Cyber Security in
Digitalization Projects


Digital transformation is the single largest cybersecurity risk factor in the world

And most organization are still ignoring it. 

Managing Digital Risks
in Digitalization Projects

  1. Digitalization Process aims to make data easily available for a larger number of players in order to reach more efficience ways of working
  2. This new approach has a direct impact in Security as the risk surface becomes bigger and with more vulerable points of contact: Your risk surface is anywhere your organization's ability to operate, reputation, assets, legal obligations, or regulatory compliance are at risk. 
  3. Our project aims to find new ways and guidelines to include Cyber Security in Digitalization Projects without compromising the Digitalizations goals: we focus on finding and categorization risks attached to digitalization projects and propose ways to mitigate, remove or monitore them.

A Smart Built Environment Initiative

Smart Built Environment is a strategic innovation program for how the social construction sector can contribute to Sweden's journey towards becoming a global pioneering country that realizes the new opportunities that digitalisation brings.

Digitization represents one of the biggest changes in society ever. In the Smart Built Environment program, we jointly implement a unique and long-term effort to develop more sustainable and integrated ways of building.

Play Video

Main Activities

The project is divided in four major activities

Threat Model

We used threat modelling techniques to document possible threats in a digitalization projects in construction. 

Security KPI

The model should be use to find the rights assets for digital surveillance in a project. We define surveillance models

Osint/Darkint

Using enhanced open source intelligence we continuosly surveillance of digital assets in a normal project.

Prototype

We create an intereactive  portal with guidelines to include cyber security in digitalization projects from the beginning. 

The Challenges

All digitalization mean a new challenge to information security

Opening the Security Perimeter

Digitalization means to making data available for users outside the normal security perimeter.

Including Security from the beginning

The security approcah should be presence in projects from the very start.

Global Players accessing data

Critical Data will be available for players  from other countries and cultures

Increasing and facilitating Knowledge

A key success factor for any security approach is to make easy for users how to include it in projects.

FAQ about the project

Is this an IT Security Project?

No. IT Security is a small but important part of a Cyber Security approach. In most cases IT Security try to solve security issues by creating a perimeter around the data as a way to protect it. In our project we see how to approach security issues in digitalization meaning when the data is supposed to be shared between different players, most of them outside the perimeter that IT Security teams build. 

So what is this about?                                         

The project is about how to increase security and surveillance when data, sometimes critical data, is exchanged between players in construction projects. So our goal is to appaoch security from the outside-in and not the other way around. The way we try to do this is to find the digital risks in the projects and remove or mititgate them applying digital surveillance of digital and physical assets. 

What methodology will you use?

We will use intelligence methodology based on enhanced OSINT (Open Source Intelligence) . The methodology is based on creating a threat model for digital and physical assets and build the security looking for vulnerabilities and risks in the Internet that might compromise projects and their critical data.

What do you want to achieve?

We would like to build and create guidelines and prototypes to include Cyber Security at the beginning of the projects without making digitalizations goals pay for it. We would like to find processes for surveillance of digitalization projects that reduce the risk profile of the projects.

When and for how long will the project run?

Project start is planned for fall 2019 and it will run until December 2020.

Lorem ipsum dolor

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Integer nisl risus, ultrices non dictum id, varius ut erat. Etiam eget tincidunt eros, at sollicitudin mauris. Nulla vehicula tellus quis justo finibus bibendum. Nulla consequat at est vitae iaculis. Interdum et malesuada fames ac ante ipsum primis in faucibus.

Project Groups and Responsibilities

A group of International and Multi-disciplinar profesionals

Process Mapping

An important part of the project is to document the mapping of a real construction project into a digitalization process that will be the base for the threat modelling.

Threat Modelling

In a first step the project will define the digital and physical assets of the process as well as the attack vectors available for the chosen project.

Stakeholders Involvment

Together with KTH we will involved the market into seminars and workshops as a way to gather usefull information and feed back from the real world.

Communication Activites

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Morbi consequat pharetra ex. Nam urna eros, vestibulum pellentesque elementum at, fringilla id elit.

Technology and Security Consultants

Developing guidelines in an interactive portal as well as building the prototype for digital surveillance based on the threat modelling.

Project Leadership

Managing time schedules, activities and economy: The challenge of running an international and multi disciplinar team to make sure that the project meet its goals and expectations

This project is financed by Swedish Authorities listed above

Contact Us for more information

Do not hestitate to contact us for more information or for contributions. 

If you are looking for documentation from the project please specify and use a business e-mail

We will try to answer all requests as soon as possible. 

Contact Us

Please send us your request

Address

Götgatan 9
116 46 Stockholm

Contacts

Email: cybersakerhet(@)kresp.se                            

Copyright (c) KRESP Projektledning AB