Uploaded August 2026 | Updated September 2026, 2 hours ago
Juha Haaga (Arctic Security, FI)
How do CERTs benchmark cybersecurity posture when available data is noisy, unverified, or incomparable? This presentation introduces a methodology for systematic security posture analysis using a selected set of verified cyber issue data, demonstrated across 8,000 categorized academic institutions in the United States and Europe.
We classify organizations by type, size, country, and public‑facing asset profile, then categorize issues into public exposure, known vulnerabilities, suspected compromise, and potential threats. Cross‑border findings reveal how security posture correlates with regulatory environments, governance models, and organizational resources—challenging common assumptions and informing priority‑setting for resource‑constrained organizations.
Education faces the highest attack rates of any sector yet lacks systematic comparative analysis. This research fills that gap while developing a transferable framework. CERTs can adapt this methodology for healthcare, government, finance, or any constituency they serve.
Attendees will gain a replicable benchmarking framework, a review of concrete cross‑border findings, and practical guidance for implementing sector‑wide posture analysis.
---
Juha Haaga leads Arctic Security's CSIRT Development Program, helping new national and sectoral CSIRT teams build early warning systems and navigate common obstacles. As Head of Customer and Market Engagement, he also leads research on large-scale cybersecurity data analysis. His 15 years working with national CSIRTs have focused on making threat data actionable, from production through consumption and distribution, and benchmarking. His background in software engineering, solutions architecture, and product management informs his practical approach to security metrics.
Juha Haaga (Arctic Security, FI)
How do CERTs benchmark cybersecurity posture when available data is noisy, unverified, or incomparable? This presentation introduces a methodology for systematic security posture analysis using a selected set of verified cyber issue data, demonstrated across 8,000 categorized academic institutions in the United States and Europe.
We classify organizations by type, size, country, and public‑facing asset profile, then categorize issues into public exposure, known vulnerabilities, suspected compromise, and potential threats. Cross‑border findings reveal how security posture correlates with regulatory environments, governance models, and organizational resources—challenging common assumptions and informing priority‑setting for resource‑constrained organizations.
Education faces the highest attack rates of any sector yet lacks systematic comparative analysis. This research fills that gap while developing a transferable framework. CERTs can adapt this methodology for healthcare, government, finance, or any constituency they serve.
Attendees will gain a replicable benchmarking framework, a review of concrete cross‑border findings, and practical guidance for implementing sector‑wide posture analysis.
---
Juha Haaga leads Arctic Security's CSIRT Development Program, helping new national and sectoral CSIRT teams build early warning systems and navigate common obstacles. As Head of Customer and Market Engagement, he also leads research on large-scale cybersecurity data analysis. His 15 years working with national CSIRTs have focused on making threat data actionable, from production through consumption and distribution, and benchmarking. His background in software engineering, solutions architecture, and product management informs his practical approach to security metrics.










