![The [InfoSec] Stack](https://s3-us-west-2.amazonaws.com/anchor-generated-image-bank/production/podcast_uploaded_nologo400/8492474/8492474-1651144356560-b72ac52a8d048.jpg)
The [InfoSec] Stack
By Cleura

The [InfoSec] StackJun 20, 2022

It's not all bad
Not everything can be pitch black and negative around us. Today we are ending this season of The InfoSec Stack with some positive news and trends.
Pod Sweet Pod: https://cleura.com/podcast

The FISA-problem in a nutshell
The questions continue to come our way regarding the current use of American cloud services. What is the big problem, especially in relation to human rights? Today we're trying to give the simplest possible explanation as to what the problem is, how difficult it is to overcome the problem and what alternatives are available to find a solution to the problem.
Pod sweet pod: https://cleura.com/podcast

Bengt Johansson & Estonian digitalisation
Kim and Daniel cover 2 completely different topics. Daniel pays homage to a great inspiration in swedish leadership, and Kim talks about one of the world's most advanced digital societies.
Pod sweet pod: https://cleura.com/podcast

Google’s IP anonymisation is a useless protection
Today we're discussing this: "After the groundbreaking decisions by the Austrian and French DPA that the use of Google Analytics is illegal, the Austrian DPA has now issued a second decision, going even further: It declared the use of Google’s IP anonymisation a useless protection measure for data transfers between the EU and the United States. The DSB further rejected the notion of a “risk based approach” that had been argued by Google."
Pod Sweet Pod: https://cleura.com/podcast

A Swedish pharmacy whispered to Facebook
The Swedish, state owned pharmacy, Apoteket, whispered to Facebook about peoples purchases. We need to talk about this...
Pod sweet Pod: https://cleura.com/podcast

Workchronicles
Today we just have some fun and talk about our favourite comic strips from https://workchronicles.com/
Pod sweet pod: https://cleura.com/podcast

Von der Leyen VS Biden
Calm down and stop spreading false information. As of right now, this "new data transfer deal" is nowhere near being a deal. Two politicians shook hands and said that they should solve this thing - that's it!
Pod Sweet Pod: https://cleura.com/podcast

GDPR is a business opportunity
We often hear that GDPR stands in the way of starting up a business and it's time to address that ridiculous claim.
Pod Sweet Pod: https://citynetwork.eu/podcast

The Swedish Customs Authorities and the €30K fine for using Google Photos
The Swedish Customs Agency received a fine because some of their employees used Google Photos on their work phones. Wake up and smell the roses.
Pod Sweet Pod: https://citynetwork.eu/podcast

Ukraine
Our thoughts on the war in Ukraine and how we all can contribute to better cybersecurity.

Mea Culpa
Kim comes clean about a mistake and statement he made earlier.
Pod Sweet Pod: https://citynetwork.eu/podcast

Incompetence
Kim had a revelation when booking tickets to the theatre. How come IT projects aren't being handled as professionally as theatre shows?
Pod sweet pod: https://citynetwork.eu/podcast

Fonts vs Analytics in relation to GDPR
We love GDPR but why were we upset about the Google Fonts case, and not the Google Analytics cases? Let's explain...
Pod sweet pod: https://citynetwork.eu/podcast

Transferring data to a third country
We're digging a bit deeper into the wonderful world of GDPR. Today we're talking about definitions and data transfers to a third country.
Pod sweet pod: https://citynetwork.eu/podcast

Let's talk some more about GDPR
By popular demand we're back on the topic of GDPR. We thought we were kind of done, however done one can be with such a vast topic, but you still want more. Let's see where we stand three years after the law was taken into effect.
Pod Sweet Pod: https://citynetwork.eu/podcast

How an app is Ops:ed
Before the holidays we talked about apps and how they work. In this first episode of the season, we're taking things a bit further and explain how an app is running, or being Opsed as it might be known as in the future.
https://en.wikipedia.org/wiki/Computer
https://en.wikipedia.org/wiki/Hypervisor
https://en.wikipedia.org/wiki/Kubernetes
Pod Sweet Pod: https://citynetwork.eu/podcast

Happy new year!
We'll end 2021 by giving you our best tips on books, podcasts and youtube channels you really should check out during the holidays.
Daily Discipline podcast
https://www.tbriankight.com/podcast
The Cybersecurity Playbook
https://www.audible.co.uk/pd/The-Cybersecurity-Playbook-Audiobook/1469074915?qid=1639145002&sr=1-1&ref=a_search_c3_lProduct_1_1&pf_rd_p=c6e316b8-14da-418d-8f91-b3cad83c5183&pf_rd_r=3RDKXYE3ZKD0K6F1Q1JX
Jocko Podcast
https://jockopodcast.com/
Algorithms to Live By
https://www.audible.co.uk/pd/Algorithms-to-Live-By-Audiobook/B01D24I714?qid=1639145132&sr=1-1&ref=a_search_c3_lProduct_1_1&pf_rd_p=c6e316b8-14da-418d-8f91-b3cad83c5183&pf_rd_r=T8XQHG3009ZH4JXS2B6M
Georgia Dow
https://www.youtube.com/c/GeorgiaDow/featured

What is an app?
We are trying to be highly educational by popular demand and explain how an app works. We can't stress enough how important it is, especially for us who make IT-related decisions, to understand how things work in the digital world.
https://citynetwork.eu/podcast

What is The EU Cybersecurity Act?
We explain the The EU Cybersecurity Act. Learn more about this ground breaking, EU-wide cybersecurity certification framework for ICT products, services and processes.
https://citynetwork.eu/podcast
https://digital-strategy.ec.europa.eu/en/policies/cybersecurity-act

Betting on European suppliers instead of on the hyperscalers
This episode is centered around the recent news that the Swedish eSam collaboration program, which comprises representatives from government authorities, municipalities and other public administrations, have tested and evaluated a number of different office suites that comply with the public sector’s security, regulatory and functionality requirements. The project is a direct result of announcements earlier this year by the Swedish Enforcement Authority and Swedish Tax Agency that they are planning to actively consider alternatives to Microsoft Teams as a collaboration platform due to privacy concerns.
This ongoing trend of betting on European suppliers instead of the American and Chinese hyperscalers is a very interesting situation that seems to be on the verge of happening all across Europe.
We also talk about the lack of European suppliers of core digital services, EDPB and data transfers.

From the archives: A question to all taxpayers
Originally published on 21 June, 2021.
Is it possible to go through the digitalization without the three large, american hyperscalers? This is todays topic in The InfoSec Stack.

From head to toe - Episode 2
Today we're talking about how to succeed with your leadership when implementing change.
https://citynetwork.eu/podcast
https://citynetwork.se/podcast

From head to toe - Episode 1
Following our most recent mini-series about the technical sides of digital transformation, we now need to talk about the people responsible for making the change happen.
https://citynetwork.eu/podcast
https://citynetwork.se/podcast

From Start To Finish - Episode 3
The time has come to end the mini series "From Start To Finish" on the topic of digital transformation. At least for this time around. Now that we have learnt how to become digital from a technical point of view, we need to talk about efficiency and what the digitalization, and the entire change is supposed to lead to.
https://citynetwork.eu/podcast
https://citynetwork.se/podcast

From Start To Finish - Episode 2
In English: https://citynetwork.eu/podcast
In Swedish: https://citynetwork.se/podcast
We continue our mini series "From start to finish" and our take on Digital Transformation. Today we clarify what Front end, Back end and API's mean.

From Start To Finish - Episode 1
In English: https://citynetwork.eu/podcast
In Swedish: https://citynetwork.se/podcast
We are kicking off a miniseries called "From Start To Finish," in which we try to make sense of specific topics concerning the cloud industry. It's a miniseries in three episodes, and we start with the subject of Digital Transformation and where it all began.
![Welcome back to another season of The [InfoSec] Stack!](https://d3t3ozftmdmh3i.cloudfront.net/production/podcast_uploaded400/8492474/8492474-1600352408787-33b708c0655a9.jpg)
Welcome back to another season of The [InfoSec] Stack!
ENG: https://citynetwork.eu/podcast
SWE: https://citynetwork.se/podcast
We're back in business after some well-deserved vacation!
In today's episode, we round up what has happened in the world of GDPR during the summer. We also discuss the differences between American and UK ownership of a company or service after Brexit.

Summer reading tips
https://citynetwork.eu/podcast
Thank you for joining us during another season of The Infosec Stack! It is now time for us to take some time off and recharge our batteries. In the mean time, enjoy these summer reading tips and we'll see you again soon!
https://en.wikipedia.org/wiki/Factfulness:_Ten_Reasons_We%27re_Wrong_About_the_World_%E2%80%93_and_Why_Things_Are_Better_Than_You_Think
https://en.wikipedia.org/wiki/Astrophysics_for_People_in_a_Hurry
https://www.goodreads.com/en/book/show/42117336-you-are-worth-it

There are no unicorns!
https://citynetwork.eu/podcast
Today we're focusing on the EU Cloud Code of Conduct. Repeat after us: There are no unicorns! Despite what some may want you to believe..
https://www.codeofconduct.cloud/
https://eucoc.cloud/en/home.html

A question to all taxpayers
https://citynetwork.eu/podcast
Is it possible to go through the digitalization without the three large, american hyperscalers? This is todays topic in The InfoSec Stack.

From the archives: Here is what you need to do if you just can't live without Microsoft 365
Originally published 23 November 2020.
https://citynetwork.eu/podcast
With the GDPR and the legal situation we have regarding data protection within the EU, we often talk about how difficult, if not impossible, it is to use some of the world's largest cloud services. The recent dilemma of the invalidation of the important, legal, mechanism - Privacy Shield - makes it all the more difficult.
But what if one refuses to believe that there are any good alternatives? What if one firmly believes that the digital transformation can not be carried out with any other provider?
Well, then one should probably, first and foremost, realise how much one is depending on one single supplier and think about how healthy that might be. First and far most from a business continuity perspective but also when it comes to ones' data subjects' personal integrity.
But let's not be so negative all the time. We have really given this some thought and here are some tips for European companies who wants to, or just needs to, keep using Microsoft 365.

Some good things about the IT industry
https://citynetwork.eu/podcast
We have been talking a lot about the negative aspects of the IT industry lately. It's always easier to be negative and criticise so we made ourselves come up with a couple of positive aspects in this weeks episode.

From the archives: BCD culture and information security
Originally published 28 September 2020.
https://citynetwork.eu/podcast
Today we're discussing group culture, specifically how a Blame, Complain, and Defend-culture impacts information security. If you are one of those who thinks that information security is all about technical measures - tune in to this and listen to a different opinion.
https://www.youtube.com/channel/UCMctd-YoxlHTTjSU6-qkHJQ
https://www.tbriankight.com/

Kim's quest
https://citynetwork.eu/podcast
Kim embarks on a quest in the spirit of digitalisation. The question is, can, and if so, how can a digital meeting be made equivalent to a physical encounter between people. Is he just old and incapable of understanding and absorbing what the youngsters seem to have down to an art, or is there a point in finding other ways?

What has become of the it-industry?
https://citynetwork.eu/podcast
Today we're discussing how skewed the it industry has become.

We met with Johan Magnusson, Assoc. Prof. at the Dept. of Applied IT, University of Gothenburg
https://citynetwork.eu/podcast
We recently interviewed Johan Magnusson, - Associate Professor, division director and researcher in balancing of efficiency and innovation in the governance of digitalization. This is a summary of that interview which we conducted in Swedish.
About Johan
Johan Magnusson is Associate Professor at the Department of Applied IT, University of Gothenburg, head of the Informatics division and director of SCDI Gothenburg. He earned his PhD in Business Administration (Accounting) at Gothenburg University in 2012 following his Licentiate degree in Informatics in 2005.
Johans research concerns the balancing of efficiency and innovation in the governance of digitalization. He works closely with primarily executives to offer insights into how governance can be designed to enhance digital capabilities in large organizations, both in his research as well as in executive education. He is also highly active in the industrial community, with recurring keynotes and media appearances intended to increase the utilization of research findings. He is principal investigator in the Digital Government research consortium, where the researchers work with a research-based model for digital maturity in supporting the digitalization of the public sector.
More information about Johan, his research, keynotes, and projects can be found here: https://scdi.se/researchers/johan-magnusson/ (info in english)

A question about data request reports from Microsoft Trust Center
https://citynetwork.eu/podcast
One of our audience members asked us if the number of requests for customer data, presented by Microsoft, can be trusted when gag orders are at play. Here is our take on the matter.
Microsoft's U.S. National Security Orders Report: https://www.microsoft.com/en-us/corporate-responsibility/us-national-security-orders-report?activetab=pivot_1%3aprimaryr2
Microsoft Law enforcement request report: https://www.microsoft.com/en-us/corporate-responsibility/law-enforcement-requests-report
Fisa court on Wikipedia: https://en.wikipedia.org/wiki/United_States_Foreign_Intelligence_Surveillance_Court#:~:text=The%20United%20States%20Foreign%20Intelligence,United%20States%20by%20federal%20law
Our interview with André Catry: https://anchor.fm/the-infosec-stack/episodes/Summarising-our-chat-with-Andr-Catry-et5vom/a-a50ncqt

Rerun: The fall of Privacy Shield and the EDPB FAQ
Originally published on September 21, 2020.
On July 16, the Court of Justice of the European Union invalidated Privacy Shield as a mechanism for legal data transfers between the EU and the US. In this episode we're discussing this important ruling and a FAQ that the European Data Protection Board has compiled for stakeholders that are transferring personal data to cloud services such as Microsoft 365, Amazon AWS, Azure and Google G Suite.
Video: Max Schrems at the Hearing of the European Parliament on EU-US Data Transfers (26:30)
European Data Protection Board publishes FAQ document on CJEU judgment

Rerun: Best of luck with the Standard Contractual Clauses - The Privacy Shield saga continues
Originally published October 5, 2020
Today we're talking about data transfers to a third country with a focus on the U.S. due to the fall of Privacy Shield.
The Swedish Data Protection Agency has produced an excellent guide on the matter and today we're covering it thoroughly.
With the fall of Privacy Shield, everything regarding global digitalisation has turned upside down. Are we allowed to transfer, process and make data available to the U.S. Which legal mechanisms can you use to do so? What are Standard Contractual Clauses? We will of course not cover all of this in one go but rest assured that we'll come back to this subject in future episodes.
"The Old Directive" as mentioned by Kim

How to measure group development
https://citynetwork.eu/podcast
This week we're talking about group development and how to measure it. As the nice people we are, we brought along Andrea, one of newest employees who started working for City Network on the same day we recorded this episode.

How big is your arena?
https://citynetwork.eu/podcast
Today we're talking about behaviours, facades, and arenas. This episode is all about culture, values and unwritten rules and at the end, we tie it all together by explaining what all of this has to do with information security.
https://en.wikipedia.org/wiki/Johari_window

Looking forward to the next episode
https://citynetwork.eu/podcast
We weren't able to publish this weeks episode but we look forward to the next.

Summarising our chat with André Catry
https://citynetwork.eu/podcast
He is one of Sweden's most prominent IT-security professionals, former world champion in hacking, and an author. The [InfoSec] Stack had the pleasure of chatting with André Catry to learn more about him and his thoughts on GDPR, FISA 702, espionage, digitalisation, digital sovereignty, and much more.
The interview was done in Swedish and we are summarising it in English.

Regulations does not stop innovation, and business culture
https://citynetwork.eu/podcast
Today we're talking about regulations, and business culture. We mention monopolies in digitalisation, digital immaturity, and wether it's time to put our foot down.
We also talk about decision making and how that process works. The question is what a compass, knife, sweater, rope and water has to do with business culture?
Let's go!

Answering your questions and discussing differences in legal practice
Today we're answering questions about Google Analytics, have some follow-up on a Swedish news story and discuss legal practice in the US compared to elsewhere.

BRAVIN(G)
https://citynetwork.eu/podcast
Today we have reached the final letter in our 7 part bonus series about The Seven Elements of Trust.

Google Analytics after the Schrems II ruling
https://citynetwork.eu/podcast
Today we share some ideas on what you need to do in order to be able to use Google Analytics in a time when GDPR is in effect, and the Schrems II ruling has been filed. In short, you CAN continue to use Google Analytics but it requires you to take a number of actions to use it legally - in terms of regulatory compliance.
https://www.reuschlaw.de/en/news/dsk-adopts-minimum-requirements-for-the-use-of-google-analytics/

Everything you've always wanted to know about certifications
https://citynetwork.eu/podcast
Today we're diving deep into the world of information security certifications such as ISO, SOC, BSI C5 and other acronyms. We're explaining the different frameworks that we're familiar with and talk about what they are for, how they work and what you need to think about - both as a supplier and as a customer.

What is Infrastructure as a Service - IaaS
https://citynetwork.eu/podcast
We recently explained different types of cloud services, the benefits of using multiple providers, the economy of cloud services and a lot of other aspects that makes cloud services so great.
Today we're digging a little deeper to explain Infrastructure as a Service - IaaS.

A history lesson about City Network
https://citynetwork.eu/podcast
Today we bring you a history lesson about the company we work for, City Network. Why we do the things we do, why we provide the services we do, and why we are passionate about regulatory compliance in the cloud.
What started as a web hosting company, mainly aimed at individuals and small businesses, in 2002, has become something entirely different almost 20 years later.
Today we explain how we got to where we are today!