Sunday

27th May 2018

Focus

EU to force firms to report major cyber attacks

  • It is the first time that EU-wide rules on cyber security are to be agreed (Photo: europarl.europa.eu)

Negotiators from the European Parliament and national governments have reached an agreement on new cyber-security rules, shortly before midnight on Monday (7 December).

Companies which fulfil certain essential societal functions will have to make sure that they can resist cyber attacks, and report digital security breaches to national authorities.

Dear EUobserver reader

Subscribe now for unrestricted access to EUobserver.

Sign up for 30 days' free trial, no obligation. Full subscription only 15 € / month or 150 € / year.

  1. Unlimited access on desktop and mobile
  2. All premium articles, analysis, commentary and investigations
  3. EUobserver archives

EUobserver is the only independent news media covering EU affairs in Brussels and all 28 member states.

♡ We value your support.

If you already have an account click here to login.

It is the first time that EU-wide rules on cyber security are agreed.

The new EU directive will lay down the criteria to determine if a company qualifies as an “operator of essential service”, but member states will be responsible for identifying these key companies, the European Parliament said in a press release.

The sectors where such essential services will need to be guaranteed are: energy, transport, banking, financial market, health, and water supply.

In its press release, the EP also specified three American internet companies as likely to be falling under the new rules.

“In addition, some internet services providers, such as online marketplaces (e.g. eBay, Amazon), search engines (e.g. Google) and clouds, will also have to ensure the safety of their infrastructure and to report on major incidents,” the press release said.

The new directive will also put a “strategic cooperation group” in place where member states should “exchange information and best practices, draw up guidelines and assist member states in cyber security capacity building”.

A complete assessment of the deal, which was clinched behind closed doors in a so-called trilogue process, is not yet possible until the consolidated text of the compromise is published. This is expected to take a few days.

'Milestone'

But the lead negotiator on behalf of the members of the European Parliament (MEPs) already expressed satisfaction with the deal.

“Today, a milestone has been achieved: we have agreed on first ever EU-wide cyber security rules, which the parliament has advocated for years”, centre-right German MEP Andreas Schwab said.

The European Commission, which proposed the cyber security rules in February 2013, mediated the talks.

Digital affairs commissioner Guenther Oettinger said Tuesday (8 December) the new rules are “a major step in raising the level of cyber security in Europe”.

In a speech last month, Oettinger already signalled the importance of the first-ever pan-European cyber security rules.

“We are opening a European legal book”, he said at an annual event of the European Union Agency for Network and Information Security (Enisa) in Brussels.

The EU agency “will play an even more prominent role”, Oettinger had noted.

In an interview with EUobserver, Enisa's executive director Udo Helmbrecht said he expects a positive effect of one of the directive's main features, the obligation for companies that provide essential public services to report major incidents like a cyber attack.

“Putting obligation of reporting incidents will hopefully create a mechanism that people say: 'oh if I have to report something, then I also have to do something for prevention' and by this increasing IT security”, said Helmbrecht.

The deal still needs approval from the full house of the EP and from national governments.

EU to beef up cybersecurity agency

The Commission's president proposed to set up a European Cybersecurity Agency. The EU already has an agency for Network and Information Security.

Hohe Cyber-Bedrohung für Frankreichs Wahlen

Frankreichs Präsident Francois Hollande kündigt an, alle notwendigen Massnahmen zu treffen, um Cyberattacken vor den Präsidentschaftswahlen im April und Mai zu verhindern. Die politischen Parteien sind jedoch weiterhin anfällig.

Are EU data watchdogs staffed for GDPR?

The success of the new general data protection regulation (GDPR) will depend on whether data protection authorities enforce the new rules - which, in turn, will be at least partly determined by how many people they employ.

Eight countries to miss EU data protection deadline

The EU starts enforcing its general data protection regulation on 25 May - but Belgium, Bulgaria, Cyprus, Czech Republic, Greece, Hungary, Lithuania and Slovenia won't be ready. The delay will cause legal uncertainty.

News in Brief

  1. Italy set to pick eurosceptic finance minister
  2. UK foreign minister fooled by Russian pranksters
  3. Rajoy ally gets 33 years in jail for corruption
  4. Close race as polls open in Irish abortion referendum
  5. Gazprom accepts EU conditions on gas supplies
  6. Facebook tells MEPs: non-users are not profiled
  7. Commission proposes ending France deficit procedure
  8. UK households hit with Brexit income loss

Stakeholders' Highlights

  1. Counter BalanceEuropean Ombudsman requests more lending transparency from European Investment Bank
  2. Nordic Council of MinistersOECD Report: Gender Equality Boosts GDP Growth in Nordic Region
  3. Centre Maurits Coppieters“Peace and reconciliation is a process that takes decades” Dr. Anthony Soares on #Brexit and Northern Ireland
  4. Mission of China to the EUMEPs Positive on China’s New Measures of Opening Up
  5. Macedonian Human Rights MovementOld White Men are Destroying Macedonia by Romanticizing Greece
  6. Counter BalanceControversial EIB-Backed Project Under Fire at European Parliament
  7. Nordic Council of MinistersIncome Inequality Increasing in Nordic Countries
  8. European Jewish CongressEU Leaders to Cease Contact with Mahmoud Abbas Until He Apologizes for Antisemitic Comments
  9. International Partnership for Human RightsAnnual Report celebrates organization’s tenth anniversary
  10. Nordic Council of MinistersNordic Cooperation Needed on Green Exports and Funding
  11. Mission of China to the EUPremier Li Confirms China Will Continue to Open Up
  12. European Jewish CongressCalls on Brussels University to Revoke Decision to Honour Ken Loach

Stakeholders' Highlights

  1. Sustainable Energy Week 2018"Lead the Clean Energy Transition"- Register and Join Us in Brussels from 5 to 7 May
  2. EU Green Week 2018Green Cities for a Greener Future. Join the Debate in Brussels from 22 to 24 May
  3. Nordic Council of Ministers12 Recommendations for Nordic Leadership on Climate and Environment
  4. Macedonian Human Rights MovementOxford Professor Calls for an End to the Anti-Macedonian Name Negotiations
  5. ACCAPeople Who Speak-Up Should Feel Safe to Do So
  6. Mission of China to the EUProgress on China-EU Cooperation
  7. Nordic Council of MinistersWorld's Energy Ministers to Meet in Oresund in May to Discuss Green Energy
  8. ILGA EuropeParabéns! Portugal Votes to Respect the Rights of Trans and Intersex People
  9. Mission of China to the EUJobs, Energy, Steel: Government Work Report Sets China's Targets
  10. European Jewish CongressKantor Center Annual Report on Antisemitism Worldwide - The Year the Mask Came Off
  11. UNICEFCalls for the Protection of Children in the Gaza Strip
  12. Mission of China to the EUForeign Minister Wang Yi Highlights Importance of China-EU Relations