0:00
-6:44
Don’t have time to read, or simply want to enjoy it while moving on with your day? Press the play button, and listen to the article!
Welcome to the INSTAR Interview Series — where we bring you original insights from the people shaping Europe's digital future through international standardisation.
We’re kicking off with Erik Andersen, an independent consultant with decades of experience in cybersecurity standardisation. Funded through CYBERSTAND.eu and active in the INSTAR Cybersecurity/eID Task Force, Erik's current focus is on decentralised Public Key Infrastructure (DPKI) and the migration of cryptographic algorithms.
This conversation dives into the technical, political, and strategic challenges facing Europe, and why coordinated action is needed now more than ever.
“My CYBERSTAND.eu-funded work focuses on the Migration of cryptographic algorithms for cybersecurity and decentralising Public Key Infrastructure (DPKI).”
At the heart of Erik's work is the effort to adapt Europe’s cybersecurity framework for a future that is increasingly decentralised and quantum-vulnerable. He is currently focused on building the foundation for a federated DPKI system, based on blockchain principles. This would allow various PKI domains to co-exist and interoperate, reducing the risk posed by any single point of failure and improving trust in digital communications.
DPKI isn’t just a buzzword—it represents a necessary shift from centralised control towards systems where trust is distributed and verified through cryptographic mechanisms. According to Erik, this model could make secure communication both more resilient and scalable.
“It will be necessary to migrate big areas at the same time like a whole country or maybe the whole EU... this could be input to the European Commission to have a common approach in the EU.”
The urgency around coordinated cybersecurity migration stems from the complex and resource-intensive nature of implementing new cryptographic standards. Erik stresses that small-scale or fragmented efforts are unlikely to achieve the desired level of trust and interoperability.
By taking a pan-European approach, Member States could avoid duplication of effort, reduce costs, and ensure that infrastructures like digital IDs, vaccination certificates, and cross-border services can function seamlessly across national boundaries.
Such coordination could also give the EU a strategic advantage on the global stage, helping it shape international standards rather than merely adopt them later.
“I am mostly seeing interest from the Far East. Regarding DPKI, I have received input from two different universities in Korea... The most eager participant, however, is from China... they have already started implementation.”
While Erik has found little traction in the Western world so far, the story is different in Asia. Universities in Korea are actively exploring DPKI, and China has already begun implementation. This underscores a crucial point: standard-setting is a race, and other regions are accelerating.
If Europe does not move quickly to establish its own models and frameworks, it may find itself in a position where it must adopt standards developed elsewhere—ones that may not align with its values or regulatory frameworks.
This makes Erik’s work not just relevant, but strategically vital for European sovereignty in the digital space.
“We are living in a very dangerous world right now with a lot of tensions... We are afraid of cyber attacks and my goal is to help get cyber security in place.”
Cybersecurity isn’t a theoretical issue. Erik points to rising geopolitical tensions, the increasing frequency of cyber attacks, and the urgent need for robust, reliable infrastructure to protect sensitive data and communication channels.
However, he is also realistic about the barriers to progress. A major one? People.
“What’s truly required are resources, specifically people to do the work... Unfortunately, there’s a shortage of individuals with the right expertise.”
Companies are often reluctant to commit their staff to long-term standardisation work, even though the benefits of these efforts will serve the entire digital ecosystem for years to come.
Erik has a long history of bringing theory into practice. He has contributed extensively to technical committees in ITU, ISO/IEC, and IEC, with real-world impact.
“X.509 is the basic specification for public key infrastructure, and I have been the editor for that now for 15 years.”
This standard underpins countless systems and services that we rely on every day. Erik is also working on newer standards like X.510 and has contributed to cybersecurity frameworks in sectors like energy (IEC TC57/WG15), where real-time operational demands create even more complex security needs.
In other words, Erik isn’t just imagining solutions—he’s building them.
“I definitely see value in initiatives like CYBERSTAND.eu and INSTAR — they can make a real difference.”
Initiatives like CYBERSTAND.eu and INSTAR provide the financial and institutional support necessary to bring highly technical ideas into policymaking spaces. Erik believes they are crucial in bridging the gap between technical working groups and European policy.
By supporting experts to engage deeply with standardisation bodies, these projects ensure that Europe’s digital infrastructure is built on principles of trust, transparency, and security.
“It takes time to get up to speed and truly understand what's going on... no companies seem willing to dedicate people for the long term.”
Developing standards isn’t just about having good ideas – it requires deep knowledge, consistent participation, and the ability to navigate often slow-moving international bodies.
But industry tends to prioritise short-term outcomes. Erik argues that without long-term investment in skilled professionals, the EU risks falling behind.
“I believe it’s really the responsibility of society to step in and address this issue.”
He suggests that national or EU-level programmes could fund technical experts to work within standardisation organisations, much like how diplomats are deployed.
This isn’t just a conversation about algorithms or infrastructure. It’s about how Europe defines trust, cooperation, and sovereignty in the digital age.
“Europe has a critical task ahead to ensure it has the necessary cybersecurity infrastructure.”
As the world becomes more digitised and more volatile, standardisation becomes a geopolitical tool. Erik Andersen's work shows that building the right foundation now will determine not only how secure our systems are, but who controls them.
📌 Enjoyed the read?
Subscribe to the INSTAR Interview Series for more conversations with the experts building the future of Europe's digital ecosystem.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.