Refine By
Clear all filter
About 703 results for "cybersecurity"
NEWS
The European Commission has proposed a new cybersecurity package aimed at addressing increasingly sophisticated cyber and hybrid threats facing the EU. According to the Commission, essential services and democratic institutions across the bloc continue to experience cyber incidents linked to both state and criminal actors.
NEWS
The European Union Agency for Cybersecurity (ENISA) has published the ENISA Cybersecurity Exercise Methodology. The methodology sets out an end-to-end framework for the planning, delivery and evaluation of cybersecurity exercises, intended to ensure that appropriate profiles and stakeholders are involved at the relevant stages. The publication incorporates theoretical material based on lessons learned, industry best practice and cybersecurity expertise. It is designed to be used alongside a support toolkit, which includes templates and guidance materials to assist planners in organising effective exercises.
NEWS
Agency for the Co-operation of Energy Regulators (ACER) has published new guidelines aimed at enhancing the protection of cybersecurity information exchanged under the EU-wide network code on sector-specific rules for cybersecurity aspects of cross-border electricity flows (NCCS). The guidelines emphasise the need to maintain the confidentiality of sensitive information on cyberattacks, threats, risk assessments, and cybersecurity expenditures while ensuring that such information is shared securely amongst entities and with the relevant authorities. It recommends the use of the Traffic Light Protocol (TLP) for exchanging information and offer methods for anonymising and aggregating data, particularly when no legally binding national classification schemes are in place.
NEWS
Corporate Crime analysis: In April 2025, the Legal Aid Agency (LAA), a cornerstone of the UK’s justice system, became the latest victim in a growing wave of cyberattacks targeting both public and private institutions. The breach, which the Ministry of Justice (MoJ) later confirmed, involved the theft of a ‘significant amount’ of sensitive personal data—including information relating to domestic abuse victims, individuals involved in family law disputes, and those facing criminal prosecution. The scale of the breach is staggering; more than two million pieces of data were reportedly accessed, with records dating back to 2010. This incident is not isolated. It follows closely on the heels of cyberattacks on major UK retailers such as Marks & Spencer, Harrods, and the Co-op, all of which suffered operational disruptions and financial losses. But the LAA breach is particularly alarming due to the nature of the data involved and the vulnerability of the individuals affected. It raises urgent questions about the resilience of public sector digital infrastructure and the broader implications of cybercrime in an increasingly interconnected world. Written by Charlotte Hill, Partner at Penningtons Manches Cooper LLP.
NEWS
The European Commission has unveiled an action plan aimed at strengthening cybersecurity measures in the healthcare sector across the EU. The plan focuses on four key areas: enhanced prevention, improved threat detection, rapid response to cyberattacks, and deterrence of threat actors. Central to the initiative is the establishment of a pan-European Cybersecurity Support Centre for hospitals and healthcare providers, which will offer tailored guidance, tools, and services. The Commission has also proposed the introduction of Cybersecurity Vouchers to assist smaller healthcare entities financially. By 2026, an EU-wide early warning service for cyber threats is expected to be operational. The plan builds upon existing EU cybersecurity legislation and will be subject to public consultation for further refinement.
NEWS
The European Commission launched a consultation on 11 April 2025 to evaluate and revise the 2019 EU Cybersecurity Act. The review focuses on the European Union Agency for Cybersecurity (ENISA) mandate, the European Cybersecurity Certification Framework, and ICT supply chain security. The consultation aims to simplify cybersecurity rules and streamline reporting obligations. Member state authorities, industry stakeholders, researchers, and consumer organisations are invited to submit responses via the Have Your Say portal. The consultation will be open until 20 June 2025.
NEWS
The European Commission has published an Action Plan on Cybersecurity and Artificial Intelligence (AI) to support the safe and responsible use of AI while strengthening Europe's cybersecurity and resilience. The Action Plan sets out a coordinated approach for Member States, businesses and public authorities to address the risks and opportunities associated with advanced AI models. It focuses on three objectives: promoting the safe and responsible use of advanced AI, reinforcing the EU's cybersecurity and resilience and scaling up Europe's AI capabilities for cybersecurity.
NEWS
The Council of the EU has adopted two new laws to enhance the EU's cybersecurity capabilities. The EU Cyber Solidarity Act establishes an EU-wide cyber security alert system and creates a cybersecurity emergency mechanism, including an EU cybersecurity reserve. A targeted amendment to the Regulation (EU) 2019/881 (EU Cybersecurity Act) enables the future adoption of European certification schemes for managed security services. These measures aim to strengthen the EU's ability to detect, prepare for, and respond to cybersecurity threats and incidents, whilst fostering co-operation and resilience across Member States.
NEWS
The European Commission has announced an enhanced co-operation on cybersecurity with the US following the EU-US Joint Cyber Safe Products Action Plan in October 2023. This collaboration between the Commission and US regulatory agencies aims to explore mutual recognition on cybersecurity requirements on Internet of Things hardware and software consumer products. Advanced co-operation in critical infrastructure protection, crisis management, software security, post quantum cryptography and cybersecurity of artificial intelligence has also been agreed. The EU has further announced its membership in the US-led Counter Ransomware Initiative policy statement, which commits the EU Member States’ authorities to not pay ransom to cyber criminals.
CHECKLISTS
Independence and impartiality are cornerstone principles of international arbitration and are embodied in arbitration rules and laws worldwide. Legal professionals have increasingly been using social media platforms for professional networking purposes. However, the use of social media may raise concerns as to the independence and impartiality of the arbitrators. These concerns could arise due to, for example, ex parte communications, stolen identities, failure to comply with disclosure obligations and potential or apparent bias due to the activities on social media. The checklist is prepared for arbitrators to follow to protect their online identity and to avoid challenges resulting from their online presence. In view of the evolving nature of the cybersecurity ecosystem, applicable laws, and regulations, please be mindful that this is a non-exhaustive list. Instead, the checklist works as a best practice guide. Creating and Auditing Your Profile List Notes • While you may not necessarily be an active
NEWS
The European Union Agency for Cybersecurity (ENISA) has published a report examining the impact of the Directive (EU) 2022/2555 on cybersecurity investments and organisational maturity (the NIS 2 Directive). The report reveals a significant increase in information security spending, with 9% of EU IT investments now allocated to this area. ENISA found that 89% of organisations anticipate needing additional cybersecurity staff to comply with the NIS 2 Directive, while 90% expect an increase in cyberattacks in 2025. The report also highlights that entities in sectors already covered by Directive (EU) 2016/1148 (the original NIS Directive) demonstrate higher cybersecurity performance compared to newly included sectors under the NIS 2 Directive.
NEWS
Regulation (EU, Euratom) 2023/2841 (Cybersecurity Regulation) laying down measures for a high common level of cybersecurity at the EU’s institutions, bodies, offices and agencies has entered into force on 7 January 2024. The Cybersecurity Regulation provides for the establishment of an internal cybersecurity risk management, governance and control framework for each EU entity, and sets up a new Interinstitutional Cybersecurity Board (IICB) to monitor and support its implementation by EU entities. It provides an extended mandate of the Computer Emergency Response Team for the EU institutions, bodies, offices and agencies (CERT-EU), as a threat intelligence, information exchange and incident response co-ordination hub, a central advisory body, and a service provider. In line with its mandate, CERT-EU is renamed to ‘Cybersecurity Service for the Union institutions, bodies, offices and agencies’, but retains the short name CERT-EU.