RegTech4ILR

Regulatory Technologies for Luxembourg Regulatory Institute

Inspiration

In the telecommunications sector, the EU Directive 2009/140/EC states that Member States shall ensure that providers of public communications networks ‘take appropriate technical and organisational measures to appropriately manage the risks posed to security of networks and services’. As part of the adoption of this directive at the national level, a first project has been developed in collaboration with the Institut Luxembourgeois de Régulation (ILR), the national regulatory authority for the telecommunications sector in Luxembourg that aimed to adapt and facilitate security risk management in the telecommunications sector. To this end, both ILR and LIST have produced an initial framework composed of two parts: an approach and a tool to support the adoption of this regulation by Telecommunications Service Providers (TSPs) at the national level (regulated entity part) and a tool collecting the data received by the regulatory authority from the regulated entities through the preceding approach (regulatory authority part).

In light of the feedbacks following the first regulatory cycle performed from December 2015 to July 2016, R&D challenges have emerged to facilitate and improve the quality of the risk management process performed by the regulated entities on one side and to improve the governance of the regulation by the regulatory authority on the other side. The main limitations identified are the lack of support to the security risk management process, a management of risks based on individual assessments instead of taking care of the whole ecosystem, and limited data analytics capabilities.

Innovation

The main objective of this project is to establish an advanced security risk management framework dealing with the limitations highlighted. To achieve this primary objective, LIST researchers specialized in the application and development of risk management methods and tools will more specifically focus on the following secondary objectives:

  • To develop and make evolve models and reference architectures supporting the risk management framework
  • To develop a customer-centric and systemic risk assessment approach, allowing to assess risk not only at the individual level of each TSP but at the level of interconnected TSPs providing services to the end-user
  • To define an extended set of measurements for data analytics for both the regulatory authority and regulated entities
  • To integrate the results in a multi-regulation platform

Impact

As outcome of the project, the planned innovation will enable a better governance of the regulation. Risk awareness and decision-making ability of ILR will be improved based on the indicators that will be established. The value for ILR will also be in the standardized and high-level quality of the results obtained to comply with the regulation, thanks to the supporting models, positioning Luxembourg as a top performer in the EU to comply with this EU Directive. Finally, the security of TSPs as well as the quality of service for end-users will be improved, hence risks taken by the end-users related to lack of security and integrity of networks and services will be minimized.

Project Profile

Start Date
 
1.1.2018
End Date
 
30.4.2020
Duration
 
28 Months
Keywords
 
cybersecurity, information security, telecommunications, regulatory framework, regtech

Funding

Funding Framework
 
FNR PUBLIC²
Call
 
PUBLIC2-17/IS

 
Supported by the Luxembourg National Research Fund (FNR) and the Luxembourg Regulatory Institute (ILR), and financed by the RegTech4ILR project (PUBLIC2-17/IS/11816300).

Partners

People

Publications

A risk management framework for security and integrity of networks and services

<p>N. Mayer, and J. Aubert</p>

<p>Journal of risk research, doi:10.1080/13669877.2020.1779786, 2020</p>

Systemic security risks in the telecommunications sector: An approach for security and integrity of networks and services

<p>in the Proceedings of the 5th International Conference on Complexity, Future Information Systems and Risk, COMPLEXIS 2020, 8-9 May, ISBN: 978-989758427-5, p. 72-79, 2020</p>

<p>N. Mayer, and J.-S. Sottet</p>

Associated projects

Telco2000
5G and EECC regulation for the telecommunications sector
View more

How can we help you?

By content type (optional)