Summary

  • Hans Petter Holen's public record connects early Norwegian internet-service building, RIPE community chairing, address-policy work, ASO/NRO number-resource governance, and current RIPE NCC executive leadership.
  • RIPE NCC identifies Holen as Managing Director and Chief Executive Officer, says he became Managing Director in May 2020, and describes his earlier RIPE Chair service from 2014 to 2020.
  • The strongest article case is not personality biography. It is institutional continuity: how a person who helped build early ISP operations later moved through the community and registry structures that keep IP addresses, ASNs, registry data, and trust services credible.
  • The profile must keep RIPE, the open technical community, distinct from the RIPE NCC, the membership association and Regional Internet Registry for Europe, the Middle East, and parts of Central Asia.
  • The available record supports a careful account of stewardship and operating accountability, not a claim that one executive alone determines RIPE, RIPE NCC, or global RIR outcomes.

Hans Petter Holen matters because the internet's most consequential infrastructure is often the least visible to the public. People see websites, outages, roaming indicators, cloud regions, fibre trenches, mobile coverage maps, and sometimes the drama of platforms failing in public. They rarely see the registries and communities that make the internet's identifiers reliable enough for all of those systems to coordinate. IP addresses and autonomous-system numbers do not feel like infrastructure in the same way a cable landing station or data centre does.

Yet when their records are unreliable, when policy legitimacy fails, when registry trust erodes, or when routing-security services are neglected, the internet's operating fabric becomes harder to defend.

Holen's public record is useful because it crosses the layers where that fabric is made. RIPE NCC identifies him as Managing Director and Chief Executive Officer, responsible for day-to-day operations and reporting to the Executive Board. RIPE governance pages identify him as RIPE Chair from May 2014 to August 2020. Official and conference biographies connect him to Oslonett, described in those profiles as one of Norway's first internet service providers, and to address-policy and global number-resource roles long before he became RIPE NCC chief executive. Those facts do not make him the author of the internet number registry system.

They place him inside a rare sequence: builder, community chair, policy entity, and registry executive.

That sequence is the story. It turns a professional biography into a map of internet authority. The first layer is operating memory. A person who helped build an early ISP does not meet registry governance only as a matter of paperwork. The operator's view starts with reachability, routing, customers, upstreams, records, and the practical cost of making services work. The second layer is community legitimacy. RIPE is not a company, not a regulator, and not a network service provider.

Its earliest terms of reference describe a forum for coordinating IP networking and exchanging technical information among parties operating wide-area IP networks. Chairing that community means working with consensus, mailing lists, meetings, working groups, and institutional memory rather than command. The third layer is registry management. The RIPE NCC is the Regional Internet Registry for Europe, the Middle East, and parts of Central Asia, and its work includes allocation and registration of IPv4, IPv6, and ASNs as well as services such as the RIPE Database, RPKI, RIPE Atlas, RIPEstat, RIS, and K-root support.

The combination matters because number-resource governance is not just administration. It is operating trust. An access provider needs address space and public registration data. A cloud or hosting provider needs records that other networks can validate. A national research network needs contactability and routing visibility. A regulator or security team may need to understand who is associated with a network resource without turning the registry into an arm of enforcement. A routing-security deployment needs a resource-certification base that networks can rely on.

A member-funded registry needs to invest in these systems without losing the legitimacy that comes from member accountability and community process. Holen's public roles sit at the junction of those demands.

The profile begins in Norway, not because Oslonett by itself explains the RIPE NCC, but because it gives Holen's later institutional work an operator's shadow. RIPE NCC's speaker profile says he was one of the co-founders of Oslonett, described there as one of the first internet service providers in Norway. ICANN's archived meeting biography makes the same broad point from an external event context, identifying Oslonett as an early commercial ISP and placing Holen among its founders.

RIPE NCC and foundation biographies also connect him to later Nordic internet and network roles, including Schibsted Nett, Scandinavia Online, Allt om Stockholm, Alt om Kobenhavn, Tiscali Nordic, and Visma.

The important point is not to turn that career list into nostalgia. Early ISP work carried a different kind of scarcity. The internet was not yet a universal utility hidden behind polished consumer experiences. Operators had to make basic questions visible: who holds the address space, how do networks exchange reachability, where does technical coordination happen, how do policy decisions affect real service delivery, and how does a small market connect to a global system without losing local accountability.

A person formed in that period would later encounter RIPE and the RIPE NCC not as abstractions but as the coordination layer behind practical connectivity.

That background helps explain why Holen's RIPE Chair years are central to the article. RIPE is an open technical community. It is not identical to the RIPE NCC, even though the RIPE NCC provides secretariat support and operates the registry institution in the same ecosystem. This distinction is easy for outsiders to miss. It is also one of the reasons Holen's transition from RIPE Chair to RIPE NCC Managing Director is so revealing.

His own 2020 RIPE Labs explanation of the chair role emphasized independence, trust, workload, and the need to keep clear lines between the less formal community and the legally structured membership organization. That was not a ceremonial concern. It was a governance boundary.

RIPE's previous-chair pages show the timing clearly. Rob Blokzijl chaired RIPE for a quarter century. Holen became RIPE Chair in May 2014 and served until August 2020. RIPE later lists Mirjam Kuhne and Niall O'Reilly as the chair team after that transition. The public record also shows that Holen did not simply inherit an informal role and leave it unchanged. The RIPE Chair selection process document records the community's move toward a more open, transparent, community-endorsed process after the Rob Blokzijl era.

Holen is among the authors of that document, which matters because it shows a community converting trust from personal continuity into institutional procedure.

That conversion is a recurring theme in internet governance. Many infrastructure institutions begin as communities of people who know one another and trust one another's competence. As they become critical to markets, public services, security, and national economies, informal trust is no longer enough. But if they move too far toward corporate command, they can lose the bottom-up legitimacy that made them credible. The RIPE Chair selection process is a small but precise example of the balance: make the role more accountable and repeatable without pretending that a community chair is the same as an executive appointment.

Holen's own account of the chair workload gives texture to that balance. The role included RIPE meetings, regional meetings, member lunches, roundtables, coordination with the RIPE NCC and Executive Board, working group chairs, the Programme Committee, mailing lists, other RIR meetings, ICANN, IETF, ISOC, and other operator communities. That list is not glamorous. It is institutional maintenance. It is the work of keeping a distributed technical community legible to itself while the surrounding internet becomes more commercial, regulated, security-sensitive, and politically important.

The address-policy dimension deepens the picture. RIPE NCC's previous-chair profile says Holen chaired the RIPE Address Policy Working Group from 1998 to 2013 and was elected to the ASO Address Council from 1999 to 2013, serving for ten years as ASO AC Chair. ICANN's archived meeting biography corroborates the address-policy and ASO/NRO context. These roles are easy to reduce to acronyms. They should not be. Address policy is where abstract scarcity becomes operational rule. It is where registries, members, networks, transfers, documentation, regional norms, and global coordination meet.

IPv4 scarcity made that world even more consequential. The ecosystem around transfers, legacy space, address-market due diligence, and IPv6 transition has made number-resource stewardship more public than it once was. The approved record for this profile does not support a detailed claim about Holen personally designing any one scarcity rule or market outcome. It does support a broader observation: his public career runs through the policy and governance bodies that had to convert address scarcity, allocation legitimacy, and regional coordination into workable practice.

That is why the move to RIPE NCC chief executive is more than a promotion. RIPE NCC's "What We Do" material describes an independent, not-for-profit membership organization that supports internet infrastructure through technical coordination in its service region. Its service catalogue shows a broad operating surface: registry services, resource certification and RPKI, RIPE Database, the LIR Portal, RIPE Atlas, RIPEstat, RIS, DNS root-server support, training, and community coordination. The public may hear "registry" and imagine a static list. The actual operating surface is dynamic.

It involves data quality, authentication, legal and compliance pressure, member service, technical resilience, transparency, security, and trust in records that many networks use indirectly every day.

Holen's executive role therefore sits in a narrow corridor. On one side is underinvestment. Registry systems age, security expectations rise, members depend on services that were not designed for today's threat environment, and routing-security infrastructure becomes more important as networks adopt RPKI and route-origin validation. On the other side is legitimacy risk. A member-funded registry cannot simply declare every cost necessary and expect consent.

It must explain why investment is needed, how it serves members, how accountability works, and why independent infrastructure should be financed before failure makes the case obvious.

Holen's 2026 RIPE Labs article, "Independent Infrastructure Requires Investment," is useful because it says that quiet part in public. He frames RIPE NCC services as independent infrastructure that members and the wider internet rely on. He links investment to core registry systems, security, compliance, technical resilience, and services such as RPKI and measurement. Because the piece is written by the chief executive, it is not independent validation of every budget priority. Its value is different. It shows the management argument: the RIPE NCC is not merely preserving a historic registry.

It is asking members to keep funding the trust infrastructure that modern routing, registry accuracy, and operational coordination increasingly require.

That argument is uncomfortable in the right way. Infrastructure is easiest to fund after it breaks, and hardest to fund while it works. If the RIPE Database is reachable, RPKI services function, measurement tools keep reporting, the LIR Portal works, and member support continues, a registry can appear uneventful. But uneventful operation is the product. A Regional Internet Registry is supposed to be boring in the way a reliable control room is boring: not because it is simple, but because many small failures are prevented before they become public.

The RIR system adds another layer of responsibility. The RIPE NCC is one of five Regional Internet Registries. The Number Resource Organization brings those RIRs into a shared coordination layer, and its Executive Council consists of the chief executives or equivalent leaders of the five registries. NRO material on Internet Coordination Policy 2 describes the formal recognition framework for RIRs. Even when the article does not need to dwell on procedural detail, the existence of that framework matters. It shows that the RIR system is not just a set of private organizations holding address records.

It is a governed institutional system whose legitimacy depends on regional service, community support, openness, neutrality, and global coordination.

Holen's 2021 RIPE Labs piece on supporting the internet number registry system provides a clear view into that institutional philosophy. Written during pressure around AFRINIC, it argues against destabilizing the RIR system or treating one RIR's difficulties as an invitation for another to take over registry functions. The article's point is not that the RIPE NCC can or should adjudicate every dispute in another region. It is that the number registry system depends on regional communities, established procedures, and continuity. For this profile, the lesson is not about one legal dispute.

It is about the operating ethics of restraint. A registry's power is partly the power not to overreach.

That restraint is part of what makes number-resource governance infrastructure rather than bureaucracy. Address records and ASNs are technical facts, but the trust around them is institutional. If the registry is seen as arbitrary, captured, inattentive, or politically convenient, then every service built on its records inherits a little more uncertainty. If the registry is accountable, transparent, technically competent, and bounded by community rules, then networks can use its records with less friction.

Holen's public writing and role history repeatedly return to this boundary: keep the community healthy, keep the registry stable, and avoid confusing executive authority with community legitimacy.

Membership accountability is the least theatrical but perhaps most practical part of the story. RIPE NCC members pay the fees that support the organization. They use the registry, request resources, maintain records, vote, attend meetings, and challenge decisions. They are not a passive customer base in the way a consumer app has customers. They are also part of the governance environment. The same member that depends on RPKI, registry accuracy, and secure portals may entity to fees, investment levels, or policy direction.

A chief executive in this setting has to manage services, budgets, staff, compliance, and technical resilience while respecting a membership model that expects explanation rather than mere instruction.

The practical consequences show up in small, recurrent ways. A local internet registry wants a portal that works, clear invoices, reliable resource records, useful training, and a support process that does not treat policy as mystery. A security-conscious operator wants RPKI and authentication systems to be available, documented, and stable enough to integrate into production operations. A researcher wants measurement and routing information that can be interpreted without guessing how the underlying service is governed. A public agency wants the registry to be dependable without turning it into an instrument of political convenience.

These expectations are not identical, and some of them are in tension. A member organization is where those tensions become operating questions rather than slogans.

That is why the article's topic is institutional continuity rather than executive charisma. Continuity sounds passive, but in registry work it is active. It means preserving old records while modernizing systems around them. It means making IPv4 scarcity governable while still encouraging IPv6 deployment. It means maintaining contactability and accountability while respecting privacy, law, and proportionality. It means keeping community policy processes open enough for legitimacy and structured enough for decisions to have operational meaning.

It means explaining why infrastructure that users rarely notice still deserves money, security attention, and governance discipline.

The RIPE Database illustrates the point. In everyday language, a database can sound like a back-office store. In this context, it is part of how networks, resource holders, and technical communities make allocation and contact information visible. Its usefulness depends on accuracy, authentication, data stewardship, abuse-contact expectations, and the willingness of members to keep records current. The RIPE NCC does not become trustworthy merely by hosting the service. Trust accumulates through policy, implementation, support, transparency, and the ability to correct or improve the service without breaking the community's expectations.

Holen's executive role is relevant because those are management problems as much as technical ones.

RPKI adds a newer version of the same issue. A certification system turns registry data into material that can be used by routing-security tools. That raises the stakes for availability, key management, software quality, documentation, and incident handling. If networks begin to treat RPKI outputs as part of production route validation, then the registry's trust service moves from helpful add-on to operational dependency. That does not mean every network will deploy the technology in the same way, or that RPKI alone can solve route leaks and hijacks.

It means the registry has to understand that a service built on number-resource authority can become part of routing infrastructure once operators rely on it.

Measurement services create a different kind of dependency. RIPE Atlas, RIPEstat, and RIS are not registries in the narrow allocation sense, but they help operators and researchers make the internet observable. The public value of these services comes partly from their institutional home. A commercial platform may measure the internet for its own optimization. A public-interest registry can provide measurements and routing views that help many actors reason about outages, reachability, interconnection, and deployment trends.

That public value still requires servers, probes, software maintenance, documentation, community trust, and budget choices. The service exists only because the institution keeps choosing to operate it.

This is where Holen's early operator background and later governance work meet in a concrete way. Operators tend to respect systems that reduce uncertainty. Community entities tend to respect processes that do not conceal power. Registry executives have to join those instincts together. A useful service that is poorly governed can lose legitimacy. A legitimate process that does not maintain reliable services can lose relevance. A technically elegant system that members cannot afford or understand can create its own distrust. The public record around Holen does not prove that he has solved those trade-offs.

It shows why he is a credible lens through which to examine them.

The global context makes the trade-offs harder. The RIPE NCC serves a region that includes Europe, the Middle East, and parts of Central Asia. That is not one legal system, one market, one language, or one security environment. Members range from large carriers and cloud providers to local ISPs, hosting companies, universities, public institutions, and specialist networks. Some are mature operators with large policy teams. Others depend heavily on registry guidance and community norms. A governance model that works only for the largest members would fail the region.

A service model that ignores scale, security, and compliance would also fail it. Continuity requires serving the full membership without pretending their needs are identical.

The RIR system's regional design is meant to help with that complexity. A single global address registry might look efficient from far away, but it would be less able to absorb regional practice, law, language, member culture, and local operating realities. The five-RIR model is not frictionless, and it can be tested by crisis. But it gives each region a community, a registry institution, and a route into global coordination. Holen's public roles in RIPE, RIPE NCC, ASO/NRO contexts, and the NRO Executive Council setting make him a person through whom that regional-global balance becomes visible.

His 2021 writing on the number registry system is especially important here because it resists a tempting centralization story. When one RIR faces pressure, the apparently efficient answer might be for another trusted RIR to step in. Holen's public argument was more cautious: do not destabilize the system, do not override regional community authority, and do not turn continuity into takeover. That position can be debated, but it is institutionally coherent. The RIR system depends on regions being accountable to their own communities.

If one registry's difficulties become a reason for another to assume authority, the whole model begins to look less like bottom-up stewardship and more like emergency centralization.

Emergency centralization can be attractive because it promises speed. Internet governance usually survives by refusing that temptation until it is genuinely necessary. It asks whether process, legitimacy, and local accountability can solve the problem first. That can be slow and frustrating, but the alternative has costs. A registry system that treats crises as permission to ignore community boundaries may solve one problem while weakening the basis for future trust. Holen's public record places him on the side of continuity through restraint, not continuity through institutional expansion.

Holen's career gives him a credible vantage point for that tension. The Oslonett and Nordic network background places him close to the operator side of the house. The RIPE Chair period places him close to the community consensus side. The RIPE NCC executive role places him in the management and resource-allocation side. Those are different forms of authority. Operators want practical service. Community entities want legitimacy and openness. Registry executives need to keep critical services funded and secure. None of those interests is illegitimate, but they can pull against one another.

The person profile matters because Holen has publicly occupied all three positions.

There is also a security story here, but not a simple one. RIPE NCC service descriptions include resource certification and RPKI, and Holen's current executive writing emphasizes security and technical resilience. RPKI is not a cure-all for routing insecurity. It helps networks validate whether an origin AS is authorized to announce a prefix, but deployment choices, route filtering, operational discipline, and policy still matter. The RIPE NCC's role is to provide a trustworthy certification and registry foundation for its service region.

The article should therefore avoid claiming that Holen or the RIPE NCC "secured routing" in some sweeping sense. The more accurate claim is that the registry institution operates part of the trust base that routing-security practice now increasingly depends on.

The same restraint applies to RIPE Atlas, RIPEstat, RIS, and other information services. These tools make parts of the internet more observable. They can help operators, researchers, and policy communities understand reachability, routing, measurements, and network conditions. They do not replace commercial observability, national measurement, or operator telemetry. But because they are provided by a membership-funded registry institution with a public technical mission, they contribute to a common evidence base. That is another reason "registry" is too small a word for the RIPE NCC's public role.

The K-root element points to the same breadth. The RIPE NCC supports operations related to one of the DNS root-server letters. A reader does not need a root-server tutorial to understand the significance. The root-server system is part of the DNS infrastructure that lets names resolve at global scale. It sits in a different technical layer from IP address allocation, but both depend on institutional trust, operational redundancy, and careful coordination. A registry organization that touches both number resources and root-server support is managing more than forms and member accounts.

Holen's public profile also intersects with broader governance and advisory roles. RIPE NCC's current structure page places him in the NRO Executive Council context and lists additional advisory or supervisory roles, including ICANN RSSAC Vice Chair and Open CSIRT Foundation supervisory-board chair. Current titles can change and should be read as status at the time of access, not permanent identity. Still, they reinforce the article's main point: the modern RIPE NCC executive sits in a web of identifier coordination, DNS-root advice, incident-response trust, and registry-system cooperation.

That web is not a hierarchy. No single RIR controls the internet. No RIPE Chair speaks for every RIPE entity. No executive can command global routing hygiene by decree. The internet's institutional architecture is more complicated and more fragile than that. It relies on overlapping communities whose legitimacy comes from service, competence, openness, and repeated cooperation. Holen's significance is that his documented career makes those overlaps visible. He is not the system. He is a useful person through whom to explain the system's continuity problem.

The continuity problem has changed since Oslonett. In the early commercial internet era, the central question was often how to get networks connected and services running.

Today, the questions include how to keep number-resource records trustworthy under legal, geopolitical, economic, and security pressure; how to maintain RPKI and registry systems under stronger compliance expectations; how to fund independent infrastructure when members are cost-sensitive; how to support IPv6 deployment while IPv4 scarcity still shapes behavior; how to keep open community processes credible when infrastructure governance has public-policy consequences; and how to make services resilient enough that their success looks boring.

Those questions are not solved by biography. But a biography can show why the questions belong together. A builder understands that identifiers are operational. A RIPE Chair understands that community legitimacy cannot be replaced by management convenience. A RIPE NCC chief executive understands that critical services need budgets, staff, security, compliance, and implementation roadmaps. Holen's public record is valuable because it links those forms of knowledge without collapsing them into one role.

The RIPE Chair selection process is one of the clearest examples. The community could have treated Rob Blokzijl's long tenure as a tradition to repeat informally. Instead, the public documents show a move toward selection, terms, a nominating committee, and community endorsement. Holen's name on that process document is not just a historical footnote. It is evidence of a community that understood succession as infrastructure. A chair role that depends only on personal trust may work for a time. A chair role with open selection and accountability has a better chance of surviving generational change.

Succession matters in registry institutions too. RIPE NCC's leadership history includes long service, evolving services, shifting legal environments, and changing member expectations. Holen took over as Managing Director in 2020, a moment when the internet had already become essential public infrastructure and when the pandemic would soon make network dependence even more visible. The approved sources for this article do not support a detailed operational history of that transition.

They do support the larger reading: the RIPE NCC moved from one long-serving executive era into a period where registry infrastructure, security expectations, and member accountability had to be explained with new urgency.

The public-policy environment has also changed. Governments care more about cyber resilience, sanctions, data accuracy, critical infrastructure, and network abuse. Law-enforcement and security communities care about contactability and attribution. Operators care about practical routing and resource management. Members care about cost and service. Civil society worries about overreach. A registry must sit among these interests without becoming simply a regulator, a police tool, or a private market gatekeeper.

Holen's public comments on RIR-system restraint and independent infrastructure investment show a leadership posture that tries to hold those boundaries in view.

That posture is not immune to criticism. Member-funded institutions should be challenged on budget growth, service priorities, staffing, transparency, and strategic focus. RIPE NCC leadership materials are not independent proof that every proposed investment is correct or that every member concern has been answered. Likewise, public profiles are not independent character studies. The responsible reading is narrower: the records show what roles Holen held, what institutions he served, what services the RIPE NCC operates, and how he publicly frames the need for continuity, independence, transparency, and investment.

The caveats matter because internet-infrastructure profiles can easily become institutional praise. A more useful profile treats institutions as operating systems with failure modes. The RIPE NCC can face member trust pressure. RIPE community processes can become hard for outsiders to understand. RPKI can create dependency and availability expectations. Registry data can be incomplete, contested, or misused. IPv4 scarcity can create transfer markets and due-diligence problems. Global RIR coordination can be tested by litigation, governance crises, or geopolitical pressure. The article's thesis is not that Holen eliminates those risks.

It is that his career places him in the roles where those risks have to be managed.

This is also why the "Norwegian ISP builder" detail should be kept in proportion. It is not a decorative origin story and not a claim that early ISP founders are uniquely qualified to run RIRs. Its relevance is practical. Oslonett and the later Nordic internet roles place Holen in the generation that saw the internet become commercial and operational before it became fully backgrounded. That experience helps explain why registry issues are not merely legal or administrative. They affect how networks are built, identified, routed, and trusted.

The "former RIPE Chair" detail carries a different weight. It shows proximity to community legitimacy. A chair in a bottom-up technical community cannot operate like a corporate executive. The role depends on trust, neutrality, facilitation, and the ability to keep technical disagreements productive. Holen's 2020 chair-commitments piece makes the independence issue explicit, especially after he became RIPE NCC Managing Director. That moment is valuable because it exposes the structure: the RIPE Chair and the RIPE NCC executive are not the same job, and the community needed a transition that respected that distinction.

The "RIPE NCC CEO" detail completes the operating arc. As chief executive, Holen is no longer only facilitating community process. He is responsible for an organization with staff, systems, legal obligations, members, budgets, and services that other networks depend on. The same person who writes about community consensus must also argue for investment, execute strategy, and maintain trust services. That dual history does not remove tension. It makes the tension visible.

The profile's central insight is therefore simple: number-resource governance works only when technical records, community legitimacy, and institutional operations reinforce one another. If records are accurate but the community loses trust, legitimacy suffers. If community process is open but services are insecure or underfunded, operations suffer. If executives invest in systems without member accountability, governance suffers. Holen's public career touches each side of that triangle.

For readers outside internet governance, the most useful analogy may be land records, public utility control rooms, and standards bodies combined. IP addresses and ASNs are not land, but they require trusted records of allocation and control. The RIPE NCC is not a public utility, but its services support a public infrastructure used by networks, platforms, businesses, governments, researchers, and users. RIPE is not a formal standards body, but its community processes help shape policy and operational norms in a region that spans many jurisdictions. Holen's work sits in the place where those analogies overlap and then fail.

That place is not glamorous, but it is powerful. It decides how resource holders are recognized, how communities debate allocation and transfer rules, how routing-security trust material is issued, how registry accuracy is maintained, how measurement services are sustained, and how a member organization explains why invisible infrastructure deserves visible investment. A profile of Holen is a profile of that operating trust.

The final measure of the story is restraint. The sources do not support private biography, personality claims, or a heroic account of one person shaping the internet. They support a sharper and more durable conclusion. Hans Petter Holen's public record places him across early Norwegian ISP building, RIPE community chairing, address-policy and global number-resource governance, and RIPE NCC executive leadership. That path makes him a useful lens on a hard truth: the internet depends not only on cables, routers, data centres, and software, but on institutions that keep identifiers legitimate enough for everyone else to build on.

In that sense, number-resource governance is operating infrastructure. It is not the packet itself. It is the trust surface that lets packets belong to networks, lets networks be accountable to records, lets policy be argued in public, and lets security services rely on an institution that members still recognize as theirs. Holen matters because his career shows how that surface is built, chaired, handed over, funded, and defended before most users ever know it exists.