Accessibility

At CAMP 2024: AI-age incident response needs to evolve with technology

This week, Liina Areng, the Director of EU CyberNet participated in the CAMP 2024 Annual Meeting in Seoul to share Estonia’s and Europe’s perspective in cybersecurity with special emphasis on ransomware and artificial intelligence.

In her intervention, Liina Areng explained that AI-age incident response needs to evolve with technology, as it enables to manage threats in new ways. CSIRTs need to adopt AI tools for a proactive and adaptive approach for comprehensive cyber threat mitigation and prevention. Sharing innovative approaches and good practices is increasingly important.

She shared best practices from Estonia’s Information System Authority (RIA) for mitigating cyber threats through developing robust cybersecurity systems and processes, enhancing resilience through community building and raising awareness of good cybersecurity practices. Liina Areng highlighted RIA’s broad approach to building cyber resilience and incident response capabilities: 24/7 monitoring, operational information exchange with partners, regular threat assessments, educating employees, supporting companies and organizations, and establishing national cyber reserve for efficient cyber crisis management.

From the European perspective, she explained how the European Union builds resilience and response capabilities by implementing the EU cybersecurity strategy and regulations, setting obligations for essential services’ operators, and establishing networks to coordinate cross-border incident response and crisis management across the EU. Good practices from the EU are shared with partners across the world through cyber capacity building initiatives, such as EU CyberNet.

Liina Areng stressed that the use of artificial intelligence tools has become a battle between machines. Attackers use AI-driven means to generate phishing attacks, predict patterns and exploit weaknesses, and the defenders should also use automated threat hunting and predictive analytics. She also pointed out that ransomware groups are using less mass spam and drive-by attacks but rather more complex, low-and-slow attacks and intermediaries to reach those that can afford paying hefty claims. This is why supply chain cybersecurity should be prioritized in national strategies.

The 3-day meeting entailed interventions, sharing best practices and introductions from member countries about the cyber security situation in their countries and regions

The Cybersecurity Alliance for Mutual Progress (CAMP) is initiated by the government of the Republic of Korea and managed by Korea Internet and Security Agency (KISA) with purpose of achieving sustainable benefits and serving as a platform for actions to keep cyberspace safe.

Photos: https://flic.kr/s/aHBqjByZph



Keep reading similar articles
At CyCon 2026: Municipal Resilience in Crisis, Conflict and Systemic Disruption

EU CyberNet hosted an interactive workshop, titled “Securing Cities: Municipal Cyber Resilience in Crisis, Conflict and Systemic Disruption” at CyCon 2026 on 26 May 2026.

Critical Sector Auditing and Risk Analysis Workshop Concluded After Three Days

The critical sector auditing and risk analysis workshop for Malaysia concluded after three days with practical table-top exercise to implement different auditing approaches.

Day 2 of the Critical Sector Auditing and Risk Analysis Workshop

Following the high-level opening conference, the second day of the critical sector auditing and risk analysis workshop for Malaysia focused on understanding different auditing approaches and their uses.

EU CyberNet Crash Course #3: Communication in Cybersecurity

The 3rd EU CyberNet Crash Course, titled “Communication in Cybersecurity” and led by Jussi Toivanen explored the fundamentals and role of communication in cyber-related crises and raising cyber awareness.

Critical Sector Auditing and Risk Analysis Workshop Opened with a High-Level Conference in Malaysia

Organised in cooperation between EU CyberNet and National Cyber Security Agency of Malaysia (NACSA), the workshop on critical sector auditing and risk analysis for Malaysia opened today, 20 May 2026 with a high-level conference.

Workshop on Critical Sector Auditing and Risk Analysis to Take Place This Week in Malaysia

EU CyberNet in cooperation with the National Cyber Security Agency (NACSA) of Malaysia and the Delegation of the European Union to Malaysia is organising a three-day programme on critical sector auditing and risk analysis from 20 to 22 May in Putrajaya, Malaysia.