Accessibility

At CAMP 2024: AI-age incident response needs to evolve with technology

This week, Liina Areng, the Director of EU CyberNet participated in the CAMP 2024 Annual Meeting in Seoul to share Estonia’s and Europe’s perspective in cybersecurity with special emphasis on ransomware and artificial intelligence.

In her intervention, Liina Areng explained that AI-age incident response needs to evolve with technology, as it enables to manage threats in new ways. CSIRTs need to adopt AI tools for a proactive and adaptive approach for comprehensive cyber threat mitigation and prevention. Sharing innovative approaches and good practices is increasingly important.

She shared best practices from Estonia’s Information System Authority (RIA) for mitigating cyber threats through developing robust cybersecurity systems and processes, enhancing resilience through community building and raising awareness of good cybersecurity practices. Liina Areng highlighted RIA’s broad approach to building cyber resilience and incident response capabilities: 24/7 monitoring, operational information exchange with partners, regular threat assessments, educating employees, supporting companies and organizations, and establishing national cyber reserve for efficient cyber crisis management.

From the European perspective, she explained how the European Union builds resilience and response capabilities by implementing the EU cybersecurity strategy and regulations, setting obligations for essential services’ operators, and establishing networks to coordinate cross-border incident response and crisis management across the EU. Good practices from the EU are shared with partners across the world through cyber capacity building initiatives, such as EU CyberNet.

Liina Areng stressed that the use of artificial intelligence tools has become a battle between machines. Attackers use AI-driven means to generate phishing attacks, predict patterns and exploit weaknesses, and the defenders should also use automated threat hunting and predictive analytics. She also pointed out that ransomware groups are using less mass spam and drive-by attacks but rather more complex, low-and-slow attacks and intermediaries to reach those that can afford paying hefty claims. This is why supply chain cybersecurity should be prioritized in national strategies.

The 3-day meeting entailed interventions, sharing best practices and introductions from member countries about the cyber security situation in their countries and regions

The Cybersecurity Alliance for Mutual Progress (CAMP) is initiated by the government of the Republic of Korea and managed by Korea Internet and Security Agency (KISA) with purpose of achieving sustainable benefits and serving as a platform for actions to keep cyberspace safe.

Photos: https://flic.kr/s/aHBqjByZph



Keep reading similar articles
At CySec 2026: Workshop on How the AI is Transforming OSINT

EU CyberNet conducted a hands-on workshop titled “AI-Enabled OSINT and Threat Intelligence” at the 4th Brunei Cybersecurity Conference CySec 2026 on 16 September 2026 to support practical knowledge-sharing and cooperation between the European Union and Indo-Pacific region.

Improving the Security of Ports in the Philippines

EU CyberNet Experts Omar Ramadan and Sergio Bryton participated in the Experts’ Forum on Critical Maritime Infrastructure in Manila, the Philippines on 8 September 2026 to discuss security of ports and strategic shipping routes.

EU CyberNet Launches Expert Podcast Series

EU CyberNet launches a podcast series to bridge the expertise from EU CyberNet’s Expert Pool and its partners to wider cybersecurity and cyber capacity building community on people, policies and practices shaping cybersecurity globally.

The 9th Blog Article of the EU CyberNet Expert Blog Series: When AI Makes Cybersecurity Decisions: Five Governance Questions Every Organisation Should Answer

EU CyberNet has published the ninth blog article in its Expert Blog Series. The ninth article, titled “When AI Makes Cybersecurity Decisions: Five Governance Questions Every Organisation Should Answer” is written by EU CyberNet Expert Anahiby Becerril.

The 8th Blog Article of the EU CyberNet Expert Blog Series: The Institutional AI Dependency Test: Can Public Services Continue When AI Cannot Be Trusted? An Evidence-Led Governance Exercise for Cyber Resilience

EU CyberNet has published the eight blog article in its Expert Blog Series. The eight article, titled “The Institutional AI Dependency Test: Can Public Services Continue When AI Cannot Be Trusted? An Evidence-Led Governance Exercise for Cyber Resilience” is written by EU CyberNet Expert Andra T. Alcalá.

Reflecting EU CyberNet Summer School 2026: Participants’ Testimonials

EU CyberNet asked four EU CyberNet Summer School 2026 participants – Gabrielle Botbol, Emmanuel Chagara, Olesya Danylchenko and Lisbeth Laurie – to share their experience in the Summer School.