Skip to main content

André Leduc Receives M3AAWG 2016 JD Falk Award for Operation Safety-Net and CASL Work that Protects Online Users

Paris, France Oct. 25, 2016 – The lead architect of both a comprehensive report that demystifies online threats for the general public and an important Canadian law that has appreciably reduced spam has received the M3AAWG 2016 JD Falk Award for his contributions to a safer online world.  André Leduc was recognized for spearheading the global Operation Safety-Net best practices report and for his role in developing the Canadian Anti-spam Legislation that requires marketers to obtain users' permission before sending commercial email.

The award was announced Oct. 25 during the four-day M3AAWG 38th General Meeting in Paris. The Messaging, Malware and Mobile Anti-Abuse Working group presents the award annually to recognize an "unsung hero" working behind the scenes to protect the internet and end-users.

"Both of these accomplishments have been widely embraced by the anti-abuse community as valuable tools in fighting spam and other cybercrime. Operation Safety-Net makes cybersecurity accessible to mainstream, non-technical users by cutting through the complicated techno-jargon about keeping our devices safe, and the anti-spam law known as CASL has dramatically reduced junk mail in Canada and beyond. Neither of these projects would have come to fruition without Andre's meticulous attention to detail, his dedicated effort that went well beyond expectations, and his persistent leadership," said Michael Adkins, M3AAWG Chairman of the Board. 

Leduc is the acting director of business, intelligence and analysis, and digital security policy, at the Canadian Department of Innovation, Science and Economic Development. He also served as a voluntary secretariat co-lead for the London Action Plan/Unsolicited Communications Enforcement Network and facilitated the cooperative work between M3AAWG and LAP/UCENet that resulted in the jointly published report. A video with Leduc explaining the motivation behind these two projects is available on the M3AAWG YouTube channel at www.youtube.com/maawg.

Operation Safety Net for Business, Government and End-Users

Operation Safety Net – Best Practices to Address Online, Mobile, and Telephony Threats is a 76-page report written by security experts from around the world that describes current cyber issues facing business, government and end-users with the proven techniques to protect against them. Leduc spearheaded the project, which was originally requested by the Organisation for Economic Co-operation and Development, and compiled the submitted material into a coherent report.

Leduc said, "Translating our technical and engineering way of talking into plain language was probably the most important part of this work. We wanted to create a report that a security officer or an engineer could give to colleagues and management to help them understand cyber attacks and why their organizations might be targeted. We also wanted to make it easy for government policy makers in both the developed and developing countries, where they may not have much technical experience, to take action."

The original report was published in 2012 then updated in 2015. The latest version covers malware and botnets; phishing and social engineering; internet protocol and domain name system (DNS) exploits; and mobile, voice over IP (VOIP) and telephony threats.  Originally published in English, it has been translated into French and Spanish, reaching much of the world's population. The report is available in these languages at www.m3aawg.org under Best Practices.

CASL Effective Beyond Canada

Leduc also was the lead architect developing the policy and legal frameworks for the Canadian Anti-spam Legislation that set a new standard for sending marketing messages when it went into effect in 2014.  The law applies to commercial or promotional information sent through email, SMS, instant messaging or social media. It also covers software installations and mobile apps. 

CASL requires marketers to obtain a user's permission to receive a commercial message before it is sent, a process known as "opt-in" that is more effective in fighting abuse and spam. For example, under the law, users need to voluntarily sign up for a mailing list or have an existing business relationship with an organization before marketers can send them related emails. Since CASL applies to all messages sent to users in Canada, including those originating from other countries, it has encouraged the voluntary adoption of opt-in practices internationally.

"The volume of spam on Canadian networks has decreased by more than a third since CASL went into effect. We have also seen a high level of compliance from senders in the countries to our south, throughout Europe, and even in Asia. Many international senders are now getting consent prior to sending commercial electronic messages to our users," Leduc said.

Leduc began work on establishing the concepts and language for CASL in 2009.  He has specialized in cybersecurity since 2004 when he led OECD ecommerce business working groups and then became part of an expert subgroup on high-tech crimes in 2004. He has represented Industry Canada (now Innovation Science and Economic Development Canada) at the OECD, the G7 and G8 summits, and the Wassenaar Arrangement.

The M3AAWG 38th General Meeting is the organization's annual European meeting and has brought together more than 350 security experts from 30 countries.  The working meeting features more than 50 sessions with network operators, social networking companies, hosting and cloud services providers, email service providers, academic researchers and public policy advisors sharing information on the latest cyber threats. The next meeting will be February 20-23, 2017 in San Francisco.

About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks and other online exploitation. M3AAWG (www.M3AAWG.org) members represent more than one billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration and public policy. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3AAWG is driven by market needs and supported by major network operators and messaging providers.

#  #  #

Media Contact: Pr@m3aawg.org

M3AAWG Board of Directors: AT&T (NYSE: T); CenturyLink (NYSE: CTL); Cloudmark, Inc.; Comcast (NASDAQ: CMCSA); Facebook; Google; LinkedIn; Message Systems; Mailchimp; Microsoft Corp.; Orange (NYSE and Euronext: ORA); Return Path; SendGrid, Inc.; Charter Communications; Vade Secure; and Yahoo! Inc.

M3AAWG Full Members: 1&1 Internet AG; Adobe Systems Inc.; Agora, Inc.; AOL; Campaign Monitor Pty.; Cisco Systems, Inc.; CloudFlare; Dyn; Exact Target, Inc.; IBM, iContact; Internet Initiative Japan (IIJ, NASDAQ: IIJI); Liberty Global; Listrak; Litmus; MAPP; McAfee Inc.; Mimecast; Nominum, Inc.; Oracle Marketing Cloud; OVH; PayPal; Proofpoint; Rackspace; Spamhaus; Sprint; and Symantec.

A complete member list is available at /about/roster.

Time To Talk Digital Issues At WTO With Focus On Developing Countries, Forum Hears

https://www.ip-watch.org/2016/09/30/time-to-talk-digital-issues-at-wto-w...

. . . dealt with by internet governance organisations such as ICANN (Internet Corporation for Assigned Names and Numbers), the UN-backed Internet Governance Forum, Internet Engineering Task Force, and the Messaging Anti Abuse Working Group.

Exploring Cybersecurity Topics on a Whirlwind Tour of Eastern Europe

https://www.icann.org/news/blog/exploring-cybersecurity-topics-on-a-whir...

 ". . . I plan to take advantage of the opportunity to network with first responders, law enforcement and cybercrime forensic professionals from Europe and Eastern Europe. APWG and similar conferences (e.g., Messaging, Malware and Mobile Anti–Abuse Working Group – M3AAWG) are venues where the IS SSR team is most successful in building trust relationships and promoting participation in ICANN's multistakeholder community."

EXPERTS TO FCC: CHANGE COURSE ON BROADBAND PRIVACY RULES INDUSTRY GROUPS AND EXPERTS AGREE: THE FCC MUST CHANGE COURSE ON BROADBAND PRIVACY

Fixed Wireless Internet Service Providers Association 

http://www.wispa.org/News/wispa_news_06-08-16_Experts_to_FCC

"A coalition of industry groups including WISPA, CTA, CTIA, and US Telecom today published a joint article in opposition to the FCC’s proposed new rules for broadband privacy protection . . . The Messaging, Malware and Mobile Anti-Abuse Working Group similarly warned that the rules as currently framed could inadvertently undermine cooperation and communication needed to secure the web from malware, viruses and hackers online. . . "

Global Cyber Alliance Joins Forces with M3AAWG to Drive Industry Adoption of Cybersecurity Solutions

San Francisco, May 4, 2016 – Global Cyber Alliance – an organization founded by the New York County District Attorney's Office, the City of London Police and the Center for Internet Security – will be collaborating with M3AAWG to push the security community to more quickly adopt concrete, quantifiable practices that can reduce online threats. The non-profit GCA has joined the Messaging, Malware and Mobile Anti-Abuse Working Group, which develops anti-abuse best practices based on the proven experience of its members, and M3AAWG has become a GCA partner for the technology sector.

“Global Cyber Alliance is pleased to partner with M3AAWG, an organization that has worked for many years on operational issues of Internet abuse.  Both of us want to make a measurable difference in minimizing cyber risk, and we are confident that we can do so,” said Philip Reitinger, GCA President and CEO.

Launched in September 2015, Global Cyber Alliance's mission is to confront, address and prevent malicious cyber activity and improve the security of the connected world. It identifies and prioritizes areas of systemic cyber risk concentrating on measurable achievements, and has established Cyber Security Strategic Action Centres (CSAC) in New York and London.

In a recent announcement, GCA revealed that its first strategic area of concentration will be phishing with a focus on two solutions shown to be effective at combatting it: implementation of DMARC to limit spoofing of email and secure DNS practices to minimize the effect of phishing and other attacks.

M3AAWG has actively supported DMARC since its inception. It has also developed materials to help the industry fight phishing, including a video on using DNS "response policy zones” to protect against illegitimate websites, anti-phishing best practices for mailbox providers, and best practices to avoid potential problems for "parked" domains where email is not enabled. 

GCA will also participate in ongoing M3AAWG work and the two M3AAWG North American general meetings and its annual European meeting. The M3AAWG 37th General Meeting will be June 13-16 in Philadelphia, Pa., U.S.A., with over 50 sessions including the co-located i2Coalition annual meeting.

M3AAWG Chairman of the Board Michael Adkins said, "The most effective best practices won't amount to much if the industry neglects them. At M3AAWG, we're able to tap into our members' experience to identify what processes are working against cyber threats around the world. Even so, it can be challenging to achieve the widespread implementation of these practices to protect the ecosystem. GCA's focus on cross-sector implementation and measurement will address some of the confusion and apathy in the industry, and will help mitigate cyber risks."

About Global Cyber Alliance

Global Cyber Alliance (GCA) is an international, cross-sector effort dedicated to confronting cyber risk and improving our connected world. It is a catalyst to bring communities of interest and affiliations together in an environment that sparks innovation with concrete, measureable achievements. While most efforts at addressing cyber risk have been industry, sector, or geographically specific, GCA partners across borders and sectors. GCA’s motto “Do Something. Measure It.” is a direct reflection of its mission to eradicate systemic cyber risks.

GCA, a 501(c)3, was founded in September 2015 by the New York County District Attorney's Office, the City of London Police and the Center for Internet Security. Learn more at www.globalcyberalliance.org.

About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks and other online exploitation. M3AAWG (www.m3aawg.org) members represent more than one billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration and public policy. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3AAWG is driven by market needs and supported by major network operators and messaging providers.

#  #  #

Media Contact: Pr@m3aawg.org

M3AAWG Board of Directors: AT&T (NYSE: T); CenturyLink (NYSE: CTL); Cloudmark, Inc.; Comcast (NASDAQ: CMCSA); Cox Communications; Facebook; Google; LinkedIn (NYSE: LNKD); Mailchimp; Message Systems; Orange (NYSE: ORAN) and (Euronext: ORA); Rackspace; Return Path; SendGrid; Time Warner Cable; Vade Retro - OpenIO; Verizon Communications; and Yahoo Inc.

M3AAWG Full Members: 1&1 Internet AG; Adobe Systems Inc.; Agora, Inc.; AOL; Bluehost-Endurance; Campaign Monitor Pty.; Cisco Systems, Inc.; CloudFlare; Constant Contact (NASDAQ: CTCT); dotmailer; Dyn; ExactTarget, Inc.; IBM; iContact; Internet Initiative Japan (IIJ, NASDAQ: IIJI); Liberty Global; Listrak; Litmus; McAfee Inc.; Microsoft Corp.; Mimecast; Nominum, Inc.; Oracle Marketing Cloud; OVH; PayPal; Proofpoint; Spamhaus; and Symantec.

A complete member list is available at /about/roster.