Refine By
Clear all filter
About 703 results for "cybersecurity"
NEWS
MLex: EU cybersecurity certification for products and services may be proposed when the European Commission reviews the Directive (EU) 2016/1148, the Network and Information Systems Directive (NIS Directive), Commissioner Thierry Breton told the European Parliament’s industry committee on 24 April 2020. The review will take place this year, he said.
PRACTICE NOTES
This Practice Note summarises key points from the Cyber Threat Report: UK Legal Sector published by the National Cyber Security Centre (NCSC), and incorporates data from the SRA’s Cyber security thematic review, published September 2020, together with the SRA’s Information security and cybercrime risk outlook. Headline facts and figures The cyber threat to the UK legal sector is significant, as is the financial and reputational impact of cyber attacks on law firms. Costs arise from: • the attack itself • remediation, and • repairing reputational damage The SRA thematic review found that three quarters of the firms it visited reported they had been the target of a cyber attack. Other firms reported that cyber criminals had directly targeted their clients during a legal transaction. While not all incidents culminated in a financial loss for clients, 23 of the 30 cases in which firms were directly targeted saw a total of more than £4m of client money stolen. While £3.6m of this was ultimately claimed against insurance policies, £400,000 had to be repaid directly from
NEWS
MLex: The European Commission has warned 19 EU countries that they could face lawsuits at the European Court of Justice if they fail to pass national legislation to enact the EU's Network and Information Systems II, which sets out EU-wide rules on cybersecurity. The following countries have two months to respond to the commission: Austria, Bulgaria, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Hungary, Ireland, Latvia, Luxembourg, the Netherlands, Poland, Portugal, Slovenia, Spain and Sweden.
PRACTICE NOTES
This Practice Note tracks the key steps of legislative initiatives on cyber security in the EU. Key EU cyber security initiatives include: • Revised EU Cybersecurity Act (proposal published on 20 January 2026) • EU Cybersecurity Act (adopted, amendments adopted in January 2025) • Digital Operational Resilience Act or DORA (adopted, started to apply on 17 January 2025) • NIS 2 Directive (adopted, started to apply on 18 October 2024. Amendments proposed on 20 January 2026) • EU Critical Entities Resilience Directive or CER (adopted, started to apply on 18 October 2024) • EU Cyber Security Regulation (adopted, started to apply on 7 January 2024) • EU Cyber Resilience Act (adopted, starts to apply on 11 December 2027) • EU Cyber Solidarity Act (adopted, started to apply on 4 February 2025) All these initiatives are tracked in this document, except for DORA, which historical legislative progress is tracked in Practice Note: Operational resilience—timeline [Archived]. Note that several of these pieces of legislation will be impacted by the proposal for a Digital Omnibus on the digital acquis published
PRACTICE NOTES
Protection of critical infrastructure and cybersecurity—EU strategy In October 2016, the European Parliament’s Committee for Industry, Research and Energy (ITRE) published a Cybersecurity Strategy for the Energy Sector. The document comprised an assessment of existing policies and legislation and explored options for the development of energy specific cybersecurity solutions and defensive practices. The study identified that the ongoing development of smart energy systems, with increasing interconnectivity and interdependency across Member State borders, has led to exponential growth of networked intelligence throughout energy grids and in consumer premises (via smart devices). This broad ‘attack surface’, combined with the fact that the energy system is fundamentally interconnected with every other critical infrastructure network, means that the energy sector is particularly vulnerable to cyber attacks. This risk has only increased since the publication of the 2016 strategy. On 16 December 2020, the European Commission and the High Representative of the Union for Foreign Affairs and Security Policy presented a new EU Cybersecurity Strategy. This 2020 strategy covers the security of essential
PRACTICE NOTES
This Practice Note considers the following data, privacy and cybersecurity issues arising in connection with the use of autonomous and connected vehicle technology: • The technology • Declaration of Amsterdam • Cooperative Intelligent Transport Systems (C-ITS) • EU General Data Protection Regulation • ePrivacy Directive • Cybersecurity • Data accessibility • Liability • EU AI Act • eCall • Data preservation and data production in the context of criminal proceedings • International • Practical issues For more information about other key legal issues arising in connection with this technology, see Practice Note: Automated vehicles—key legal issues in the EU and for a summary of key dates and information, see Practice Notes: EU data initiatives—tracker [Archived], EU Media, digital and telecoms tracker—horizon scanner and EU Media, digital and telecoms tracker—key developments tracker. To track developments in the UK, see Practice Notes: Autonomous vehicles—key legal issues, Autonomous and connected vehicles—data protection and privacy issues and UK automated vehicles—tracker. The technology Modern vehicles already feature a range of external communications systems such
Q&As
How are law firms vulnerable to attack? Cyber-attacks are indiscriminate, affecting both large and small firms. The primary risk is that information that the firm holds about itself, clients and third parties can be vulnerable to attack. Examples of this information include: • client lists • strategic client information • financial information • payment and transactional information A breach of security may be subtle and caused by one of the following: • phishing
PRECEDENTS
The issue Unfortunately, during a pandemic situation cybercriminals tend to increase their activity; the pandemic provides an issue to prey on individuals worldwide. While we work from home, we need to be aware of potential cyber-attacks against our personal and work environments. During the coronavirus pandemic, cybercriminals [are using OR used] the situation to impersonate local/national governments, regional/global health organizations and popular news sources. In addition to phishing emails, cybercriminals [are using OR used]: • text messages to mobile phones claiming to be from official entities, eg the UK government; • fake pandemic-related websites hosting malware and malicious apps; and • impersonation of VPN/portal representatives to capture employee credentials. What we need from you It is important that we continue to follow all standard processes and standard company-issued IT resources during a pandemic situation. Any changes to our processes should be fully documented, reviewed and approved by management, and communicated through normal internal communication
PRACTICE NOTES
This Practice Note focuses on the data protection and privacy implications of the internet of things (IoT) and the data collected by it in the EU. The following key areas are examined: • What is the internet of things? • Data protection • The identified key themes for concern • Article 29 Working Party opinion on recent developments on the internet of things • Cookies and equivalent tools • Practical actions regarding data protection • Cybersecurity • EU Data Governance Act and EU Data Act • Revised EU Product Liability Directive • EU AI Act • e-Evidence Regulation For more detailed information on the key commercial issues arising in relation to the IoT, see Practice Note: Internet of Things (IoT)—key legal issues in the EU. Note that specific issues related to automated vehicles are not covered in this Practice Note, for more information, see Practice Note: Automated vehicles—data, privacy and cybersecurity issues in the EU. For information
NEWS
MLex: The EU’s ban on Chinese inverters in renewable-energy projects involving EU funding is driven by cybersecurity and dependency risks, a European Commission official said on 4 May 2026. The Commission has evidence that inverters from high-risk countries could be used to disrupt the EU grid, while China’s dominance of production poses a security-of-supply risk. Advanced projects notified by 15 May 2026 and submitted for decision by 1 November 2026 can continue under old rules.
Q&As
Practice Note: Email disclaimers provides sample wording for commercial email disclaimers. Law firms may wish to consider something along the following lines as an email footer: Confidentiality and Security Notice: This email, its contents and any attachment are strictly confidential and intended solely for the addressee. They may contain information covered by legal, professional or other privilege.
NEWS
Information Law analysis: What are the likely effects of the war in Ukraine on cybersecurity and related obligations under EU and UK data protection laws? Written by André Bywater and Jonathan Armstrong, solicitors, of Cordery in London where their focus is on compliance issues.