www.thalesgroup.com Security in critical infrastructures Business Cluster Semiconductors @ NedCard Nijmegen, 14 february 2014 lukas.roffel@nl.thalesgroup.com CTO Thales Nederland B.V. OPEN Collective intelligence for a safer world Whenever critical decisions need to be made, Thales has a role to play. In all its markets — aerospace, space, ground transportation, defence and security — Thales solutions help customers to make the right decisions at the right time and act accordingly. World-class technology, the combined expertise of 65,000 employees and operations in 56 countries have made Thales a key player in keeping the public safe and secure, guarding vital infrastructure and protecting the national security interests of countries around the globe. A balanced revenue structure Revenues in 2012 14.2 billion euros Shareholders (at 31 May 2013) (workforce at 31 Dec. 2012) Float French State 27% % 47 of which Global presence 56 45% 55% Employees 65,000 Civil Defence employees 3% countries Dassault Aviation 26% Research and development 2.5 billion euros (approx. 20% of revenues) Corporate Communications – January 2014 OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Profile 2 / Dual markets Military & Civil AEROSPACE SPACE GROUND TRANSPORTATION DEFENCE TRUSTED PARTNER FOR A SAFER WORLD WHEREVER SAFETY AND SECURITY ARE CRITICAL, THALES DELIVERS. TOGETHER, WE INNOVATE WITH OUR CUSTOMERS TO BUILD SMARTER SOLUTIONS. EVERYWHERE. Corporate Communications – January 2014 OPEN SECURITY This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Markets we serve 3 / THE CRITICAL DECISION CHAIN SECURITY / INTEGRITY Data gathering Secure data transmission Observation and electronic surveillance satellites Secure communication networks Sensing Radars Optronics Sonars Electronic warfare Inertial Passive sensors Etc. Cryogenics UAVs and airborne reconnaissance systems Ground-based surveillance and intelligence Data processing > Information Decision support Action Command systems Jamming Air and rail traffic supervision Missiles and other armaments Tactical datalinks Combat management systems Satcoms Advanced information processing Air traffic management Radio communications Data fusion and big data Rail traffic management (imagery, video, semantics) Etc. Etc. Airspace surveillance Etc. Thales solutions help customers to make the right decisions at the right time and act accordingly Corporate Communications – January 2014 OPEN Assessment Information from sensors, data gathering systems and data transmission and processing systems This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Whenever critical decisions have to be taken, Thales has a role to play 4 / A strategy driven by innovation 5 / ● 20% of revenues invested in R&D ● Focus on key technical domains • Complex systems • Hardware (sensor technologies) ALBERT FERT scientific director of the CNRS/Thales joint physics unit and winner of the 2007 Nobel Prize in Physics. • Software • Algorithms and decision support ● Open research policy Thales confirmed as one of the world's most innovative companies for the second consecutive year, in Thomson Reuters 2013 Top 100 Global Innovators • International network of research centres • Cooperation with academic and government research institutes worldwide ● Focused product policy • Shorter development cycles • Risk reduction Inventing tomorrow’s products today Corporate Communications – January 2014 OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Long-term vision Ground Transportation 6 / Boosting the capacity and efficiency of transportation systems with improved safety, lower costs and better passenger services Corporate Communications – December 2013 OPEN Serving ground transportation operators, infrastructure managers, integrators, EPCs… ● Optimising rail and road infrastructure N 2 • Safety Worldwide in rail signaling • Efficiency World leader in • Traveller services ETCS systems (European Train Control System) for mainline rail networks CBTC solutions (Communications-Based Train Control) for urban rail networks ● Rail & Public Transport • Train Control for mainline and urban rail • Route & Operation Control Integrated communication and supervision systems for transportation networks Fare Collection systems • Field Elements • Tramways & LRT • Fare Collection Management ● Roads Driving improvements in transportation safety and efficiency • Tolling, Traffic Management, Car Park Management Corporate Communications – January 2014 OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Ground Transportation 7 / Signalling systems for urban transport networks, with CBTC: 56 metro lines over 30 cities: London Undergroud, Vancouver SkyTrain, Dubai, Shanghai, Beijing, Istanbul, Hong Kong, New York, South Korea, … Operation Control and integrated communications & supervision for rail networks: Caracas, Dubai, Athen, Manchester, Paris, Brussels, Bangalore, Istanbul, Mecca, Guangzhou, Hong Kong, Copenhagen, Florence, Lausanne, … Fare collection systems: Netherlands, Auckland, Toronto, Beijing, Santo Domingo, Oslo, Lisbon, Mexico, New Delhi, Bangkok, Cairo, Singapore, Gautrain, … Signalling systems for main line rail with ETCS: Spain, Switzerland, Mexico, Austria, Germany, Poland, Turkey, South Korea, Saudi Arabia, Denmark, Portugal, Hungary, etc. Corporate Communications – January 2014 OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Ground Transportation references 8 / © THALES NEDERLAND B.V. AND/OR ITS SUPPLIERS Subject to restrictive legend on title page 9 / Corporate Communications – January 2014 OPEN THALES NEDERLAND B.V. Date. reference This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. © THALES NEDERLAND B.V. AND/OR ITS SUPPLIERS Subject to restrictive legend on title page 10 / Corporate Communications – January 2014 OPEN THALES NEDERLAND B.V. Date. reference This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. 2013: 1.906.196.268 +6,74% 2012: 1,8 miljard 2010: 900 miljoen 2009: 250 miljoen 1.906.196.268 Sinds de start van het systeem in 2005 zijn tot nu toe totaal 6,3 miljard transacties gegenereerd. 2013 Inmiddels 18,5 miljoen OV-chipkaarten geproduceerd. Hiervan zijn er 13,6 miljoen actief: 8 miljoen persoonlijke OV-chipkaarten en 5,5 miljoen anonieme OV-chipkaarten. 2012 Per week worden gemiddeld 2,8 miljoen kaarten gebruikt. 2011 2010 2007 Corporate Communications – January 2014 OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. OV Chipkaart in figures 11 / Level 4 Integrated Transit Hub Level 3 THALES Central Processing Systems Level 2 Light Rail & -Trail Products Range W AN Station Processing Systems Depot Process Systems WiFi Level 1 W AN LAN Level 0 BUS & Tram Products Range Front End Equipment Contactless Smart Tickets & Cards Fare Media Corporate Communications – January 2014 OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Architecture 12 / © THALES NEDERLAND B.V. AND/OR ITS SUPPLIERS Subject to restrictive legend on title page 13 / Station Lelylaan TVM 20.04 OPEN Extreme damage, TVM total loss, missing parts internally. TVM needs to be replaced. Corporate Communications – January 2014 This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Roadmap of contactless technologies and extended applications E-purse / micro-payments — Parking meters — Retail — Fast food — Vending machines — Public facilities — Museums — Cinemas — Taxis Corporate Communications – January 2014 Integration with banking world Mobile phones — Mastercard — Near Field PayPass Communication (NFC) technology — Visa Cash — Co-branding with — Mobile phone replaces fare media — Download fare — Timetables — Routes OPEN — Access control for offices — University applications banks — Libraries — Integrate with — E-tolls — Card credit and other payment cards products and additional applications Other customisation This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Beyond Smart Card and Transport 15 / Security 16 / Developing integrated solutions, resilient networks and value-added services to protect citizens, sensitive data and critical infrastructure Corporate Communications – December 2013 OPEN A comprehensive approach 17 / 21 NATO member countries 19 of the 20 largest banks in the world 3,000 financial institutions worldwide Securing over 70% of the payment transactions 4 out of 5 top energy companies 4 out of 5 aerospace companies Supporting governments and enterprises worldwide in order to protect: Critical Information Systems Critical Industrial Information Systems (e.g. SCADA) Critical Embedded Information Systems Critical global systems Sensitive data And to prevent unpredictable events with integrated & resilient solutions Corporate Communications – January 2014 OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Thales products currently protect data for: States (e-border, border surveillance, national security, identity) More than 250 million secure identity documents in over 25 countries. French market leader in civil biometric systems Cities (Urban security) Mexico - Ciudad Segura: urban security for Mexico City, the most complex urban security system in the world Saudi Arabia: Security of the Mecca pilgrimage France: Security of public sites in Paris Critical Infrastructure (airports, sensitive sites, energy) 4 major international hubs: Dubai, Doha, Durban airports and Singapore Changhi airport France: securing the Defence Minister’s new site, Balard Corporate Communications – January 2014 Cyberspace: security products and solutions in 50 countries (25 NATO countries). Protection of 70% of the world's banking transactions . TEOPAD, a secure professional environment for smartphones and tablets OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Security references 18 / Thales IT Security Services offer solutions that protect organizations from threats and vulnerabilities while reducing the costs and complexity of security: Business risk analysis and compliance IT security architecture design IT security training & awareness Disaster Recovery Plan (DRP) & Business Continuity Plan (BCP) Crisis management Dedicated penetration testing services focusing on business applications and network security Incident response Audit and Risk analysis Corporate Communications – January 2014 ISO 17999 ISO 27001 Security solutions Security policies OPEN EBIOS Security management This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. IT Security Services 19 / Protection • • • • Mistral Datacryptor ECHINOPS TCE 621 Network security Corporate Communications – January 2014 Active defense • TEOPAD • nShield connect • nShield Solo • nShield edge • THEMIS • ELIPS • Security Gateway • CYBELS • iStop Mobile security Security Modules Crosslevel Hypervision OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Thales Portfolio 20 / TEOPAD – Smartphones & Tablets security 21 / Mobility cause multiple threats to data security In business, only 17% of data is secure Teopad creates a secure desktop for business applications Support all available applications on the market Hardware based authentication (option) Encryption of stored and exchanged data Secure phone calls (SIP-TLS, SRTP) Secure access to corporate network (TLS VPN) Large choice of Smartphone (Android) A leading edge solution to secure professional apps on smartphones & tablets Corporate Communications – January 2014 OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. 250 million mobile workers in 2013 ● Today, nation’s critical infrastructure and defense are more interconnected on the Internet than ever before ● Increased connectivity brings increased risk thus making cybersecurity one of most important national security priorities ● Improve the detection, analysis, mitigation and response to sophisticated cyber threats, provide effective countermeasures against such attacks iStop CYBELS CYBELS CYBELS Vulnerability Scanner Sensor View Practice Corporate Communications – January 2014 OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Cyber-Security Hypervision 22 / © THALES NEDERLAND B.V. AND/OR ITS SUPPLIERS Subject to restrictive legend on title page Balard Ciudad Segura IT Security solutions for physical access control system Risk analysis and security review for Mexico Urban Safety program Bionet Uzbekistan Biometric Passport Security expertise and HSM for biometric visa application management (FR) Corporate Communications – January 2014 Security policy and security hardening of enrolment stations OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Security references 23 / © THALES NEDERLAND B.V. AND/OR ITS SUPPLIERS Subject to restrictive legend on title page 24 / Corporate Communications – January 2014 Iridium Galileo EGNOS Component Evaluation Galileo security IOC & FOC Accreditation support OPEN Space references Athena FIDUS Security study This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. © THALES NEDERLAND B.V. AND/OR ITS SUPPLIERS Subject to restrictive legend on title page 25 / Corporate Communications – January 2014 Netherlands Risk analysis, Security Policy, Crisis Management and HSM Risk analysis support and penetration testing for Urban Rail (TORONTO) Danish Travel Cards Security review before the system goes live EU FP7 SECUR-ED Cybersecurity scenario Ground Transportation references OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved. Corporate Communications – January 2014 26 26 26/ // © THALES NEDERLAND B.V. AND/OR ITS SUPPLIERS Subject to restrictive legend on title page Questions? OPEN This document is not to be reproduced, modified, adapted, published, translated in any material form in whole or in part nor disclosed to any third party without the prior written permission of Thales.© THALES 2013 – All rights reserved.