Opening RemarksMathias CormannSecretary-GeneralOECD
Preliminary draft agenda
- All session times are marked in Korea Standard Time (KST)
- All sessions will take place at the Swiss Grand hotel in Seoul, Korea.
- The welcome remarks, the sessions under each theme, and the keynote speech will be publicly livestreamed. To view all other sessions, participants will need to register.
Day
1 :
July 10, 202413:30 - 14:30
Registration
14:30 - 14:55
14:55 - 15:10
High-level group photo
15:10 - 15:25
15:25 - 16:25
Session 1 – Security-by-design and open-source software
Security-by-design is an approach that seeks to build security in products and services from the outset and throughout their lifecycle rather than as an afterthought, while maintaining the capacity to innovate and adapt to an ever-changing threat landscape. Following OECD Recommendations in this area, policy makers encourage its adoption by industry to reduce digital security risk, building on existing methodologies and standards such as the Secure Development Lifecycle. However, it is unclear how OSS projects can implement security-by-design. This session will explore the opportunities and challenges related to security-by-design in OSS.
ModeratorJeremy WestHead of Digital Security and Safety UnitOECD
SpeakerAllan FriedmanSenior Technical Advisor and StrategistCybersecurity and Infrastructure Security Agency (CISA)
SpeakerElina MacheferOpen Source Security Programs LeadFrench Cybersecurity Agency (Agence nationale de la sécurité des systèmes d'information ANSSI)
SpeakerRasma ArabyManaging DirectorAtsec information security AB
SpeakerRobin GinnExecutive DirectorOpenJS Foundation
SpeakerHeejo LeeProfessor, Department of Computer Science and EngineeringKorea University
16:25 - 16:45
Coffee Break
16:45 - 17:35
Session 2 – Open-source software and vulnerability treatment
When it comes to vulnerabilities, both proprietary and open-source software face the same reality: the more complex the code, the more vulnerabilities there are, and despite all efforts to secure the code by design, some vulnerabilities still remain, as explained in recent OECD work. The solution to software vulnerabilities is their detection and resolution, including through vulnerability treatment and co-ordinated vulnerability disclosure (CVD), a collaborative process involving all stakeholders, from security researchers (detection, disclosure) to software editors (vulnerability handling and resolution) and users (patching and vulnerability management). In 2022, the OECD recommended the adoption of public policies to encourage vulnerability treatment. This session will explore the specificities of OSS with respect to vulnerability treatment, and the unique characteristics of its ecosystem.
ModeratorHarry ToorChief of StaffThe Linux Foundation
Speakerİsmail ErkekCoordinator of Advanced Cyber Security OperationsComputer Emergency Response Team of the Republic of Türkiye (TR-CERT)
SpeakerKyoungae KimOpen source task team leaderLG Electronics
SpeakerTaketo YamadaDirector for Cybersecurity StrategyMinistry of Economy Trade and Industry of Japan
SpeakerMelanie RiebackChief Executive OfficerRadically Open Security
17:45 - 20:30
Reception hosted by MSIT and KISA
Welcome remarks from, Sang-Joong Lee, President, KISA
Day
2 :
July 11, 202409:30 - 09:45
ARRIVAL
09:45 - 10:00
A case study on digital security in the supply chain
10:00 - 10:50
Session 3 – Managed Service Providers (MSPs): the weakest link in the supply chain?
The 2020 attack that leveraged vulnerabilities of the MSP SolarWinds showed how devastating a supply chain attack can be, including through cascading effects affecting other managed service providers down the supply chain, including some of the most well-known cybersecurity firms. This attack also showed that the weakest link is not necessarily the smallest or the least secure partner. MSPs play an increasingly important role in the maintenance and operation of today’s information systems in organisations of all sizes. But at the same time, as MSPs are becoming critical in the supply chain, they are also becoming a prime target for malicious actors. MSPs can turn out to be the weakest point in the chain of security, leading to massive downstream incidents. This session will be an opportunity to discuss the criticality of MSPs and will bring together representatives from public and private organisations.
ModeratorAllan FriedmanSenior Advisor and StrategistCybersecurity and Infrastructure Security Agency (CISA)
SpeakerYoung Hoon KimDirector of Public Policy for Japan and KoreaAmazon Web Services Korea
SpeakerYock Hau DanAssistant Chief Executive, National Cyber ResilienceCyber Security Agency of Singapore
SpeakerMarissa MaldonadoChief Executive OfficerProda Technology, LLC
SpeakerHarry ToorChief of StaffOpen Source Security Foundation
10:50 - 11:10
Coffee Break
11:10 - 12:00
Session 4 – Zero trust: a panacea to increase security of supply chains?
Zero trust is increasingly being promoted as a new security paradigm to address the vanishing of digital security perimeters around organisations, including partners within supply chains. While in principle at least the migration to zero trust security offers a way to improve security quite radically, its cost/benefit is unclear, notably when considering usability, organisation, complexity, and other management aspects. Another issue related to zero trust is the extent to which it can enhance the security of supply chains in complex ecosystems with numerous partners, and how smaller partners who are not zero trust-ready (or cannot afford it) can nevertheless be included. This session will bring together technical and policy experts.
ModeratorMelanie RiebackChief Executive OfficerRadically Open Security
SpeakerEunsu JeongDirector of Cyber Security Industry DivisionMinistry of Science and ICT of Korea
SpeakerAviram AtzabaExecutive Director for International Strategic AffairsIsrael National Cyber Directorate (INCD)
SpeakerClément RouaultChief Technology Officer and co-founderExaTrack
SpeakerFlorian SchützDirector, National Cyber Security Centre (NCSC) Switzerland, Chair of the OECD Working Party on Digital Security
12:00 - 14:00
Lunch Break
14:15 - 15:15
Session 5 – Is more digital security regulation inevitable?
In an increasingly interconnected world, the need for robust digital security measures is undeniable. Yet the landscape is complex, with various sectors facing unique challenges. From critical infrastructure to the Internet of Things (IoT), cloud services, and the realm of certification and labels, the demand for regulation varies. This session will explore where regulation should become the norm to enhance digital security. It will also examine instances where self-regulation has shown promise, and yet sometimes faltered. Experts from governmental and private organisations will exchange views during the session.
ModeratorFlorian SchützDirector, National Cyber Security Centre (NCSC) Switzerland, Chair of the OECD Working Party on Digital Security
SpeakerTakashi MichikataDirector for International Affairs, Office of the Director-General for CybersecurityMinistry of Internal Affairs and Communications of Japan
SpeakerBenjamin BögelHead of Sector for Product Security and Certification PolicyEuropean Commission
SpeakerKeun Woo LeePartner and Vice Head of the New Project GroupYoon & Yang LLC
SpeakerAnne-Louise BrownDirector of PolicyCyber Security Cooperative Research Centre (CSCRC) Australia
SpeakerMurat YazganHead of DepartmentMinistry of Industry and Technology of Republic of Türkiye
15:15 - 15:35
Coffee Break
15:35 - 16:25
Session 6 – How to stimulate and enhance collaboration?
Collaboration among countries, stakeholders, and sectors is paramount to effectively combat cyber threats, which are constantly increasing in intensity and complexity. The session will look at best practices and concrete examples from a variety of contexts. From government initiatives to industry partnerships and cross-sectoral collaborations, the session will analyse what works best to foster cooperation and strengthen digital security. This session will bring together representatives from governmental organisation, private companies, and civil society.
ModeratorAudrey PlonkDeputy Director Science, Technology and InnovationOECD
SpeakerShinya TahataSenior Director, Information Security, Bureau of Digital Services, Tokyo Metropolitan Government, Vice-Chair of the OECD Working Party on Digital Security
SpeakerJennifer J. QuaidExecutive DirectorCanadian Cyber Threat Exchange (CCTX)
SpeakerEvangelos OuzounisHead of Policy Development and Implementation UnitEuropean Union Agency for Cybersecurity (ENISA)
SpeakerFlorent KirchnerHead of the national cybersecurity strategySecrétariat général pour l'investissement (SGPI)
16:25 - 16:35