SecurityCafé

"Sovereignty Is the Wrong Word": Digital Autonomy with Mika Lauhde


Listen Later

SecurityCafe — "Sovereignty Is the Wrong Word": Digital Autonomy with Mika Lauhde

Hosts: Menno van der Horst & Quint Ketting Guest: Mika Lauhde, Luxembourg House of Cybersecurity (linkedin.com/in/mika-lauhde-4270711)

About this episode

Mika Lauhde spent 30 years across Nokia, Huawei, and ENISA before landing at Luxembourg House of Cybersecurity, the national hub keeping Luxembourg's municipalities, SMEs, and economy cyber-resilient. His argument: Europe has the wrong word. Not "sovereignty" — hard borders around who owns what — but autonomy: acting independently while still sharing tools and trust. From GPS glitches during US foreign policy disputes, to Europe always getting the second-best tech (fighter jets included), to a national CERT running entirely on open source — this one covers a lot of ground.

In this episode
  • 00:11 — Welcome & Mika's background (Nokia, Huawei, ENISA, Luxembourg House of Cybersecurity)
  • 02:08 — News: an integrator data-leak claim ("888") and what makes integrator breaches different
  • 06:06 — Android's new developer certificate as a "kill switch," African nations building their own internet, UK VPN/age-verification rollout, an EU "tech sovereignty" proposal that leans on non-European hardware
  • 09:11 — A US court ruling that may have quietly broken a GDPR assumption on data transfers
  • 10:34 — NIS2 finally live in NL (15 Aug) — are our laws fast enough for machine-speed attacks?
  • 19:20 — The "SplinterNet," and why Mika argues for shared autonomy over walled-garden sovereignty
  • 23:46 — The Cyber Resilience Act's unprecedented recognition of open source (79 mentions)
  • 24:19 — AI models as the new trade weapon — allies get the previous generation, like fighter jets
  • 26:50 — The GPS/Galileo story, and SES's Iris² as Europe's answer to Starlink
  • 30:15 — EU tax rules that quietly disadvantage open source; the Nokia N900 as Europe's "Sputnik moment"
  • 33:00 — Luxembourg's national CERT runs entirely on open-source tools
  • 34:40 — The call to action: a free open-source toolkit so any EU SME can stand up a cyber ops center
  • 36:41 — What to read: Quint's, Mika's, and Menno's picks
  • 41:04 — Wrap-up
Key takeaways
  • Autonomy, not sovereignty — sharing open standards beats walling off borders
  • Dependency is invisible until it breaks — GPS glitches led to Galileo, now to Iris²
  • New tech follows old patterns — AI models, like military hardware, come second-best to allies
  • Open source is operational, not aspirational — Luxembourg's CERT proves it at national scale
Mentioned

Accenture leak claims (unconfirmed) · NIS2 (NL) · Cyber Resilience Act · European OSPO network · SES Iris² · Trump v. Slaughter ruling Reads: The Subtle Art of Not Giving a Fck* by Mark Manson (markmanson.net/books/subtle-art) · Max Schrems / noyb (noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers) · Bert Hubert's blog (berthub.eu)

SecurityCafe is hosted by Menno van der Horst and Quint Ketting. Powered by Atos.

...more
View all episodesView all episodes
Download on the App Store

SecurityCaféBy Quint Ketting Menno van der Horst