All Posts By

John Exporter

Fryktkultur og lave utdanningskrav: skiller Luftfartstilsynet seg fra andre statlige tilsyn?

By | Uncategorized

Sorry, this entry is only available in Norwegian. For the sake of viewer convenience, the content is shown below in the alternative language. You may click the link to switch the active language.

Dette er et debattinnlegg. Det handler ikke om enkeltpersoner, men om en strukturell forskjell: hvilken kompetanse staten krever av dem som skal føre tilsyn — og hvorfor luftfart ser ut til å stille lavere formelle utdanningskrav enn sammenlignbare statlige tilsyn.

Et halvt århundre med flysikkerhetsforskning peker på det samme: ulykker forebygges best når folk tør å rapportere feil og nestenulykker åpent — og når de som fører tilsyn har den faglige bredden til å skille det som ser farlig ut fra det som faktisk øker risiko. På begge punkter er det grunn til å stille spørsmål ved norsk luftfartstilsyn.

Andre statlige tilsyn krever akademisk bredde

Gå gjennom stillingsutlysningene til de store statlige tilsynene, så ser du et tydelig mønster. For inspektør- og saksbehandlerstillinger kreves det som regel høyere utdanning — ofte mastergrad innen et relevant fagfelt:

  • Finanstilsynet — høyere økonomisk/juridisk utdanning, normalt mastergrad.
  • Havtilsynet (tidl. Petroleumstilsynet) — relevant ingeniør-/realfaglig høyere utdanning, ofte master.
  • Statens helsetilsyn — helsefaglig høyere utdanning, ofte kombinert med juridisk/administrativ kompetanse.
  • Statens jernbanetilsyn — relevant ingeniør- og sikkerhetsfaglig høyere utdanning.
  • Mattilsynet, Arbeidstilsynet og NSM — relevant høyere utdanning som hovedregel.

Begrunnelsen er den samme overalt: et tilsyn skal ikke bare kunne faget «på gulvet» — det skal kunne risikoanalyse, statistikk, systemtenkning, menneskelige faktorer, metode og forvaltningsrett. Det er den akademiske breddeforståelsen som gjør at en inspektør kan vurdere reell risiko, ikke bare synlige enkeltavvik.

Luftfartstilsynet: piloterfaring framfor akademisk bredde?

Operative inspektører i luftfarten rekrutteres i stor grad på flygererfaring. Og la det være helt klart: den erfaringen er uvurderlig. Ingen leser en operativ virkelighet bedre enn en som selv har sittet bak stikka i krevende oppdrag. Problemet er ikke at pilotkompetanse er til stede — det er at den i mange tilfeller står alene, uten den akademiske breddeutdanningen andre tilsyn krever som et minimum.

Konsekvensen er en smalere verktøykasse. Når tilsynet i hovedsak hviler på operativ erfaring, blir vurderingene lett basert på «slik gjorde vi det» framfor systematisk, etterprøvbar risikometodikk. Det er nettopp her moderne flysikkerhet har beveget seg — bort fra telling av enkeltavvik og mot Safety Management Systems (ICAO Annex 19), der man måler risiko på systemnivå.

Når smal kompetanse møter fryktkultur

Hver av disse to tingene er håndterbar for seg. Det er kombinasjonen som er farlig.

Et tilsyn med smal faglig bredde, men ydmyk og lyttende kultur, vil fange opp sine egne blindsoner gjennom dialog med operatørene. Et tilsyn med bred akademisk kompetanse og en viss autoritær stil kan likevel lande riktig, fordi vurderingene er metodisk forankret. Men et tilsyn som er både smalt i kompetanse og preget av frykt, lukker begge utganger: det mangler verktøyene til å se hele bildet selv, og det skremmer bort den eksterne korreksjonen som kunne kompensert.

Resultatet er velkjent fra sikkerhetsforskningen: underrapportering. Operatører deler ikke det de er usikre på, fordi usikkerhet straffes. Da forsvinner nettopp de svake signalene som god sikkerhetsledelse lever av. Kjernen i europeisk luftfart kalles just culture — ærlige feil møtes med læring, mens grov uaktsomhet fortsatt får konsekvenser. EASA og EUROCONTROL har gjort dette til et bærende prinsipp.

Poenget i én setning: Smal kompetanse blir særlig uheldig når den møtes med en fryktkultur — da forsvinner den faglige dialogen som skulle korrigert den.

Tre spørsmål til Luftfartstilsynet

1. Hvorfor lavere formelle utdanningskrav enn andre tilsyn?

Hvis Finanstilsynet, Havtilsynet og Statens jernbanetilsyn krever mastergrad eller tilsvarende for sine inspektører — hva er den faglige begrunnelsen for at flysikkerhet skal kunne forvaltes med snevrere formelle krav?

2. Hvordan sikres akademisk bredde i tillegg til operativ erfaring?

Operativ erfaring og akademisk bredde er ikke motsetninger — de er komplementære. Hvilke krav stilles til risikometodikk, menneskelige faktorer og systemtenkning, ut over selve flygererfaringen?

3. Hvordan måles tilsynets egen kultur?

Andre sektorer måler jevnlig sin egen sikkerhets- og tilsynskultur. Måler Luftfartstilsynet hvordan det selv oppleves av dem det fører tilsyn med — og publiseres resultatet?

Veien videre: bredde og tillit, ikke enten–eller

Svaret er ikke å erstatte pilotene med akademikere. Svaret er begge deler: behold den operative erfaringen, men løft de formelle kompetansekravene opp på linje med andre statlige tilsyn — og kombiner det med en ekte just culture. Et tilsyn som både kan faget bredt og inviterer til åpenhet, får se de virkelige risikoene. Et tilsyn som er smalt og fryktet, får bare se det operatørene tør vise.

I Heliwing jobber vi systematisk med HMS og åpen rapportering — fordi trygg helikopterdrift bygger på kompetanse og tillit, ikke på frykt.

Tilsvar: Dette er et debattinnlegg. Påstandene om kompetansekrav og kultur gjengir kritikk fra bransjen og er ment å reise spørsmål — ikke å felle en dom over enkeltpersoner. Mange dyktige fagfolk i Luftfartstilsynet har bred utdanning. Luftfartstilsynet er velkommen til samtidig imøtegåelse, og vi publiserer gjerne tilsvar. Kontakt: sogn@heliwing.no.

Kilder og bakgrunn: ICAO — Safety Management (Annex 19); EUROCONTROL — Just Culture; Finanstilsynet, Havtilsynet, Statens helsetilsyn og Statens jernbanetilsyn (kompetansekrav i stillingsutlysninger); James Reason: «Managing the Risks of Organizational Accidents».

Microsoft Azure does not meet the Norwegian Security Act

Microsoft Azure does not satisfy the security law – Powerline companies should sound the alarm

By | , Myndigheter, Uncategorized
⚠ ALARM · Security and data sovereignty

Microsoft Azure does not meet the Norwegian Security Act – grid companies should sound the alarm

Classified information about Norwegian power infrastructure ends up in a US cloud that does not meet the requirements of the Security Act. It can prove costly – quite literally, with daily fines.

Map of pylon positions and power-line corridors in a Norwegian grid – classified grid data under the Norwegian Security Act
A complete overview of pylon positions and line corridors draws a map of critical infrastructure – exactly the kind of information the Security Act is designed to protect. The screenshot (from Strøm.app) is a randomly chosen example and does not imply that this case is particularly relevant to the grid company in this area.

Today's unpredictable international situation makes protecting information about critical infrastructure more relevant than ever. Yet a number of Norwegian grid companies store sensitive grid data in Microsoft Azure – a cloud that, in my view, does not meet the requirements of the Security Act.

The Norwegian Security Act and NSM: what the law requires of grid companies

The Norwegian Security Act (sikkerhetsloven) is administered by the Norwegian National Security Authority (NSM) and is designed to protect values worthy of protection – information, information systems, objects and infrastructure of importance to basic national functions. Power supply is one such function. This means that critical infrastructure in the power sector may contain elements that are classified under the law.

Among other things, the law imposes strict requirements on encryption, storage and processing of classified information. Security-graded information must be handled in information systems approved for the purpose, and cryptographic solutions must be approved by NSM. In the event of breaches, the authorities can issue orders – and impose coercive fines, i.e. ongoing daily fines – until the matter is rectified.

The core of the alarm: Information that collectively describes Norwegian power infrastructure – for example pylon positions and line corridors at grid companies – may be subject to protection. If such information is stored in Microsoft Azure, both the storage and the processing software may be in breach of the Security Act.

When pylon positions become classified information

A single pylon is no secret. But a complete, aggregated overview of every pylon, corridor, junction and weak point in a grid draws a detailed map of critical infrastructure. Aggregated information can have a completely different protective value than the individual pieces on their own. It is precisely this aggregation the Security Act is meant to protect – and it is exactly this kind of dataset that is increasingly being collected, not least through helicopter-based powerline inspection.

Why Microsoft Azure breaches the requirements of the Security Act

In the 1990s I led one of Norway's largest channels for Microsoft volume licensing agreements, and I know the company well from the inside. That is precisely why I am sounding the alarm: the problem is not that Microsoft delivers poor technology – it does not. The problem is jurisdiction and control.

Microsoft is established in the USA and is subject to US legislation, including the CLOUD Act. It gives US authorities the legal basis to demand the disclosure of data from American companies – regardless of whether the data physically sits on a server in Norway or the EU. A "Norwegian" Azure region does not change who ultimately holds legal control over the data.

For classified information this is decisive. You cannot simultaneously meet the Security Act's requirement of Norwegian control and store the data in an infrastructure where a foreign state has legal grounds for access. Azure therefore does not, in my view, meet the Security Act's requirements for storing such data – yet this is exactly what a number of companies use.

Classified data must be stored physically in Norway

A central point is where the data physically resides. For classified information, the physical storage must take place at a geographic location that enables national control – which in practice means in Norway. Without a Norwegian location, there is no real possibility for Norwegian authorities to enforce control over the data.

Microsoft Azure does not store this data in Norway. The very precondition for meeting the Security Act therefore falls away – regardless of how good the encryption or the technology may otherwise be.

Physical location is not a detail – it is a requirement: Classified data must be stored at a geographic location that enables national control, i.e. in Norway. If it is stored outside the country, as in Microsoft Azure, the requirement is, in my view, not met.

The processing software for line inspection must also be approved

Many think only about where the data is stored. But the Security Act also applies to the processing. If the data from a line inspection is classified, then the processing software – the tools that analyse, store and present the inspection data – must also be approved for the purpose. An analysis tool running as a service in Azure inherits the same jurisdictional problems as the storage.

Three warnings to grid companies using Microsoft Azure:
  1. The data is not stored physically in Norway. Classified information must be stored at a location that enables national control – in Norway. Azure does not do that.
  2. The cloud service does not meet the Security Act for storing classified information – also because of US jurisdiction over the data.
  3. The processing software for line inspection must also be approved if the data is classified – it is not enough to "move the server to Norway".

Azure lock-in: popular today, dangerously expensive over time

Microsoft Azure is a popular product. But over time it can become dangerously expensive. Azure is a proprietary system that "locks" the customer into a closed architecture – difficult and costly to get out of again. The barrier to use is high, and operation typically requires support from an in-house IT department and/or an external IT agency.

This is entirely in line with Microsoft's fundamental philosophy: hand out cheap – lock in – expand features – and open the door to extensive use of expensive external consultants and IT agencies.

What we are seeing with Azure is Microsoft's channel strategy striking again – just as in the 1990s and later: get everyone onto a closed, proprietary system they never get out of, but on which the vendor earns handsomely. All controlled by Microsoft in the USA.

Here is how the machinery works: Azure is "pumped" into the market by the IT companies Microsoft has "authorised" as Azure partners – and they profit handsomely from it. The losers are small and medium-sized businesses without their own IT department: a low entry threshold lures them in, the business is locked in, costs rise over time, and there is no real way out. And at the heart of it all: no national control over data security.

Wake up!

Europe has already woken up: Denmark and Germany are leaving Microsoft

This is not a distant theory. Several European authorities have already begun to disconnect from Microsoft – for exactly the same reasons I am warning about here: digital sovereignty, cost and the CLOUD Act.

Denmark: The Ministry of Digital Affairs, led by Minister of Digital Affairs Caroline Stage Olsen, replaced Microsoft Office 365 with open source (LibreOffice) in 2025, and is moving towards Linux. The stated reason: to reduce dependence on foreign technology and regain control over its own data.

The municipalities are following suit: Both Copenhagen and Aarhus are phasing out Microsoft. Danish municipalities' spending on proprietary software rose sharply – in Copenhagen by up to 72% over five years – from DKK 313 million to DKK 538 million between 2018 and 2023. In Aarhus, operating costs were cut from around DKK 800,000 to about DKK 225,000 per year after the switch.

Germany: The state of Schleswig-Holstein is moving around 30,000 workstations from Microsoft to open source, and expects to save tens of millions of euros over time.

When entire state administrations and major cities in neighbouring countries are moving out of Microsoft for the sake of sovereignty – why should the most sensitive data about Norwegian power infrastructure sit in Microsoft Azure?

The Security Act and Azure: what grid companies should do now

  • Carry out a value assessment: Are pylon positions, corridors and inspection data, taken together, classified? Take the question to NSM if you are in doubt.
  • Map where the data actually resides physically, and require storage in Norway at a location that enables national control – not just which "region" has been selected.
  • Assess the processing software, not just the storage – the whole chain must hold.
  • Choose solutions with genuine Norwegian control for anything that is classified.

The international situation is unpredictable, and which national legislation applies in the country where the supplier is established ought to ring a few bells at Norwegian grid companies currently building on Microsoft Azure. Within the Heliwing system we believe data about Norwegian power infrastructure belongs under Norwegian control.

Right of reply: This is an opinion piece. The claims reflect the author's assessments and industry experience, and are intended to raise an important question – not to deliver a final legal verdict. Microsoft and affected parties are welcome to respond, and we will gladly publish replies. Contact: salg@heliwing.no.
Sources
  • The Norwegian Security Act (sikkerhetsloven) – Lovdata
  • Norwegian National Security Authority (NSM) – nsm.no
  • NSM – Basic principles for ICT security and guidance on the Security Act – nsm.no/regelverk
  • U.S. CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) – congress.gov
  • Denmark's Ministry of Digital Affairs drops Microsoft Office – The Record / Computing
  • Copenhagen and Aarhus choose open source – EU Open Source Observatory
  • Schleswig-Holstein leaves Microsoft (30,000 workstations) – VARINDIA
error: Content is protected !!