Refine By
Clear all filter
About 703 results for "cybersecurity"
NEWS
The Council of the EU has approved conclusions on the EU Agency for Cybersecurity (ENISA), acknowledging its expanded role due to recent legislative initiatives and increasing cyber threats. The Council has recommended adequate resourcing to match ENISA's growing responsibilities, while emphasising the need for prioritisation and cooperation to avoid task duplication. The conclusions call for improvements in certification schemes and the establishment of a single reporting platform, recognising ENISA's crucial role in enhancing situational awareness and crisis response across the EU.
NEWS
The National Cyber Security Centre (NCSC) has released guidance on artificial intelligence (AI) and cybersecurity. The guidance highlights how AI works, why there is a growing interest in AI and the benefits and risks of using AI tools. The guidance also considers the cybersecurity risks of using AI and how leaders can develop AI safely and securely, among other things.
NEWS
The European Commission has launched a call for evidence on legislative proposal to revise the Regulation (EU) 2019/881 (EU Cybersecurity Act). The initiative aims to strengthen EU cyber resilience, update the mandate of the EU Agency for Cybersecurity (ENISA) and improve the effectiveness of the European Cybersecurity Certification Framework. The Commission noted that the cybersecurity landscape has become significantly more complex and threat‑intensive since the Act’s adoption in 2019, while subsequent EU legislation has expanded ENISA’s tasks beyond its original mandate, creating the need to streamline, simplify and supplement the existing framework to ensure coherence, reduce administrative burdens and improve implementation for businesses and users. The initiative focuses on measures to support a secure and resilient Information and Communication Technology supply chain and the EU cybersecurity industrial base, addresses shortcomings in the certification framework such as slow adoption, unclear roles, limited agility and insufficient clarity on covered risks, including non‑technical factors, and considers alignment with newer instruments such as the Cyber Resilience Act. The call for evidence will run until 7 April 2026.
NEWS
The European Commission has adopted the first European Common Criteria-based cybersecurity certification scheme (EUCC), in accordance with Regulation (EU) 2019/881 (the EU Cybersecurity Act). The scheme provides a Union-wide set of rules and plans on how to certify information and communication technology products in their lifecycle to make them more trustworthy for users. The EUCC will be published in the Official Journal of the European Union shortly and will come into force 20 days after publication. The Commission will also publish the first Union Rolling Work Programme for European cybersecurity certification, which lays out a strategic vision and reflections on areas for future European cybersecurity certification schemes.
NEWS
The European Commission has welcomed the adoption of the G7 Cybersecurity Working Group Declaration, issued under France's G7 Presidency and the leadership of the Agence Nationale de la Sécurité des Systèmes d'Information. The Declaration sets out four key priorities and highlights the need for co-ordinated action on: (1) post-quantum cryptography migration; (2) cybersecurity risks from and to artificial intelligence (AI) systems, with the Declaration highlighting the dual role of generative AI and large language models as tools for cyber offenders and as targets themselves, as well as the effect that emerging AI cyber capabilities, such as AI-assisted vulnerability discovery and AI-assisted code generation, may have on software security and vulnerability patching; (3) telecoms resilience, recognising telecoms as critical infrastructure and highlighting the systemic risks created by increasingly complex and interdependent networks and (4) small and medium-sized enterprise (SME) empowerment, focusing on 'secure by design' principles for products to help secure critical SMEs. The Commission will engage in the G7 Cybersecurity Working Group's autumn 2026 meeting to advance these priorities before the group's presidency transitions to the US for 2027.
PRACTICE NOTES
The ever-increasing digitalisation of society and the economy has led to a growing risk of exposure to cyber-attacks for organisations. To address this issue, the EU has introduced Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, the Network and Information Security Directive, NIS 2 Directive or NIS 2. NIS 2 is a cybersecurity framework that imposes extensive governance and incident reporting obligations of a range of sectors that have been identified as being of critical importance. It has replaced Directive (EU) 2016/1148, NIS Directive or NIS, (from 18 October 2024) which entered into force in 2016. This results in a significant increase in the cybersecurity standards that apply to organisations that fall within the scope of the Directive. Member States were required to implement NIS 2 into their national laws by 17 October 2024, meaning that organisations needed to prepare to comply during the course of 2023/24. When available, national
NEWS
The European Commission has opened a consultation on its draft implementing Regulation on cybersecurity risk management & reporting obligations for digital infrastructure, providers and information and communications technology (ICT) service managers. Directive (EU) 2022/2555 (the NIS2 Directive) aims to enhance cybersecurity risk-management measures and make incident-reporting obligations for various numbers of operators across the EU more efficient. The draft Regulation requires the Commission to align the rules at EU level, due to the cross-border nature of some operators. The draft Regulation will also specify the cases when an incident must be considered important. The consultation will close on 25 July 2024.
NEWS
The European Commission has launched a public consultation on its proposal to repeal Delegated Regulation (EU) 2022/30 (RED Delegated Regulation on cybersecurity). The repeal is scheduled to take effect on 11 December 2027, coinciding with the full application of the Cyber Resilience Act (CRA). This is intended to avoid any overlap between the cybersecurity requirements of the Radio Equipment Directive (RED) and those of the CRA, and to provide legal certainty. The consultation closes on 7 January 2026.
NEWS
The three European Supervisory Authorities (the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority—ESAs) have concluded a multilateral memorandum of understanding (MoU) to strengthen co-operation and information exchange with the European Union Agency for Cybersecurity (ENISA).
NEWS
The European Union Agency for Cybersecurity (ENISA) has published the ENISA NIS360 2026 report assessing the cybersecurity maturity and criticality of sectors of high criticality under the EU NIS 2 Directive (NIS2). The report finds that cybersecurity maturity across EU critical sectors has steadily improved, with banking, electricity and telecommunications remaining the most mature and critical sectors, while trust services, aviation and financial market infrastructures (FMI)s have moved into the high-maturity band. It attributes this progress to cybersecurity legislation, including the NIS2 and the Digital Operational Resilience Act (DORA), as well as increased political attention, stronger information sharing and collaboration and improved operational preparedness. However, maturity remains uneven across and within sectors, with health, railway, maritime, ICT service management, public administrations, space, drinking water and wastewater remaining in the NIS360 risk zone, where criticality exceeds cybersecurity maturity. The report also identifies artificial intelligence (AI), supply chain and third-party risks and geopolitical volatility as key factors shaping the cybersecurity maturity and resilience of high-criticality sectors.
NEWS
The European Commission has adopted a draft delegated regulation supplementing Article 59 of the Regulation (EU) 2019/943 (the Electricity Regulation), which establishes the first EU network code on sector-specific rules for cybersecurity aspects of cross-border electricity flows. The network code will help enhance the cyber resilience of critical EU energy infrastructure and services and will create a recurrent process of cybersecurity risk assessments in the electricity sector. These assessments are targeted at systematically highlighting the entities that perform digitalised processes with a critical or high effect in cross-border electricity flows, their cybersecurity risks, and the necessary mitigating measures required. It will support a high, common level of cybersecurity for cross-border electricity flows in Europe. The European Parliament and Council of the EU will now scrutinise the delegated act regarding the network code. They will each have a period of two months for objection to this secondary legislation, which can be extended by two months.
NEWS
MedTech Europe has published its response to the European Commission’s consultation on the revision of the EU Cybersecurity Act, supporting stronger EU cybersecurity resilience while calling for a proportionate framework for the healthcare sector. MedTech Europe says the revised framework should avoid overlapping cybersecurity requirements for medical devices already regulated under Regulation (EU) 2017/745 (Medical Device Regulation (MDR)) and Regulation (EU) 2017/746 (In Vitro Diagnostic Medical Devices Regulation (IVDR)). It adds that cybersecurity certification schemes should remain voluntary and aligned with existing EU and international standards. MedTech Europe also welcomes the proposed expansion of the European Union Agency for Cybersecurity’s role in vulnerability coordination and information sharing, while warning against additional reporting obligations that could affect healthcare operations and patient care. It further calls for risk-based supply-chain measures, sector-specific expertise in cybersecurity assessments, and international recognition of certification schemes to reduce duplication and support continuity of care.