Refine By
Clear all filter
About 701 results for "cybersecurity"
NEWS
The Agency for the Cooperation of Energy Regulators (ACER) has published guidance on the voluntary submission of information to support the monitoring of cybersecurity-related operational reliability performance indicators in the electricity sector under the Network Code for Cybersecurity (NCCS). The guidance establishes three performance indicators applicable to high-impact and critical-impact entities under the NCCS, which cover: (1) the annual number of reportable cyber-attacks assessed as having high or critical gravity; (2) the annual number of reportable cyber threats; and (3) the annual number of exploited unpatched (zero-day) vulnerabilities. According to ACER, the indicators are intended to support consistent and comparable monitoring of cybersecurity risks with potential operational consequences for cross-border electricity flows, while minimising data sensitivity.
NEWS
The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted Joint Opinion 4/2026 assessing the European Commission’s proposals for a revised EU Cybersecurity Act and amendments to the EU NIS 2 Directive (NIS2), following a formal consultation. They supported the overall objectives of strengthening the European Union Agency for Cybersecurity’s (ENISA’s) role, reviving the European cybersecurity certification framework, simplifying compliance, and addressing  information and communication technology (ICT) supply chain risks, while underlining that cybersecurity measures must remain necessary and proportionate to avoid undue interference with privacy and data protection. They welcomed improved cooperation mechanisms and a single-entry point for incident and personal data breach reporting. They recommended safeguards where ENISA processes personal data, including clear legislative limits and prior EDPS consultation, extending the European Cybersecurity Skills Framework to the general workforce, clarifying links with EU General Data Protection Regulation certification, supporting ICT supply chain measures and the designation of digital identity and business wallet providers as essential entities, and ensuring safeguards for ransomware reporting.
NEWS
The European Union Agency for Cybersecurity (ENISA) has published its third annual NIS360 report, which found that cybersecurity maturity across EU critical sectors has improved, while the level of sector criticality has remained largely unchanged. The report identifies health, railway, maritime, ICT management services, space, public administration, drinking water and wastewater as sectors where cybersecurity maturity remains lower than their level of criticality. ENISA says the gas sector has begun moving out of this risk category due to improved information sharing, collaboration and risk management.
NEWS
The European Association of Medical Devices Notified Bodies (Team-NB) has published  a letter on setting out its position on strengthening cybersecurity for medical devices in Europe and responding to proposed amendments to the Medical Devices Regulation and In Vitro Diagnostic Regulation. Team-NB welcomed efforts to improve cybersecurity for the benefit of patients and expressed support for proposals that clarify general safety and performance requirements and involve the EU Agency for Cybersecurity, while stressing that decisions on device availability and patient safety should remain within the existing MDR and Regulation (EU) 2017/746 (the In Vitro Diagnostic Medical Devices Regulation (IVDR)) governance structures. It also supported updating regulatory guidance and developing harmonised standards, noting that this would facilitate compliance, enable presumption of conformity, and reduce burdens, particularly for small and medium-sized enterprises.
NEWS
HM Treasury (HMT) has published a G7 Cyber Expert Group (CEG) statement on artificial intelligence (AI) and cybersecurity, focusing on the risks and opportunities for the financial sector. The statement calls on jurisdictions to monitor developments in generative AI, agentic AI, and other advanced systems; promote collaboration among the public, private, and academic sectors; and proactively address emerging cybersecurity risks. The CEG highlights that AI can enhance cyber resilience by improving anomaly detection and fraud prevention, while also acknowledging that AI can amplify existing threats—for example, through AI-powered phishing and automated exploit development.
NEWS
The European Commission has published a draft Council Recommendation for the EU Blueprint on cybersecurity crisis management. This non-binding framework aims to guide EU-level entities in managing cyber crises, enhancing co-operation between civilian and military actors, and utilising mechanisms like the Cybersecurity Emergency Mechanism. It also seeks to secure communication and strategic efforts to counter disinformation. The Blueprint updates the 2017 recommendation, incorporating lessons from EU-level exercises to improve crisis response. It also builds upon existing frameworks, such as the Integrated Political Crisis Response and the EU Cyber Diplomacy Toolbox.
NEWS
The National Cyber Security Centre (NCSC) has published its eighth Annual Review, covering the period from 1 September 2023 to 31 August 2024. The review showcases the organisation's efforts to enhance the UK's online safety and provide clarity in an increasingly complex digital landscape.
NEWS
MLex: Recent events have revealed weaknesses in cyber security across critical services in the UK, just as a new government took power. The existing cyber regulation has never been fully enforced, and is so unclear that organisations are not sure whether they are even in its scope. Where the previous government delayed, the new administration is bringing in new legislation. Will the incidents and the Cyber Security and Resilience Bill lead to a cultural as well as regulatory shift akin to that of the EU’s General Data Protection Regulation that could see cyber issues taken (and enforced) much more seriously?
NEWS
The Department for Science, Innovation and Technology has launched two consultations calling for views on new measures aimed at enhancing cybersecurity in AI and software, contained respectively in two new codes of practice. The codes establish requirements for software and AI developers to fortify their products against tampering, hacking and sabotage , with the aim of boosting confidence in the use of AI models and thereby driving growth in the cybersecurity sector. Both consultations close on 10 July 2024.
NEWS
Information Law analysis: Charlie Wedin, partner, Katie Simmonds, associate director, and Nina Lazic, associate director, of Osborne Clarke, consider the UK and EU's proposals for reform of cybersecurity laws and what divergence this is likely to create between UK and EU law going forwards.
PRACTICE NOTES
Cybercrime is a fast-moving, ever-evolving unpredictable risk to all commercial organisations which must be managed properly. This Practice Note pulls together examples of good practice in terms of generally reducing the risk of cybercrime and cybersecurity breaches. It is aimed at compliance professionals, not cybercrime experts. It does not cover specialist sectors like telecommunications. Responsibility Cyber risk, like any other risk to your business, needs to be managed properly and considered a high priority risk for the internal compliance or legal team. It is a business risk that must be managed within an overall information risk-management and crime prevention framework, and should not be left just to the IT department. A senior person should take overall responsibility for conducting a risk assessment and, from there, developing and implementing your policies and procedures. They should be trained and have adequate resources to ensure those policies and procedures are properly maintained. All staff should be made aware of who this person is. Risk assessment Your starting point should be a risk assessment. A high-quality risk assessment involves
NEWS
The Pensions Regulator (TPR) has published a report outlining how it worked alongside pension administrator Capita to assess the risk to pension schemes following a cyber security incident in March 2023. The report shows that TPR stepped in to ensure that Capita was taking steps to identify the extent of any impact on schemes and to inform trustees of affected schemes so that protective measures could be put in place. TPR says that this swift reaction helped ensure that thousands of pension savers were protected.