Asia-Pacific resolves to move from crisis to resilience

In 2019, the United Nations Office for Disaster Risk Reduction’s (UNDRR) Global Assessment Report called on countries to abandon “hazard-by-hazard” risk management, in favour of a holistic approach that examines risk in the context of its impact in systems, including cascading impacts.
A year later, the COVID-19 pandemic presented the world with an unfortunate case study of how systemic risk, if left untreated, can snowball into a disaster and a global crisis.
However, the pandemic was not the only disaster of the year, as 2020 saw countries in Asia-Pacific deal with a perfect storm of dual and multiple disasters, including droughts, floods and typhoons.
For countries in the region to guard against future disasters and mitigate the compounded impact of disasters, a fundamental shift in risk governance at national and local levels is required.
The post-COVID recovery process is one avenue to embed this new approach in socio-economic development processes, to avoid the creation of new risks while risk-proofing development gains.
However, some preconditions need to be met to facilitate this transformation, including committed leadership, investments, engagement of all sectors and stakeholders, and an embrace of science-based multi-hazard risk reduction. All of these elements are in line with the commitments that countries made in the adoption of the Sendai Framework for Disaster Risk Reduction 2015-2030.
The 2021 Asia-Pacific Ministerial Conference for Disaster Risk Reduction (APMCDRR), as the first major UNDRR regional platform since the onset of COVID-19, offers countries and stakeholders an opportunity to determine how these conditions can be met to achieve a transformation in risk governance.
With that goal, UNDRR and Australian Government, as the convener and host of the APMCDRR respectively, completed this week a major step in the roadmap to the ministerial conference, the organizing of the Asia-Pacific Partnership for Disaster Risk Reduction (APP-DRR) Forum.
The APP-DRR was organized on 1-2 December as a virtual meeting with 175 participants from 30 Asia-Pacific governments, over 10 intergovernmental organisations, several UN and international organizations, and stakeholder groups.
The Forum was kicked off with a statement by Ms. Mami Mizutori, Special Representative of the UN Secretary-General for Disaster Risk Reduction, who exhorted the participants to “think big and out of the box”. Opening remarks were made by the Australian Government:
"This forum is an important opportunity to take stock of how we're progressing against our Sendai commitments and to work together to accelerate this process," said Ms. Rebecca Bryant, Assistant Secretary at the Australian Department of Foreign Affairs and Trade, adding:
"Australia is firmly committed to working with countries to further enhance our region's resilience to disasters and to learn from each other's experience."
Of importance to the APMCDRR is building the disaster resilience of small island developing states in the Pacific. These countries are often the most vulnerable countries to extreme weather events, and still have to mobilize resources to counter a global pandemic.
Speaking on both aspects, the Honorable Dr. Ifereimi Waqainabete, Minister of Health and Medical Services in Fiji, said:
“Our coordinates cannot change... we need to understand as a nation that we are prone to disasters. We are prone to cyclones, droughts and other extreme weather events, almost every year,” emphasizing that “as leaders in our own right, we must continue to make better decisions in building resilience to ensure that the devastating impacts of disasters are mitigated and reduced.”
To make the right decisions, countries need to strengthen their data collection systems and understanding of risk, which in turn contributes to the development of sound national and local disaster risk reduction strategies.
On that front, UNDRR noted that the region was making progress in reporting on several Sendai Framework indicators, as 67% of countries in Asia-Pacific have reported some data as of October 2020.
However, challenges remain around the collection of data that is disaggregated by sex, age and disability, which hinders the effectiveness of planning to ensure no one is left behind.
Moreover, countries continue to face challenges in adopting integrated approaches that combine climate change adaptation with disaster risk reduction and expanding their risk governance mechanisms to other sectors.
As the availability of funding is often a hindrance to the implementation of risk reduction strategies, UNDRR presented recommendations on how countries could finance risk prevention.
Green investment offers a particularly effective way to fund climate change adaptation and risk reduction measures, as is highlighted in a report that was launched by UNDRR at the APP-DRR, titled ‘Ecosystem-Based Disaster Risk Reduction: Implementing Nature-based Solutions for Resilience.’
However, as a result of the downturn in economic activity caused by the COVID-19 crisis, it might be necessary for governments to increase their support for green investments as part of their recovery efforts.
“Financially constrained firms have weaker environmental performance and COVID-19 could be detrimental to environmental investments. Going forward, there will be a need for some forms of public support to encourage green recovery,” said Dr. Hiroko Oura from the International Monetary Fund.
The APP-DRR was also an opportunity for countries and stakeholder groups to voice their priorities and concerns. These reflections were posted on the event page and will help inform planning for APMCDRR.

NIS Directive has Positive Effect, though Study Finds Gaps in Cybersecurity Investment Exist

The European Union Agency for Cybersecurity (ENISA) released a new report on information security spending for network and information services (NIS) under the NIS Directive, the first EU-wide legislation on cybersecurity. The NIS Investments report is based on a survey of 251 organisations of operators of essential services (OES) and digital service providers (DSP) from France, Germany, Italy, Spain and Poland. Eighty-two percent of those surveyed reported the NIS Directive had a positive effect on their information security.
The new ENISA study examining cybersecurity spending states that 82% of Operators of Essential Services and Digital Services Providers find that the NIS Directive has a positive effect. However, gaps in investment still exist. When comparing organisations from the EU to those from the United States, data shows that EU organisations allocate on average 41% less to cybersecurity than their US counterparts.
NIS Directive Implementation
The report provides input to the European Commission’s review of the NIS Directive on the 16th of December, four years after the Directive entered into force and two years after the transposition into national law.
Challenges remain after the implementation of the Directive -- the lack of clarity of the NIS Directive expectations after transposition into national law was a common issue. More than 35% of organisations surveyed believe the NIS Directive expectations are unclear. Twenty-two percent of respondents listed limited support from national authorities as one of their top challenges when implementing the Directive.
Cybersecurity Investments: EU vs. US
When comparing organisations from the EU to organisations from the United States, the study shows that EU organisations allocate on average 41% less to information security than their US counterparts.
Key findings about the NIS Directive implementation in the NIS Investment report
- The average budget for NIS Directive implementation projects is approximately €175k, with 42.7% of affected organisations allocating between €100k and €250k. Slightly less than 50% of surveyed organisations had to hire additional security matter experts.
- Surveyed organisations prioritised the following security domains: Governance, Risk & Compliance and Network Security.
- When implementing the NIS Directive, 64% of surveyed organisations procured security incident & event log collection solutions, as well as security awareness & training services.
- “Unclear expectations” (35%)  and “Limited support from the national authority” (22%) are among the top challenges faced by surveyed organisations when implementing the NIS Directive.
- 81% of the surveyed organisations have established a mechanism to report information security incidents to their national authority.
- 43% of surveyed organisations experienced information security incidents with a direct financial impact to up to €500k, while 15% experienced incidents with over half a million euro.

CISA Issue Emergency Directive to Mitigate Compromise of Solarwinds Orion Network Management Products

The Cybersecurity and Infrastructure Security Agency (CISA) has issued Emergency Directive 21-01, in response to a known compromise involving SolarWinds Orion products that are currently being exploited by malicious actors. This Emergency Directive calls on all federal civilian agencies to review their networks for indicators of compromise and disconnect or power down SolarWinds Orion products immediately.
“The compromise of SolarWinds’ Orion Network Management Products poses unacceptable risks to the security of federal networks,” said CISA Acting Director Brandon Wales. “This directive is intended to mitigate potential compromises within federal civilian networks, and we urge all our partners—in the public and private sectors—to assess their exposure to this compromise and to secure their networks against any exploitation.”
This is the fifth Emergency Directive issued by CISA under the authorities granted by Congress in the Cybersecurity Act of 2015. All agencies operating SolarWinds products should provide a completion report to CISA.

CISA Highlights Theft of FireEye Red Team Tools

The Cybersecurity & Infrastructure Security Agency (CISA) has advised FireEye has released a blog addressing unauthorized access to their Red Team’s tools by a highly sophisticated threat actor. Red Team tools are often used by cybersecurity organizations to evaluate the security posture of enterprise systems. Although the Cybersecurity and Infrastructure Security Agency (CISA) has not received reporting of these tools being maliciously used to date, unauthorized third-party users could abuse these tools to take control of targeted systems. The exposed tools do not contain zero-day exploits.

CISA recommends cybersecurity practitioners review FireEye’s two blog posts for more information and FireEye’s GitHub repository for detection countermeasures:

Focus on National Cybersecurity Capabilities: New Self-Assessment Framework to Empower EU Member States

The EU Agency for Cybersecurity issues a National Capabilities Assessment Framework (NCAF) to help EU Member States self-measure the level of maturity of their national cybersecurity capabilities.
Developed with the support of 19 EU Member States, this framework was designed following an extensive exchange of ideas and good practices. The strategic objectives of the national cybersecurity strategies served as a basis of the study.
The framework was developed as part of the mandate of ENISA, as defined in the Cybersecurity Act. It falls under the provision to support EU Member States in building capacities in the area of national cybersecurity strategies through the exchange of good practices.
The key features
The self-assessment framework is composed of 17 objectives structured around 4 clusters. Each of these clusters is associated to a key thematic area for building cybersecurity capacity. Different objectives are also associated to each cluster. Based on 5 levels of maturity, specific questions were devised for each objective.
The clusters are as follows:
(I) Cybersecurity governance and standards - This dimension considers aspects of planning to prepare the Member State against cyber-attacks as well standards to protect Member States and digital identity
(II) Capacity-building and awareness - This cluster assesses the capacity of the Member States to raise awareness on cybersecurity risks and threats and on how to tackle them. Additionally, this dimension gauges the ability of the country to continuously build cybersecurity capabilities, increase knowledge and skills in the cybersecurity domain.
(III) Legal and regulatory - This cluster measures the capacity of the Member States to put in place the necessary legal and regulatory instruments to address cybercrime and also address legal requirements such as incident reporting, privacy matters, CIIP.
(IV) Cooperation - This cluster evaluates the cooperation and information sharing between different stakeholder groups at the national and international level.
Target Audience
The report issued is intended for policymakers as well as experts and officials responsible for, or involved in the design, implementation and evaluation of a national cybersecurity strategy and/or of national cybersecurity capabilities.
Why a capability assessment framework?
Cybersecurity capabilities are the main tools used by EU Member States to achieve the objectives of their National Cybersecurity Strategies. The purpose of the framework is to help Member States build and enhance cybersecurity capabilities by assessing their level of maturity.
The framework will allow EU Member States to:
- Perform the evaluation of their national cybersecurity capabilities.
- Increase the maturity level of awareness;
- Identify areas for improvement;
- Build new cybersecurity capabilities.

Supporting cities in advancing a holistic and systemic approach to resilience in Central Asia

The United Nations Office for Disaster Risk Reduction (UNDRR), within its project “Strengthening disaster resilience and accelerating implementation of Sendai Framework for Disaster Risk Reduction in Central Asia”, engages with the capital cities of Central Asia with the aim to support local governments to reduce risks and advance a holistic and systemic approach to urban resilience. The initiative is funded by the European Commission.
A network of focal points at the city administrations and interagency technical working groups are being established, including representatives of various departments of local and national governments, as well as risk analysis institutions, public councils and private sector. UNDRR will support assessments of Local Resilience Strategies and Action Plans of the five capital cities in Central Asian.
The initiative will contribute directly to the achievement of the Sustainable Development Goal 11 (SDG11) and other global frameworks, including the Sendai Framework for Disaster Risk Reduction, the Paris Agreement and the New Urban Agenda in the region. The importance of engagement with local governments is emphasized by the fact, according to the UNECE estimates, 65% of the total SDG targets globally need to be delivered by local authorities and actors.
Increasing climate and disaster resilience is a priority for the Governments of Central Asia. The region is highly vulnerability to climate change and exposed to a range of natural and technological hazards.
UNDRR will also provide support to the capital cities of Central Asia through its Making Cities Resilient 2030 (MCR2030) launched in October 2020. Building upon the MCR Campaign success and lessons learned, it represents a new and unique multi-stakeholder initiative for improving local resilience. It lays out a broader offer of support to the cities than the MCR Campaign and enhances local resilience through advocacy, sharing knowledge and experiences, reinforcing city-to-city learning networks, injecting technical expertise, connecting multiple layers of government, and building partnerships.

Public launch of MIDAS: the models behind EU policies

The European Commission opens the MIDAS inventory to the public, providing a user-friendly platform to explore the models used to support evidence-informed policymaking in the EU.
The new public version of MIDAS, the Modelling Inventory and Knowledge Management System, helps anyone explore any of the 35 models used for impact assessments since 2017.
The information available on the platform can help everyone to better understand the evidence used by the Commission when designing and evaluating policies that address today’s big challenges.
As well as providing useful documents and references, MIDAS explains how each model supported the analysis carried out for each impact assessment - indicating the leading Commission department, who runs the model, and which impacts it has helped to assess.
For each model, MIDAS also gives information on:
- Structure : details on the modelling approach, data inputs and outputs, spatial and temporal extent and resolution;
- Transparency: The extent to which underlying data, model results, code and documentation are available and accessible;
- Quality : if and how uncertainties are quantified and accounted for, if sensitivity analysis has been done, if the model has been peer reviewed or validated, if results are published in peer reviewed journals.
The Commission makes extensive use of models to support policymaking, from their initial design to evaluating their environmental, economic and social impacts. Models are used in many policy areas, such as agriculture, the environment, transport, economics and fisheries.
For example, the Commission recently used modelling to assess the feasibility of committing to EU climate neutrality by 2050, and of the 2030 Climate Target Plan, which raises the EU's ambition on reducing greenhouse gas emissions to at least 55% below 1990 levels by 2030.
By clearly presenting information on models that supported Commission impact assessments and making that information easy for the public to navigate, MIDAS encourages scrutiny of the quality of evidence provided by modelling and the exchange of good practices in model use.
The aim is to give everyone - whether it’s research bodies, decision makers or the general public - confidence in the contribution that these models make to better policy design and evaluation.

INTERPOL warns of organized crime threat to COVID-19 vaccines

INTERPOL has issued a global alert to law enforcement across its 194 member countries warning them to prepare for organized crime networks targeting COVID-19 vaccines, both physically and online.
The INTERPOL Orange Notice outlines potential criminal activity in relation to the falsification, theft and illegal advertising of COVID-19 and flu vaccines, with the pandemic having already triggered unprecedented opportunistic and predatory criminal behaviour.
It also includes examples of crimes where individuals have been advertising, selling and administering fake vaccines.
As a number of COVID-19 vaccines come closer to approval and global distribution, ensuring the safety of the supply chain and identifying illicit websites selling fake products will be essential.
The need for coordination between law enforcement and health regulatory bodies will also play a vital role to ensure the safety of individuals and wellbeing of communities are protected.
Vaccines prime target of organized crime
“Criminal networks will also be targeting unsuspecting members of the public via fake websites and false cures, which could pose a significant risk to their health, even their lives.
“It is essential that law enforcement is as prepared as possible for what will be an onslaught of all types of criminal activity linked to the COVID-19 vaccine, which is why INTERPOL has issued this global warning,” concluded Secretary General Stock.
As well as targeting COVID-19 vaccines, as international travel gradually resumes it is likely that testing for the virus will become of greater importance, resulting in a parallel production and distribution of unauthorized and falsified testing kits.
Online dangers
With an increasing amount of COVID-related frauds, INTERPOL is also advising members of the public to take special care when going online to search for medical equipment or medicines.
In addition to the dangers of ordering potentially life-threatening products, an analysis by the INTERPOL’s Cybercrime Unit revealed that of 3,000 websites associated with online pharmacies suspected of selling illicit medicines and medical devices, around 1,700 contained cyber threats, especially phishing and spamming malware.
To avoid falling victim to online scams, it is important to be vigilant, be skeptical and be safe, as offers which appear too good to be true usually are. Always check with your national health authorities or the World Health Organization for the latest health advice in relation to COVID-19.

New FEMA Study Projects Implementing I-Codes Could Save $600 Billion by 2060

FEMA released its landmark study, “Building Codes Save: A National Study,” featuring an in-depth look at the quantified benefits—avoided losses to buildings and building contents—from adopting modern building codes and standards. As the frequency and severity of natural hazards continue to increase year-over-year, this study reaffirms that building codes continue to be the best first line of defense.
“With incredible analytic detail, this study reaffirms what so many studies before have concluded — adopting and implementing the I-Codes is one of the most effective ways to safeguard our communities against disasters,” said Code Council Chief Executive Officer Dominic Sims, CBO. “But further strides must be made in states and localities where the report identifies there are no codes adopted or where codes have not been updated this century.  We thank FEMA for highlighting the value of and need for coordinated action at all levels of government that is critical to ensuring our homes and businesses are best positioned to weather the increasing hazard risks posed by our changing climate.”
International Code Council and FLASH celebrate the most comprehensive study conducted around hazard-resilient building codes to-date
The study affirmed the recent finding by the National Institute of Building Sciences that adopting modern codes provides $11 in mitigation savings for every $1 invested. Alarmingly, the FEMA study found that currently 65 percent of counties, cities, and towns across the U.S. have not adopted modern building codes, only 50 percent of cumulative post-2000 construction adhered to the I-Codes, and 30 percent of new construction is occurring in communities with no codes at all  or codes that are more than 20 years outdated.
“This study is excellent news for consumers as it delivers powerful economic evidence that modern building codes are the essential public policy tool to help communities survive and recover from disasters,” said FLASH President and CEO Leslie Chapman-Henderson. “The findings validate yet again that safer and stronger buildings preserve our quality of life today and strengthen our ability to confront an accelerating number of deadly, billion-dollar disasters tomorrow. We urge all leaders to recognize and use these profound insights to champion the cause for codes, and we thank FEMA for their leadership in bringing this critical information forward.”
“We are not powerless in the face of severe weather,” explains Dr. Anne Cope, chief engineer for the Insurance Institute for Business & Home Safety (IBHS). “The latest building science, including research conducted at the IBHS Research Center, points us to actionable and affordable ways to strengthen our homes and businesses to reduce avoidable losses from natural catastrophes. A critical step toward ending the cycle of repeated losses, particularly in coastal areas, is the adoption and enforcement of modern building codes.”
Based on a database of more than 18 million actual buildings constructed since the inception of the I-Codes in 2000, the frequency of hazard events across the country, and the contents and edition of the International Residential Code (IRC) and International Building Code (IBC) in effect in each locality where post-2000 construction took place, the study found:
- The IRC and IBC provided more than $27 billion in cumulative mitigation benefits against flood, hurricane wind, and earthquake hazards from 2000 to 2016. These benefits could have been doubled if all post 2000 construction adhered to the I-Codes.
- If construction continues at the pace the study observed and if the proportion of that construction adhering to the I-Codes is consistent with the trend the study identifies, the I-Codes could help communities avoid $132 billion to $171 billion in cumulative losses through 2040.
- If all new buildings across the U.S. were built to modern editions of the I-Codes, the country would save more than $600 billion by 2060.
The cost of not adopting building codes is too high. As FEMA’s materials make clear: “Adopting building codes is the single most effective thing we can do! One change in building codes can save lives and protect property for generations to come.” Proper implementation of adopted codes is also critical, as the means through which codes’ theoretical benefits are delivered in the field.

ENISA Report Highlights Resilience of Telecom Sector in Facing the Pandemic

ENISA is releasing its ‘Telecom Security During a Pandemic’ report at the 32nd meeting of EU telecom security authorities. Underlining the current strength of the sector in the face of the pandemic, the report also calls for increased cooperation, as telecommunications become more and more essential for Europe’s society and economy.
the European Union Agency for Cybersecurity (ENISA) is releasing its Telecom Security During a Pandemic report, which gives an overview of initiatives and good practices in the telecom sector to mitigate the impact of the pandemic. The report highlights the resiliency of telecom networks and services during the pandemic, which sustained major fluctuations in usage and traffic. The report also points to the need for increased cooperation between the public and private sectors as the role of telecoms expands.
The COVID-19 pandemic triggered major changes in the use of telecom networks and services: employees are teleworking; students are learning online; people are communicating via video. Almost overnight, the telecoms sector became a lifeline for Europe’s citizens and businesses. The pandemic put the telecom sector to the test with traffic peaks and spikes, combined with a national crisis and difficult working circumstances. Peaks followed major announcements about the pandemic; spikes occurred after news of lockdowns and closures. The diagram below shows the correlation between COVID-19 cases and fluctuations in network traffic on a single timeline. This is an example of one provider in one EU country, but it is representative of what other operators in Europe observed.
The report is divided in three parts:
- Early response phase: The report assesses the steps taken by telecom providers in the early response phase when providers activated their business continuity plans and supported emergency communications and communications via public warning systems.
- From initial strain to the new normal: Telecom providers had to deal with major surges and shifts in usage and in traffic patterns from the start of the pandemic. Gradually, this stabilised and became “the new normal”. The report examines the changes in usage, traffic patterns and network performance during the pandemic, and provides various examples of how providers managed the increased network loads.
- Response by the national authorities and collaboration with the telecom sector: The report provides a brief country-by-country summary of the pandemic response by the national telecom security authorities in the Union. It also highlights examples of industry initiatives, collaboration initiatives and information sharing between providers and authorities.
1 40 41 42 43 44 48