#Cyberclown: Hype mechanisms in public OT security discourse

And why it’s our job to name them

Photo by Karsten Winegeart on Unsplash

Context: #Cyberclown

  1. Arne Schönbohm has not been particularly popular among security experts, who say he lacks technical expertise and has too many lobbying connections. All this has been going on since he took office in 2016, which is where the term “cyberclown” comes from — from a ZEIT ONLINE article from 2016.
    Old News.
  2. Cyber-Sicherheitsrat Deutschland e.V.: Arne Schönbohm hat den “Cyber-Sicherheitsrat Deutschland e.V.” mitgegründet, einen dubiosen Verein, der so tut, als sei er eine offzielle deutsche Behörde. Der jetzige “Präsident” des Vereins, Hans-Wilhelm Dünn, steht gemäß Berichten von 2019 Russland bzw. russischen Geheimdiensten nah. Doof bis dubios, aber Arne Schönbohm hat sich und das BSI sogar schon öffentlich von dem Verein distanziert.
    Old News.
  3. Cyber-Sicherheitsrat Deutschland e.V.: Arne Schönbohm co-founded the “Cyber-Sicherheitsrat Deutschland e.V.”, a dubious association that pretends to be an official German authority. The current “president” of the association, Hans-Wilhelm Dünn, is close to Russia or Russian intelligence services, according to 2019 reports. This is dumb and without doubt a bit shady, but Arne Schönbohm has even already publicly distanced himself and the BSI from the association.
    Old News.
  4. Protelion: One of the member companies in the “Cyber-Sicherheitsrat Deutschland e.V.” association is Protelion, German offshoot of a Russian IT security company founded by an ex-KGB member. The company appears to be just as dubious as the association. Their software would probably not be recommended to anyone, critical infrastructure or not.
    What is missing: the “so what”. We do not know what advantages the dubious company has from its membership in the dubious association and whether the software is used anywhere in German critical infrastructures or by the German government. This raises exciting questions that could be investigated, but as of now, these are nothing but:
    Unsubstantiated assumptions.
  5. Arne Schönbohm recently gave a speech at the 10th anniversary of his dubious association, although he had actually distanced himself from the whole thing. These are the only real news in the matter. One can rightfully criticize his appearance, at the very least it is politically instinctless. But without all the fuss, would that have been enough to make a president of a federal authority resign from office within eleven days?

Talking publicly about dry topics: Framing for relevance

Four hype mechanisms in cybersecurity reporting

Hype mechanism 1: “critical infrastructure” namedropping

Hype mechanism 2: FUD

Hype mechanism 3: gatekeeping

Hype mechanism 4: Not refutable speculations

Get out of the dark mode!

Dieser article was published as part of the monthly Security Briefing for Hard Hats (in German).

--

--

Friction generates heat — true for writing and engineering. Fluchsfriction generates writings on security engineering. Heated debates welcome! CTO@admeritia

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
Sarah Fluchs

Friction generates heat — true for writing and engineering. Fluchsfriction generates writings on security engineering. Heated debates welcome! CTO@admeritia