Cristian Tracci's Avatar

Cristian Tracci

@cristracci

πŸ€“ Cyber, international security and public policy β˜€οΈPositive thoughts and 🧠 interesting conversations πŸ›οΈπŸ¦ Columbia SIPA alumnus

66
Followers
201
Following
62
Posts
22.10.2023
Joined
Posts Following

Latest posts by Cristian Tracci @cristracci

They should do more Model UNπŸ€“

28.04.2025 06:45 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

We missed you guys last week!! πŸ₯²

19.04.2025 13:04 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Do not shorten the show!! Love every second of it!!

05.04.2025 09:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Thanks to @techpolicypress.bsky.social for publishing my thoughts!

07.03.2025 17:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Europe can certainly build technological platforms and improve processes – this is not the main problem.

Solving these issues requires more than identifying operational tweaks and engineering efficiencies because streamlining regulation is more about politics than operational optimization.

07.03.2025 17:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Bridging Europe's Cybersecurity Divide Through Political Will | TechPolicy.Press Cristian Tracci argues hard work is needed to harmonize cybersecurity regulations in Europe, but the real test lies in political agreement.

Cybersecurity Policy Harmonization: how should it be done?

Today, cybersecurity is regulated by hundreds of policies at the EU and national levels. Building a comprehensive overview that allows us to identify what should stay and what should be scrapped is a daunting task.

07.03.2025 17:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Who would be the European Rob Joyce? Not in terms of job role, but insights, personality, tech/policy mix

06.02.2025 21:19 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Very nice to see some rigorous research into governance and cybersecurity awareness. Well overdue.

10.01.2025 22:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Perceived Rigor (RSR): This dimension captures how strict or demanding employees perceive the SRs to be.

10.01.2025 22:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Perceived Legitimacy and Effectiveness (LESR): This dimension reflects how legitimate and effective employees believe the SRs are in protecting organizational information.

10.01.2025 22:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

To be more precise:

Employees' attitudes toward SRs are multidimensional, comprising two main factors:

10.01.2025 22:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
It is not only about having good attitudes: factor exploration of the attitudes toward security recommendations Abstract. Numerous factors determine information security-related actions (IS-actions) in the workplace. Attitudes toward following security rules and reco

The paper "It is not only about having good attitudes: factor exploration of the attitudes toward security recommendations" how employees perceive and evaluate security recommendations (SRs) within organizations.
By Miguel A Toro-Jarrin, Pilar Pazos, Miguel A Padilla
academic.oup.com/cybersecurit...

10.01.2025 22:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

If you are developing and enforcing security policies and recommendations across your organisations, ask yourself two questions:
1. Will people actually believe it is effective to protect the org?
2. Will people find it too strict or demanding?

10.01.2025 22:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I am a 20y experienced red teamer. I took up 2 jobs as a blue teamer and I burned out. That’a why I do policy now.

Quote

05.12.2024 12:27 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Is the EC doing anything with US authorities on the telco hack?
- Yes, we are tracking it.

05.12.2024 10:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

How can we avoid duplicating efforts with international partners?
- There is no duplication or overlaps. The same stakeholders are working together.

EU Space Law: Is Space a critical sector? Should we combine it with NIS/CRA?
- Yes, critical, and covered by NIS and CRA.

05.12.2024 10:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

What is the timing for mutual recognition under the CRA?
- Very important item on the agenda

Will the UK Cyber Bill align with EU legislations?
- To be discussed today during the Dialogue.

05.12.2024 10:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Qs:
What about research? What is the plan? The budget has been going down.
- We do need more funding, focusing on PQC, GenAI, cyber defense.

What should be done for the electricity sector?
- We are looking at specific sectoral RAs and the supply chain.

05.12.2024 10:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image
05.12.2024 10:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Hospitals? They are completely not ready. We’ve seen so many mining bitcoins - they had already been compromised.

05.12.2024 08:53 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Piotr Ciepiela, Cybersecurity Leader, EY Partner.
The private sector is raising concerns about the amount and harmonisation of legislation.
At the same time, is important to have those regulations.

05.12.2024 08:53 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

On the international side, we have been working with the US, UK, Japan, Korea, and Ukraine. Plus the Italian Presidency of the G7 set up a dedicated working group on cyber.

05.12.2024 08:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Last, the full implementation of the 5G toolbox.

05.12.2024 08:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

We need to make sure our critical entities have the enabling tools and tech.

05.12.2024 08:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

The revision of the Cybersecurity Act, with the mandate of ENISA and the certifications.

05.12.2024 08:42 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

We are evaluating the Blueprint. We need to take into account the latest legislative changes, from NIS2 and Cyber Solidarity Act.

05.12.2024 08:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Among the new things that are going to come, in January, an Action Plan for Healthcare in Cybersecurity will come out. Why hospitals? Because of the threat landscape in this sector.

05.12.2024 08:35 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

There is very strong commitment to streamline regulation. We are doing a screening now to identify areas where we can simplify. We are keen to hear from industry and companies. Consider this as an invitation.
Christiane Kirketerp de Viron, Acting Director, Digital Society, Trust, and Cybersec

05.12.2024 08:35 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Lorenzo Pupillo kicking off CEPS Cybersecurity Summit 2024

05.12.2024 08:29 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Special bonus point? A reference to Roger Federer in a cybersec book.

03.12.2024 07:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0