[DEPESHES] – The National Cybersecurity strategy Act has many good elements, but a fewer issues are missing, including references to devices of the net of Things (IoT), which will be very crucial in the 5G network – This is General Włodzimierz Nowak, erstwhile government typical for cybersecurity. The thought of setting up a strategical safety network operator is besides questionable.

Firstly, specified a serious issue should be regulated in a separate law. Secondly, it is essential to examine whether specified an entity will actually contribute to improving the safety of the State. According to the expert, it may be the opposite.
In the explanatory memorandum of the fresh version of the Act, the government points out that the aim of the strategical safety network is to guarantee the performance of tasks for defence, state safety and safety and public order in the telecommunications field. The operator of the strategical safety network (OSSB) is to be the entity required to launch and manage it. It is to be designated by the president of the Council of Ministers from among the single-member companies of the Treasury, which are at the same time a telecommunications company, have the telecommunications infrastructure essential to guarantee the performance of tasks, have method and organisational means to guarantee the safe processing of data on the telecommunications network and an industrial safety certificate.
– This should not be included in this law, a separate bill should be drawn up if specified an operator is to be appointed, due to the fact that this is simply a very serious substance affecting the safety of the most crucial state authorities that will gotta usage specified a network. This part is very poorly discussed. As far as I know, this besides raises quite a few controversy with operators, due to the fact that there is simply a procedure for creating an intermediary that does not contribute much, but is to be financed for being an intermediary. This is about frequencies and 700 MHz band management – Says Newseria Business agency Gen. Włodzimierz Nowak, erstwhile associate of the T-Mobile board, erstwhile NATO Vice president CIS Services Agency and erstwhile government typical for cybersecurity.
It points out that the establishment of a strategical safety network is simply a very crucial thing, and the task lacks quite a few crucial information. The request to make specified an entity is frequently argued that they function, among others, in France (Orange) and Germany (Deutsche Telekom). However, according to the expert, these are completely different situations, because, as he emphasizes, they are typically business entities that carry out their obligations for the safety of the home countries, with powerful intellectual, technological, investment and network coverage. Orange employs around 160 1000 people as a public company with shares in free circulation, Deutsche Telekom is 200 1000 employees and 32-percent state participation. Gen. Nowak points out that in Poland the operator is to be a tiny company Exatel with 450 employees and telecommunications possible assessed at little than 5% on a national scale, and in addition in full in the hands of the Treasury. According to the expert, this is not the right solution.
–Interestingly, even though it is simply a safety network operator by name, there are no assumptions that this operator will supply safe communications channels utilizing cryptographic devices, and only standard communications based on fibre networks and mobile connections specified as commercial operators. specified an approach makes the sense of setting up specified an operator even more questionable, unless the aim is to reconstruct the situation from the times of the Polish People's Republic, where everything had to be state. I personally don't miss state telecommunications from the time I waited 10 years to install the telephone – emphasizes Gen. Nowak.
The expert's concerns are besides raised by nominations in many companies of the State Treasury from a political key, which may have a crucial impact on the level of competence of management staff.
– In my opinion, the operator entrusted with the function of strategical operator should have no more than 49 percent of the State Treasury's share in order to guarantee its competitiveness and professional management. Moreover, the practice shows that administrative orders to usage a peculiar entity increase the costs of these services while reducing their quality, as in the case of monopolies – adds.
Another aspect requiring attention is to guarantee real safety for operators utilizing specified an operator.
– In Poland we have 4 large and respective smaller operators. The administrative creation of specified an operator in the form proposed by the Act will not supply any State security, and even this will make safety worse – notes General Włodzimierz Nowak. – If there are announcements that this operator will be forced to usage the military, police, state offices, possibly local governments, and besides the critical infrastructure of the state, it is becoming dangerous. It lacks diversification, possible to defy possible attacks. It's besides an apparent signal that we have everything in 1 place. From a military point of view, the easiest thing to destruct is the state can paralyze by disposing of 1 operator.
The expert so recommends diversifying and basing the OSSB on an infrastructure operator and, secondly, a virtual operator that can usage the resources of all another operators in the country.
– This creates a large redundancy of the system, opposition to interference, reduces the costs of the state on this strategy and, above all, makes it very hard for a possible attacker to paralyze specified an operator “The erstwhile typical of the government for cybersecurity argues.
In the opinion of General Włodzimierz Nowak, cooperation between the private and public sectors in cybersecurity, based on the current law, established procedures and the interaction of state authorities with telecommunications operators and critical infrastructure, is developing rather well. Like any system, it can besides be improved, but dialog is needed. To the erstwhile version of the KSC Act, the various marketplace participants submitted 750 comments, but only a fewer of them were included in the fresh version.
– There is no mention in the law to network architecture, which is besides very crucial for the plan of the full safety strategy – notes the cybersecurity expert. – I would urge that state entities, together with cooperating entities, namely civilian and critical infrastructure, take a good look at the architecture of the national network in terms of adapting it to defend against cyber attacks. Network segmentation is an essential component of cybersecurity affecting the magnitude of the possible cyber attack.
It besides proposes that the existing IoT devices and those that will function in the 5G network be taken into account in the legislation.
– The 5G network will have millions of connected devices of the net of Things – Like General Włodzimierz Nowak. – Many attacks take place through devices specified as sensors, light bulbs, cameras, printers and various others, which fundamentally do not have any safety features just due to the fact that no 1 has placed specified a request on manufacturers. These devices would most likely be a small more costly then, but I don't think it would be a large price difference. You gotta set specified requirements now, due to the fact that if we have 100 million of these devices on the 5G network, it will be besides late.
The bill's draft amendment was addressed on 18 October to the Committee of the Council of Ministers for National safety and Defence Affairs. It will then be discussed by the Standing Committee of the Council of Ministers, and after being verified by the legal committee, the Council of Ministers will mention it to the Sejm.