Telekom Slovenije's Cyber Security Operations Centre, which was established in 2018, received its second award for the most innovative security solution, awarded by the Institute of Corporative Security Studies in collaboration with the Slovenian Association for Corporative Security.
Telekom Slovenije's Cyber Security Operations Centre is the biggest security operations centre in Slovenia, and represents an important added value in providing cybersecurity both at the national level, as well as to businesses and other organisations. Telekom Slovenije received the award for the most innovative security solution at the international conference Corporate Security Days.
Telekom Slovenije's Cyber Security Operations Centre has detected and blocked more than 12.000 distributed denial of service (DDoS) attacks in the past year, while the number of handled security incidents nearly doubled in 2021 compared to the year before. The most frequent security incidents are malware (worms, trojans, etc.) and ransomware that attackers most often deliver to the victim through phishing attacks or software vulnerabilities, followed by DDoS attacks and data loss, disclosure and/or theft.
"Telekom Slovenije's Cyber Security Operations Centre utilises highly advanced technology, supported by accomplished and certified processes and competent employees. Its processes focus on the support of three key areas, namely in the corporate environment with an emphasis on business information systems, on national security with an emphasis on critical infrastructure, state institutions and providers of essential services, and on the private sector, where it ensures personal data security of individuals who are part of the organisational systems," wrote the conference organisers in the commentary on the award.
The award was accepted on behalf of Telekom Slovenije by the President of the Management Board Cvetko Sršen, who emphasised that the company has "over the past few years developed advanced solutions in preventive, reactive and predictive cybersecurity. As we speak, our Cyber Security Operations Centre actively protects companies of all sizes and institutions in Slovenia, the region and broader. We monitor security incidents 24/7, analyse and assess the information that we receive from different sources regarding potential threats. At the global level, we collaborate with different organisations and adopt additional measures for increasing security of both our services, and the services we provide to our subscribers, with our full cyber response team at full alert. Appropriate cyber protection demands constant development, education, training, and care for comprehensive management of IT infrastructure. Consequently, this award belongs to Telekom Slovenije's top security experts who make sure that we are – also in cybersecurity – the first choice."
Employees and the processes in the Cyber Security Operations Centre are certified and compliant with the most prominent certificates and standards in information security, including ISO 27001. Event organisers especially emphasised the ISO 22301 standard for ensuring business continuity, which Telekom Slovenije was the first company to receive in Slovenia and still remains the only Slovenian telecommunications operator to hold one.
Future development in cybersecurity
Telekom Slovenije actively monitors the latest trends and activities in cybersecurity. With continued investment, the company is planning upgrading technologies for advanced threat detection, in-depth analytics, increased level of automation of operative processes and different security and intrusion tests. At the moment the company is implementing new solutions for active response to cybersecurity incidents, and the co-called zero trust principle. New security solutions utilising artificial intelligence technology are being introduced across all the segments of networks and services.
The company is also constantly making sure that internal rules, guidelines and protocols are up-to-date (also by utilising external audits), and to re-certify the processes and services in accordance with the ISO 23001 and ISO 27001 standards. They constantly ensure that their security experts receive education, training and new competencies, and actively participate at international exercises in cybersecurity, allowing them to build on their competencies and obtain valuable experience. An exceptionally important experience was also providing support to Slovenia's presidency of the EU Council in 2021. Telekom Slovenije is the only company in Slovenia that has been accredited to become a member of the international organisation CSIRT; the only other Slovenian organisation that is an accredited member is the Slovenian Computer Emergency Response Team (SI-CERT).
A growing number of companies and organisations are choosing security services
A growing number of organisations and companies are opting for Telekom Slovenije's security services, with cybersecurity services provided by the Cyber Security Operations Centre are aimed at protecting businesses, as well organisations operating critical infrastructure and other essential activities, and corporations of all industries and sizes. One of the key advantages of the solution is how the managed service providing cybersecurity and protection can adapt to each customer.
Over the past few years Telekom Slovenije has utilised process automation, integration, artificial intelligence and machine learning, as well as state-of-the-art security solutions, to expand the Centre's operations to the segments of medium, small and micro businesses. This allows them to provide cybersecurity to companies of all sizes – from the biggest enterprise systems to the smallest businesses. Another service the Centre provides is system security reviews and security reviews for Microsoft solutions, which, unlike one-off reviews, provide reviews and monitoring over a longer period of time. They also provide consultation services to organisations on business compliance and the suitability of technical measures for personal data protection, manage customers' IT infrastructure (networks, servers, firewalls, personal computers), and provides a system for managing secure business mobility and business applications across all user devices.