Sikt – the Norwegian Agency for Shared Services in Education and Research, delivers a lot of services to the sector. They also have a public list of contact info for incident response teams (IRT) at all organizations that have established Traffic Light Protocol (TLP) agreements with Sikt.
Naturally I wanted to check whether these organizations have sufficient email security, in accordance with existing Internet standards, that also happens to be either requirements or recommendations from Norwegian authorities. Once again using the excellent compliance service of Dutch Internet Standards Platform (Internet.nl) , which checks for compliance with a range of internet standards that are recommended by the Dutch government. Very close to the recommendations of the Norwegian government I should say, with some being requirements for the public sector as well.
The good part: the IRT teams all have PGP keys. The bad part: email security for the organizations is not really where they should be.
This affects not only universities, but organizations such as Andøya Space , KSAT – Kongsberg Satellite Services , Norid , Norwegian Institute of International Affairs (NUPI) , Politihøgskolen , Simula Research Laboratory and the Norwegian Directorate for Education and Training ( Utdanningsdirektoratet ).
First, a congratulations for the top 4 organizations with a shared 82% score: Andøya Space , The Directorate for Higher Education and Skills , Norwegian Environment Agency and Norsk Regnesentral STI . You are all very close to achieving a 100% score, which I hope to see soon!
The complete email security report can be found here, with ability to search and sort.
What is more troublesome from this particular scan is that a vast majority have issues with missing RPKI. Cloudflare has a blog post from 2018 explaining what RPKI is. I won’t go into details in this particular article on potential problems due to lack of RPKI for the organizations in question, but those that does need to know have been responsibly contacted a long time ago.
Given what all these organizations are handling of data, and the amount of information I can only guess is sent by email every day, there is most certainly room for improvement on email security.
Originally published on LinkedIn.
