Large‑Scale DDoS Attack Disrupts Norway’s Digital Identity Services and Public Portals
What Happened — A massive distributed denial‑of‑service (DDoS) attack targeted the infrastructure of Vivicta, the IT partner for Norway’s Digitalisation Agency (Digdir). The assault lasted more than 30 hours, taking ten public digital services offline, including the national identity gateway ID‑porten used by 4.5 million citizens.
Why It Matters for Compliance & Audit Readiness
- The outage shows why SOC 2 Availability controls (CC6.1) and a documented incident‑response plan must be in place and auditable.
- Continuous monitoring of third‑party service health and DDoS‑mitigation provisions is a core element of vendor‑risk management under SOC 2 Trust Services Criteria.
- Capturing mitigation steps, logs, and communications provides the defensible evidence auditors expect for the “System Operations” principle.
Who Is Affected — Government agencies, digital‑identity providers, health‑care portals, and any business that relies on Norway’s public‑service APIs.
Recommended Actions —
- Map the DDoS event to SOC 2 Availability controls; retain traffic logs, mitigation actions, and stakeholder communications as audit artifacts.
- Verify that contracts with third‑party providers include DDoS‑mitigation clauses and that you receive continuous performance‑monitoring reports.
- Conduct a tabletop exercise to test response procedures for prolonged service‑disruption scenarios. Source: https://therecord.media/norway-cyberattack-ddos-government
Technical Notes — The attack flooded Vivicta’s front‑end servers with volumetric traffic, overwhelming bandwidth and application layers. No data exfiltration or credential compromise was reported. Source: https://therecord.media/norway-cyberattack-ddos-government