, but in general, what would you...
like me as a CEO, or every CEO for that matter, to know or worry about when it comes to this particular topic? What should we put on the agenda that we may not have on the agenda today? Well you, of course, on a special position with your direct involvement in cables. But it's you know, of course, a large part of my job is on cybersecurity, and that's something we, I mean, that's going to be a CEO issue.
And that's also new because in the past they thought, well, I have a CISO. I can leave it to the CISO to take care of the cybersecurity. And now with the new cyber security law we just adopted, actually in the Netherlands, last week it was, it puts the responsibility in the hands of the CEO, and that's a crucial change. But it also made the awareness of the CEO different.
They suddenly realized that for their company, the whole digital infrastructure is crucial. They cannot function without and that they should be aware of. And this is NIS2. And then in the Netherlands, specifically the new Cybersecurity Act, I think.
Right. Or? Yeah, that's based on the NIS2. Yeah.
Yeah. Yeah. Okay. So that's just...
And do you think maybe the final, final question, do you think that realization is, is hitting home within the boardrooms? Meeting and you... I'm involved. It's my job.
Right. So in that sense I know about it. But do you think it's trickling through or do we need to do additional marketing or communication about actually hitting home within the boardrooms? No, we're working on that.
I'm also a member of the Cyber Security Council of the Netherlands, and we created a manual for CEOs and secretary generals of ministries, how to deal with the cybersecurity law. What does it mean? What kind of question I should ask my CISO, because they are not cybersecurity specialists and should not become it, but it still means there's still a lot of work to do. In a sense, I mean, I'm not happy with the hacks, but of course, with the Odido hack, companies start to realize- The awareness is increasing.
I don't want to be in the news with this. So you get, and actually those ways, these hacks are relatively easy done. Very not sophisticated hacks, but it creates more additional awareness, I think, with CEOs, with boards of companies and organizations that we really have to work on that. So in light of Threat Talks, it’s a real threat that now not just the CISO and security people, but actually the board should be worried about as well.
Including the CEO. Absolutely. Okay. Well, on that bombshell, on that note, let's end this episode.
Thank you very much, Ernst. Like I said, I think we'll be back for a second one. So everybody, thank you for watching. In the show notes, we'll put a number of links and and more information.
One thing maybe there is a report or that's coming from the IPCC. I think that's coming out soon. Right. The report of the advisory body.
Yeah. That will be published most likely in June. Okay. On the website right now of the ITU, you can find it easily and you can read already the recommendations of these three groups.
Okay. So we'll make sure we'll get that into the show notes as well. Thank you for watching. This was Threat Talks.
See you soon. Thank you for listening to Threat Talks, a podcast by ON2IT cybersecurity and AMS-IX. Did you like what you heard? Do you want to learn more?
Follow Threat Talks to stay up to date on the topic of cybersecurity.