Refine By
Clear all filter
About 703 results for "cybersecurity"
PRACTICE NOTES
This Practice Note provides an overview of the key aspects of Regulation (EU) 2024/2847, the EU Cyber Resilience Act (CRA), its background, timeline, objectives and how it interacts with other EU laws. For more information on the scope of the CRA or key obligations for economic operators, see Practice Notes: • The EU Cyber Resilience Act—scope and classification of products • The EU Cyber Resilience Act—obligations, compliance and enforcement Regulation (EU) 2024/2847, the EU Cyber Resilience Act (CRA) is a first of its kind EU legislation that imposes mandatory cybersecurity standards on ‘products with digital elements’ throughout the EU. Products that do not meet these standards will not be eligible for sale on the EU market as of December 2027. Compliance with the CRA will therefore become essential to gain access to the EU market for hardware and software products. Manufacturers, importers and distributors of such products will be subject to extensive cybersecurity obligations and face substantial fines if they fail to comply. The CRA has
PRACTICE NOTES
This Practice Note covers the manufacturer, authorised representative, importer and distributor obligations under Regulation (EU) 2024/2847, the EU Cyber Resilience Act (CRA). It also covers the enforcement and sanctions under the CRA and what the new requirements mean for organisations in practice. For more information on the background and scope of the CRA, see Practice Notes: • The EU Cyber Resilience Act—overview and regulatory framework • The EU Cyber Resilience Act—scope and classification of products The CRA is a first of its kind EU legislation that imposes mandatory cybersecurity standards on ‘products with digital elements’ throughout the EU. Products that do not meet these standards will not be eligible for sale on the EU market as of December 2027. Compliance with the CRA will therefore become essential to gain access to the EU market for hardware and software products. Manufacturers, importers and distributors of such products will be subject to extensive cybersecurity obligations and face substantial fines if they fail to comply. The CRA has been
NEWS
The European Commission has sent notice letters to 26 Member States for failing to transpose Directive 2022/2555 (the NIS2 Directive) on cybersecurity and Directive (EU) 2022/2557 (the CER Directive) on the resilience of critical entities.
PRACTICE NOTES
Though taking preventative steps obviously makes good sense (see Practice Note: Cybercrime prevention), it is not possible to totally eradicate the risk of cybercrime or cyber attack. An effective mechanism to deal with cybercrime and cybersecurity threats will not only include solid defences, but will also include a plan or strategy to deal with the effects of an attack in the event that it happens. This Practice Note sets out some practical guidance on putting together the incident management element of your Cybercrime prevention strategy and incident management plan. It includes breach notification requirements under the General Data Protection Regulation (UK GDPR), Assimilated Regulation (EU) 2016/679, which apply where the cybercrime incident involves a personal data breach. This Practice Note is intended for compliance professionals in general commercial organisations. It is not intended to cover sector-specific requirements. Cybercrime incident involving a personal data breach Many, but not all, cybercrime incidents will involve a personal data breach. You must notify the Information Commissioner’s Office (ICO) of a personal data breach without undue delay and, where feasible, not later
PRECEDENTS
1 Introduction 1.1 This strategy and plan builds on and supplements our other data management and security policies and procedures, namely our: 1.1.1 [ [[Data protection policy;]] 1.1.2 [[Data breach plan;]] 1.1.3 [[Information management and security policy;]] 1.1.4 [[Bring your own device policy;]] 1.1.5 [[Password policy;]] 1.1.6 [[Information and communications technology (ICT) plan;]] 1.1.7 [[Internet, email and communications policy;]] 1.1.8 [Social media policy;] 1.1.9 [[Remote working and removable media policy;]] 1.1.10 [[Business continuity plan (BCP);]] 1.1.11 [Generative AI policy.]] 2 Purpose and scope 2.1 The purpose of this document is to establish systems and controls to protect the organisation from cybercriminals and associated cybersecurity risks, as well as set out an action plan should the organisation fall victim to cybercrime. 2.2 This plan is relevant to all staff[ in every office]. 3 Responsibility 3.1 [Insert name] is responsible for this strategy and plan. 3.2 They are responsible for: 3.2.1 conducting and maintaining cybercrime/cybersecurity risk assessments; 3.2.2 monitoring compliance with this strategy and related policies and procedures; 3.2.3 invoking the relevant incident management plan, as appropriate and in conjunction with the business continuity team. 4 What is cybercrime? Cybercrime is simply a crime that has some kind of computer or cyber aspect to it. It takes shape in a variety of different forms, eg hacking, phishing, malware, viruses
PRECEDENTS
1 Introduction 1.1 Passwords are a critical aspect of our information and cybersecurity measures. They are our first line of defence. 1.2 This policy: 1.2.1 establishes guidelines on selecting strong passwords; 1.2.2 provides for the protection of passwords; and 1.2.3 sets out how often passwords must be changed. 1.3 This policy applies to all staff. 1.4 [Insert name] is responsible for this policy. Please contact them if you have any questions or concerns about anything in this policy. 2 Using strong passwords 2.1 Your passwords must: 2.1.1 be
NEWS
MLex: The EU Data Act is the latest addition to a patchwork of tech regulations that require companies to negotiate overlaps and potential contradictions to comply. Business groups argue that in the EU’s zeal to boost to European companies by hobbling US tech giants, potentially adverse consequences have not been thought through. They worry that the slew of regulation from the EU Data Act to the EU Digital Markets Act (EU DMA), EU Digital Services Act (EU DSA) and EU Artificial Intelligence Act (EU AI Act), is adding layers of complexity for companies trying to avoid hefty EU fines.
PRACTICE NOTES
The Product Security and Telecommunications Infrastructure Act 2022 (PSTIA 2022) is a law of two parts having been developed over a number of years, primarily from the government’s 2018 Code of Practice for consumer internet of things security (the Code) and the Electronic Communications Code (see below). It was put forward with two stated policy objectives: to improve digital connectivity to help drive UK economic growth by removing blockers on the deployment of key infrastructure; and to make consumer connectable or Internet of Things (IoT) products more secure. This Practice Note primarily considers PSTIA 2022, Pt 1 (PSTIA 2022, ss 1–56), which deals with product safety and IoT security. PSTIA 2022, Pt 2 concerns telecommunications infrastructure, and is considered only briefly by this Practice Note in order to place the legislation in context. PSTIA 2022 applies to ‘relevant connectable products’ (see below) and these may also be known as IoT products or devices. The term IoT
PRACTICE NOTES
This Practice Note is intended as a quick guide that outlines the main cyber threats commercial organisations face, and identifies some top tips for organisations in defending themselves. It should be read in conjunction with Practice Notes: Cybercrime prevention and Cybercrime incident management and the Cybersecurity subtopic generally. Threat What is it? Best defence/top tips Advanced persistent threat (APT) Attackers gain unauthorised access to a system and remain undetected for a prolonged period of time. They may carry out unauthorised transfers of sensitive data.Even when they are detected, they may leave several ‘backdoors’ open so they can return. Ensure user awareness of the risk and of basic account security procedures—see Precedent: Cybercrime awareness campaign.Use firewalls to inspect and filter traffic.Use antivirus software.Remember: protective software needs frequent updating so that it keeps up with the latest techniques cyber criminals use. Botnet Collection of infected computers remotely controlled by a hacker.The hacker can share or sell access to the computers to other cyber criminals to be used to distribute spam or overload
NEWS
Information law analysis: In September 2024 the Department for Science, Innovation and Technology announced new plans to boost data centres and protect them from cyber threats and power outages, designating data centres as Critical National Infrastructure (CNI) alongside key facilities such as energy and water systems. Adam Richardson, Barrister, 4-5 Gray’s Inn Square discusses the background to this designation and its implications.
NEWS
The Council of the EU has approved conclusions on the future of cybersecurity aiming to provide guidance and setting the principles towards building a more cybersecure and more resilient EU. The Council also indicates that rules in sectoral legislation should avoid fragmentation and make clear roles and responsibilities in the cyber domain. In light of the changed and rising threat level, the Council finally invites the European Commission and the High Representative to present a revised cybersecurity strategy.
NEWS
MLex: The European Commission has proposed binding rules under a revised Cybersecurity Act to force telecom operators and other priority sectors to phase out high-risk IT vendors such as Huawei. The move replaces voluntary measures, sets strict timelines for telecoms, and could later affect sectors including cloud services, medical devices and semiconductors, subject to risk assessments.