Press Release

EU agency ENISA analyses cyber security legislation & spots implementation gaps; incidents remain undetected or not reported

In a new paper the EU ‘cyber security’ agency ENISA takes a snapshot of existing and future EU legislation on security measures and incident reporting. The analysis underlines important steps forward, but also identifies gaps in national implementation, as most incidents are not reported.

Published on August 27, 2012

Cyber security incidents significantly impact society. Here are five well-known examples:

Each time, millions of citizens and businesses were seriously impacted. But most incidents are not reported or not even detected. Dr Marnix Dekker and Chris Karsberg, the report’s co-authors, argue: “Cyber incidents are most commonly kept secret when discovered, leaving customers and policymakers in the dark about frequency, impact and root causes.”

The new report’Cyber Incident Reporting in the EU’’ provides an overview of existing and planned legislation (please see graphic attached) covering the mandatory incident reporting clauses in Article 13a of the Telecom package and Article 4 of the e-privacy directive, the proposed e-ID regulation’s Article 15, and Articles 30, 31, 32 of the Data Protection reform. The study shows common factors and differences between the articles and looks ahead to the EU cyber security strategy. The paper also identifies areas for improvement. For example, only one of the above-mentioned incidents was within the scope of the national regulators mandate, indicating that there are gaps in the regulation. Thus, EU-wide sharing of incident reports sharing should be improved.

Much progress has been made recently: An ENISA working group for national regulators has developed both a common set of security measures and an incident reporting format. This will enable a more uniform implementation of Article 13a. ENISA just received reports on 51 large incidents from the regulators, describing impact, root causes, actions taken and lessons learnt. This material is used as input for the European cyber security strategy and the European cyber security exercise.

The Executive Director of ENISA, Professor Udo Helmbrecht, commented: “Incident reporting is essential to obtain a true cyber security picture. The EU’s cyber security strategy is an important step and one of its goals is to extend the scope of reporting provisions like Article 13a beyond the telecommunications sector.”

For Full Report

Background: European Cyber Security Strategy and Art 13a working group documents


For interviews: Ulf Bergstrom, Spokesman, ENISA, press@enisa.europa.eu, Mobile: + 30 6948 460 143, or, Dr Marnix Dekker, ENISA, marnix.dekker@enisa.europa.eu

Stay updated - subscribe to RSS feeds of both ENISA news items & press releases!

News items;

http://www.enisa.europa.eu/media/news-items/news-wires/RSS

PRs:

http://www.enisa.europa.eu/media/press-releases/press-releases/RSS

This site uses cookies to offer you a better browsing experience.
Aside from essential cookies we also use tracking cookies for analytics.
Find out more on how we use cookies.

Accept all cookies Accept only essential cookies