Friday

24th Mar 2023

Germany tells EU to slow down on new cyber rules

  • The directive on security of network and information systems should be implemented first, according to German official. (Photo: Pixabay)

Germany has poured cold water on the European Commission's proposal for a stronger EU cybersecurity agency.

A German government agency official said on Tuesday (10 October) at the Cybersec conference in Krakow that EU member states should first focus on implementing the rules that have already been agreed.

Read and decide

Join EUobserver today

Become an expert on Europe

Get instant access to all articles — and 20 years of archives. 14-day free trial.

... or subscribe as a group

"The most important response I would like to give is: 'first comes first'," said Roland Hartmann, head of international relations at the German federal office for information security (BSI).

"We at BSI appreciate the ambition of the European Commission to look beyond the NIS directive," said Hartmann, referring to the first-ever pan-EU set of rules on cybersecurity, the directive on security of network and information systems (NIS).

"But we should not neglect that we first need to establish, I would like to call it basic reading and writing skills in Europe, as the NIS directive tells us to, before we get to the advanced mathematics level, as intended by the cybersecurity package," he said metaphorically.

The NIS directive was adopted in July 2016. Member states have until 9 May 2018 to transpose it into national law.

Enisa to become European Cybersecurity Agency

Last month, the EU commission published a legislative proposal on cybersecurity, foreseeing a beefed up role for the Greece-based European Union Agency for Network and Information Security (Enisa), which would be restyled as European Cybersecurity Agency.

The new agency would have a bigger budget and staff, although a spokesman for Enisa told EUobserver earlier on Tuesday that the exact number of additional staff will only be known once the proposal has become law.

The plan can only come into force if it has the backing of the European Parliament and the Council of the EU, in which national governments meet.

In the Council, Germany's voice is very strong because it is the largest EU member state.

Hartmann downplayed expectations of Enisa, which currently has 84 staff members, as a pan-EU cybersecurity hub.

"It is important to see that EU member states should create own capacities, and invest in cybersecurity," he said.

"Even an expected Enisa, with a size of 125 or more people, may not substitute increased national efforts. Even more important: we may not risk the already developed national achievements, and we should not risk a thorough implementation of the NIS directive."

The NIS directive will require certain companies to report security breaches to their national government. That will mean there needs to be trust between the two sides - industry and government.

Hartmann said the BSI officials in Germany, as well as national authorities in other countries, have established this "mutual relationship of trust and support" with the relevant industries.

"A pure regulatory, formalistic approach would not lead to the beneficial situation [of] information sharing in Europe," he said.

"Ownership, trust and on-the-ground support are more essential and relevant than the best regulation."

EU agency to fight election hacking

A new-model EU cybersecurity agency could help states defend their elections against "hybrid attacks", the Commission has said.

Interview

EU 'underestimated' cyber-crime

"Cybercrime is growing much, much faster than I think we anticipated," the EU commissioner for security, Julian King, told EUobserver.

Interview

Greece keen to keep EU cybersecurity agency

Greek official welcomed proposal to give the agency a bigger role, downplayed its kitchen sink problems, and said he was himself the victim of a computer virus.

EU to beef up cybersecurity agency

The Commission's president proposed to set up a European Cybersecurity Agency. The EU already has an agency for Network and Information Security.

Opinion

Big Tech's attempt to water down the EU AI act revealed

The launch of ChatGPT has sparked a worldwide debate on Artificial Intelligence systems. Amidst Big Tech's proclamations that these AI systems will revolutionise our daily lives, the companies are engaged in a fierce lobbying battle to water-down regulations.

Latest News

  1. EU leaders agree 1m artillery shells for Ukraine
  2. Polish abortion rights activist vows to appeal case
  3. How German business interests have shaped EU climate agenda
  4. The EU-Turkey migration deal is dead on arrival at this summit
  5. Sweden worried by EU visa-free deal with Venezuela
  6. Spain denies any responsibility in Melilla migrant deaths
  7. How much can we trust Russian opinion polls on the war?
  8. Banning PFAS 'forever chemicals' may take forever in Brussels

Stakeholders' Highlights

  1. Nordic Council of MinistersNordic and Baltic ways to prevent gender-based violence
  2. Nordic Council of MinistersCSW67: Economic gender equality now! Nordic ways to close the pension gap
  3. Nordic Council of MinistersCSW67: Pushing back the push-back - Nordic solutions to online gender-based violence
  4. Nordic Council of MinistersCSW67: The Nordics are ready to push for gender equality
  5. Promote UkraineInvitation to the National Demonstration in solidarity with Ukraine on 25.02.2023
  6. Azerbaijan Embassy9th Southern Gas Corridor Advisory Council Ministerial Meeting and 1st Green Energy Advisory Council Ministerial Meeting

Join EUobserver

Support quality EU news

Join us