Cern Progresses on Cybersecurity Upgrades Following External Review
Cern has announced that it is making steady progress on the 73 cybersecurity enhancements recommended by an external audit conducted last summer.
On August 16, the international nuclear research facility reported that a third-party firm carried out the audit in mid-2023, generating 82 recommendations. The Cern director general endorsed 73 of these suggestions, many of which were either already planned or in progress.
The audit assessed Cern’s cybersecurity measures against global standards outlined in the CIS v8 framework, chosen for its compatibility with Cern’s existing protocols and priorities.
While none of the recommendations were deemed critical, they ranged from significant to minor, including updates such as implementing two-factor authentication and revising outdated policies from the early 2000s.
The implementation of the recommendations not already in progress began in the last quarter of 2023 and is expected to continue into 2024 and 2025.
This audit, part of a five-year internal review strategy, involved interviews conducted by the external firm. Given the heightened global risks to public infrastructure, cybersecurity remains a top priority.
Cern’s internal audit committee, representing member states, will determine the schedule for future cybersecurity evaluations.



