2026/9 Weekly Update from the EU ISAC for Cities & Regions: GRC solution progressing – data loads in progress and CIS controls added / Classifying and prioritising IT related data / EUROPEAN COUNCIL OF ISACS (EU-CI) agrees on a charter
** For Back Issues see https://isac4cities.eu/blog **
The City ISAC (I4C+) is an Information and Analysis Centre whose members are IT and cyber security decision makers exchanging knowledge to improve their cities and collective cyber resilience. I4C+ is a Special Interest Group (SIG) hosted by Major Cities Europe (MCE). Dr. Oliver Schwabe is a member of MCE and in his function Chair of the ISAC for Cities Plus (I4C+). He is the person in charge of this effort on behalf of MCE and the responsible contact person. I4C+ is recognized by the European Agency for Cybersecurity ENISA. See https://isac4cities.eu/.
Discussion Summary
Hi everyone – again full house this morning with our Crisam GRC friends sharing progress on the current pilot with colleagues from Bulgaria, Italy, Ireland, and Luxemburg joining. Reviewed further adjustments (i.e. CIS controls loaded, control remediation measures introduced), progressing on data loading of the first risk register, and again practised conducting a basic risk review using the solution. Now moving to the question of what standard IMPACT assessment criteria might look like – very different approaches, and perhaps the effect of incidents on the supported business services might help (i.e. disrupt or degrade with relevant estimated recovery times) – the conversations here show we have a way to go, however in the end it is probably a conversation among the stakeholders to achieve agreement that is key. We also looked at how entries from our MISP might help understand threats faced by an asset and / or business process.
One interesting discussion prompted by an IT leader of one of our participating city administrations (about 130k citizens) was how to get started in classifying and prioritising IT related data. Clear view from the ISAC perspective is that there are some key steps (a) list the services offered to citizens (b) filter for those related to national security (i.e. Safeguards against espionage, sabotage, or other threats to national stability.), (c) filter for those that use GDPR related data, (d) filter for those where you operate (versus manage or subscribe) the digital solutions supporting these services, and (e) filter for those covered by your SOC. Then ensure your incident management process is word-class -> after that the needed controls and actions become a little more specific to your context. Happy to support in this sensemaking and we are beginning to see how the GRC solution is helping us structure and guide the thinking. My guess would be that the very first digital solution you need to really fortify is your citizen registry.
Great news that the EUROPEAN COUNCIL OF ISACS has now (finally) agreed on a charter and voted to adopt it. We are among the founding members, and I will share more about activities as soon as the officers are voted in by the end of the summer. Some initial details below:
“SECTION ONE: MISSION & PURPOSE
The mission of the European Council of ISACs (EUR CI) is to enhance the robustness and resilience of European cyber infrastructure across national borders for the members of its participating Information Sharing and Analysis Centres (ISACs) by fostering cross-sector collaboration, sharing of best practices and information, and collective defence. The Council will coordinate shared strategic initiatives, enhance collective situational awareness, promote best practices, and assist in capacity building to better protect the European digital ecosystem. Where appropriate it will serve as a unified liaison to relevant public authorities in Europe.
The EUR CI’s Objectives, Goals, and Deliverables are to:
- Maintain and enhance inter-ISAC coordination to improve communication, trust, and collaboration across sectors;
- Partner with other regional councils (e.g. NCI) and other ISACs;
- Establish and maintain a dialogue with the governmental entities that interface with ISACs, including providing a direct connection between EU cyber agencies and the entities affected by directives, policies and procedures to help in ensuring easily actionable support;
- Encourage outreach to other entities as appropriate to fulfilling the Council mission;
- Consider the potential global reach of ISACs;
- Identify and address/resolve ISAC community issues, especially ISAC operations and operational policy;
- Develop and maintain a practical, manageable data and information sharing protocol: what and how to share;
- Develop analytical methods to assist the ISACs to support their own sectors and the other sectors with which there are interdependencies;
- Strive to provide a trusted forum to enable collaboration on all hazards and threats;
- Identify and disseminate knowledge, best practices and lessons learned;
- Support cross-sector participation in exercises.
The European Council of ISACs is a voluntary and collaborative organisation managed by European ISACs for the benefit of Europe’s critical infrastructure and digital ecosystem while acknowledging that threat actors and cybersecurity defence have no borders. It actively seeks and encourages all infrastructure to be represented on the Council.”
Cheers
Oliver
| ISAC Services (Member Funded) |
We have published our services at Services Offered – EU ISAC for Cities (isac4cities.eu). Please do review and consider reaching out to include such in your activities and budgets.
Note that emerging new services are related to managing the MISP platform (and onboarding) plus Barista.
Please remember you can reach the whole group via city-isac-i4c-tlpwhite@majorcities.eu. A dedicated group for those cities signing the NDAs is available separately.
Also note our LinkedIn organisational page at https://www.linkedin.com/company/eu-city-information-sharing-and-analysis-center-isac/ and our discussion group at https://www.linkedin.com/groups/12773643/. Do follow us / join.
Thank you for the support, your City ISAC I4C+ Team.
Cheers and ever onwards
Oliver
Innovating our Future… Together
Chair City ISAC I4C+ / Dr. Oliver Schwabe.
Email: oliver.schwabe@isac4cities.eu Mobile: +49 (0) 1709053671. Web: https://i4c.isacs.eu/ & https://www.majorcities.eu/isac-for-cities-plus/