Refine By
Clear all filter
About 703 results for "cybersecurity"
NEWS
EU Law analysis: On 20 January 2026, the European Commission published a new ‘Cybersecurity Package’ consisting of a proposed Regulation referred to as ‘Cybersecurity Act 2’ of the ‘Revised EU Cybersecurity Act’ that would replace Regulation (EU) 2019/881, the current EU Cybersecurity Act (‘CSA’) and a proposal for a Directive amending Directive (EU) 2022/2555, the EU NIS 2 Directive (‘NIS2’). The proposals aim to address non-technical ICT supply-chain risks, reform the EU Cybersecurity Certification Framework, and make targeted changes to NIS 2. Written by Dr Henrik Hanssen, attorney and counsel at Hogan Lovells International LLP.
PRACTICE NOTES
This Practice Note considers cybersecurity in international arbitration. An introduction to cybercrime and cybersecurity in international arbitration A single arbitration can involve numerous participants from multiple jurisdictions, including parties, their funders and insurers, arbitrators, counsel, experts, witnesses, an arbitral institution or other administering organisation and third-party service providers (broadly referred to here as ‘Participants’). Within the arbitral process, those Participants may share material which is not in the public domain. Access to this material may have the potential to cause commercial damage, influence share prices, corporate strategies or even government policy. The outcome of an arbitration could have significant repercussions in the financial markets. This means that obtaining a draft form of an arbitral award before release to the parties themselves could be very lucrative for cybercriminals. As such, the arbitral process is a target for cyberattacks, particularly if hackers can identify a weak link in
NEWS
MLex: The revision of the EU’s Cybersecurity Act is set to move into a new phase in early June 2026, with Cyprus expected to present a compromise text on the EU cybersecurity agency and on certification rules, according to a 13 May 2026 document seen by MLex. Negotiations on the proposed EU Cybersecurity Act 2 will then continue under Ireland’s incoming presidency of the Council of the EU, while talks on NIS2 Directive simplification measures are due to begin later in May 2026.
PRACTICE NOTES
This Practice Note offers a concise overview of cybersecurity challenges for life sciences companies, providing practical advice for EU-based organisations. It covers the regulatory landscape regarding cybersecurity in the EU, including NIS 2 Directive, Medical Devices Regulations (MDR and IVDR), EU AI Act, EU Cyber Solidarity Act, EU Cyber Resilience Act, European Health Data Space Regulation or EHDS, among others, and their compliance obligations and their sanctions or enforcement consequences in the event of non-compliance. It also highlights key regulatory authorities and industry bodies, concluding with insights into cybersecurity legislation trends and future outlooks. The cybersecurity landscape in the life sciences sector The life sciences sector, covering research and development (R&D) of pharmaceuticals, medical devices, and biotechnology; clinical trials; and healthcare services, increasingly integrates digital technologies like telemedicine, health apps, and artificial intelligence (AI) to boost operations and innovation. This digital adoption, however, introduces cybersecurity risks. For the purpose of the current Practice Note, cybersecurity refers to the protection of data and systems from unauthorised or malicious
PRACTICE NOTES
This Practice Note is intended to provide an overview of the laws and regulations relating to cybersecurity in the EU, with a particular focus on: • Regulation (EU) 2016/679, the EU General Data Protection Regulation (EU GDPR) • Directive (EU) 2022/2555, the second EU’s Network and Information Systems Directive (NIS 2 Directive), which replaced Directive (EU) 2016/1148 (NIS Directive) • Directive (EU) 2022/2557, the EU Critical Entities Resilience Directive, (CER Directive) • Directive 2002/58/EC, the EU ePrivacy Directive • Directive (EU) 2018/1972, the European Electronic Communications Code (EECC) • financial legislation such as Regulation (EU) 2022/2554, the Digital Operational Resilience Act (DORA) and Directive (EU) 2015/2366, the second EU Payment Services Directive (PSD2), and • Regulation (EU) 2024/2847, the EU Cyber Resilience Act ( CRA) • Regulation (EU) 2024/1689, the EU AI Act These laws and regulations are discussed in the context of: • the entities that are required to comply with such rules • the security obligations
NEWS
Information Law analysis: It is common knowledge that a number of AI models were launched in 2023/2024 that have a transformational impact on our daily lives. At the same time, the current geopolitical situation has led to a less publicised, but still crucial, focus on cybersecurity. Recognising this, the UK Government published a call for views on the cybersecurity of AI focusing on the cybersecurity risks to AI, rather than the security risks caused by AI (which are also not insignificant). This led to the publication of the Code of Practice for the Cyber Security of AI on 31 January 2025 (the Code).
NEWS
MLex: Germany is proposing changes to the EU's planned cybersecurity certification framework that would give national governments a greater role in deciding how security goals evolve as technology and cyber threats change, according to a discussion paper seen by MLex. The framework is part of the EU's proposed overhaul of the Cybersecurity Act, which would establish a single EU system for certifying the cybersecurity of information and communications technology (ICT) products and services, allowing certificates to be recognised across the EU.
NEWS
MLex: More UK companies can expect to be caught in the scope of the cybersecurity regulatory framework, as the government detailed its plans to extend obligations to additional sectors and supply chains on 1 April 2025. Details of the planned reform were revealed by the Secretary of State for Science, Innovation and Technology, Peter Kyle, who said the Cyber Security and Resilience Bill (the Bill) would give the government the power to make regulated organisations shore up their cyber defenses. A draft Bill should be presented to lawmakers for parliamentary scrutiny later in 2025.
Q&As
The UK has left the EU on the basis of the Withdrawal Agreement as implemented in the European Union (Withdrawal) Act 2018 and the European Union (Withdrawal Agreement) Act 2020. However, we are now in an implementation period running until 31 December 2020 during which time the UK will generally continue to abide by EU rules. The government will enter into negotiations for a post-Brexit UK-EU relationship. In a situation where no new arrangements are put in place by the end of the year (a ‘non-negotiated outcome’), legislation previously prepared for a no-deal scenario will apply. As with counter-terrorist financing, efforts to thwart cybercriminals
PRACTICE NOTES
Pandemics are exceptional events which present organisations with difficult business conditions, uncertainty and particularly challenging information and cybersecurity issues. Office closures and social distancing required during a pandemic create unusual circumstances for businesses, including potentially managing an unprecedented number of staff who are working from home, some of whom having never done so before. Key information and cybersecurity risks to consider and seek to mitigate during a pandemic centre around: • continued compliance with legal and regulatory requirements • cybercrime • keeping systems and devices secure, and • staff awareness This Practice Note considers each risk area and suggests practical steps you can take to mitigate them. Legal and regulatory requirements Sound risk management practices require you to identify, monitor and manage all material risks to your business. See Practice Note: How to identify and evaluate risk across the business. Information and cybersecurity are important risks for any business. Identifying, monitoring and managing material risks is a regulatory requirement for law firms. Confidentiality Solicitors and law firms must keep the affairs of
NEWS
MLex: Operators of essential services, including digital infrastructure and telecom companies, face a wait for EU countries to reach agreement on revised cybersecurity rules as they are still at odds on the scope. According to a new policy document, EU governments also have yet to agree on enforcement action as well as co-operation with countries outside the EU under the revision of the Network and Information Security (NIS) Directive.
CHECKLISTS
The Checklist aims to set out the key steps for consideration for arbitrators throughout the life cycle of a proceeding from appointment and the first procedural order to rendering an award and discharging arbitrators’ duties. It provides guidance for arbitrators on the kind of terms to be expected in procedural orders dealing with matters of data security throughout the lifespan of an arbitration. In view of the evolving nature of the cybersecurity ecosystem, applicable laws, and regulations, please be mindful that this is a non-exhaustive list. Instead, the checklist works as a best practices guidance. Arbitration phase: pre-appointment of the Tribunal Steps Notes Legal Steps • Protect your online identity to be perceived as independent and impartial despite the challenges that can be created by your online presence. See: Checklist for Arbitrators on the Use of Social Media and the Duty of Impartiality—the cybersecurity approach to arbitration. Technical Steps • Take necessary cybersecurity measures in terms