{"id":1351,"date":"2024-08-02T07:26:43","date_gmt":"2024-08-02T11:26:43","guid":{"rendered":"https:\/\/www.packagingindustrynews.com\/?p=1351"},"modified":"2024-08-02T07:26:43","modified_gmt":"2024-08-02T11:26:43","slug":"ecso-proposes-changes-to-eu-cybersecurity-rules","status":"publish","type":"post","link":"https:\/\/www.packagingindustrynews.com\/?p=1351","title":{"rendered":"ECSO proposes changes to EU cybersecurity rules"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<div class=\"article-image\">\n<figure class=\"article-image__container\">\n                                    <picture><source media=\"(min-width: 990px)\" srcset=\"https:\/\/www.packaging-gateway.com\/wp-content\/uploads\/sites\/16\/2024\/08\/EU-Cyber-770x433.jpg\"\/><source media=\"(min-width: 430px)\" srcset=\"https:\/\/www.packaging-gateway.com\/wp-content\/uploads\/sites\/16\/2024\/08\/EU-Cyber-940x528.jpg\"\/>\n                                    <\/picture><figcaption class=\"c-featured-image__description\">ECSO offers recommendations to ensure the Act effectively strengthens cybersecurity across Europe \/ Credit: Tero Vesalainen via Shutterstock<\/figcaption><\/figure>\n<\/p><\/div>\n<p class=\"drop-cap\">ECSO, the European organisation for cybersecurity, comprising over 300 members, has shared its views on the recently published NIS2 Implementing Act.<\/p>\n<p>            <!-- sponsored-whitepaper sponsored hidden sponsored-with-form --><\/p>\n<p>While acknowledging the progress towards enhancing cybersecurity across Europe, ECSO has identified several areas of concern and provided recommendations to improve the Act\u2019s effectiveness.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-concerns-over-implementation-costs-and-requirements\">Concerns over implementation costs and requirements<\/h2>\n<p>One of the primary concerns raised by ECSO is the potential for excessive and disproportionate costs associated with implementing the cybersecurity requirements outlined in the Act.<\/p>\n<p>The organisation emphasises that cybersecurity measures should be risk-based and tailored to the specific threats and vulnerabilities faced by individual entities.<\/p>\n<p>This approach would help avoid unnecessary financial burdens on organisations while ensuring adequate protection against cyber threats.<\/p>\n<p>ECSO also highlights the ambiguity in some of the security requirements, which could hinder effective implementation. The lack of clarity might lead to inconsistent application of the rules across different entities, potentially undermining the overall security objectives.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-reporting-of-significant-incidents\">Reporting of significant incidents<\/h2>\n<p>Another issue identified by ECSO is the extensive list of criteria for defining significant incidents.<\/p>\n<p>The organisation warns that this could lead to over-reporting, increasing both the financial and administrative load on affected entities. ECSO suggests that the Act should require two or more criteria to be met for an incident to be considered significant, ensuring a more proportional approach.<\/p>\n<p>Furthermore, ECSO recommends aligning the Act\u2019s requirements with existing compliance schemes, such as ISO\/IEC 27001. This alignment would help streamline the implementation process and reduce the burden on entities, particularly those with technical limitations.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-need-for-clearer-incident-reporting-guidelines\">Need for clearer incident reporting guidelines<\/h2>\n<p>ECSO calls for more detailed and actionable technical references for cybersecurity teams, as opposed to high-level guidelines focused on legal or managerial aspects.<\/p>\n<p>Clarification is needed regarding whether incidents should be reported in the entities\u2019 primary country of establishment, or all member states impacted by the incident.<\/p>\n<p>The term \u201cbecoming aware,\u201d used as a criterion for submitting an early warning within 24 hours, also requires a formal definition.<\/p>\n<p>ECSO notes that some current criteria for categorising incidents, such as \u201creputational damage\u201d and \u201ccomplaints from users,\u201d could lead to manipulation and should be revised or removed.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-recommendations-for-improved-risk-management\">Recommendations for improved risk management<\/h2>\n<p>ECSO recommends tying the criteria for defining significant incidents to the requirements of digital service providers rather than the entities using the services.<\/p>\n<p>This is crucial, as providers may not have visibility into key incident information from their customers.<\/p>\n<p>The organisation also advises increasing the duration of operational disruption considered significant and clarifying whether incidents affecting both a digital service provider and its users should be reported by one or both parties.<\/p>\n<p>In the end, while ECSO acknowledges the progress made with the NIS2 Implementing Act, it calls for several adjustments to ensure that the measures are practical, proportionate, and effectively enhance cybersecurity across Europe.<\/p>\n<p>            <!-- sponsored-whitepaper sponsored hidden sponsored-with-form --><\/p>\n<p>            <!-- Newsletter banner start --><\/p>\n<p><!-- <link rel=\"stylesheet\" href=\"\"> --><\/p>\n<div class=\"grid-container\">\n<section class=\"gdm-newsletter-banner__container\">\n<div class=\"gdm-newsletter-banner__wrapper-container gdm-newsletter-banner__wrapper-container--article\">\n<div class=\"gdm-newsletter-banner-info__wrapper\">\n<div class=\"gdm-newsletter-banner-logo__container\">\n                    <img decoding=\"async\" src=\"https:\/\/www.packaging-gateway.com\/wp-content\/themes\/goodlife-wp-B2B\/assets\/images\/newsletter-new.svg\" alt=\"Email newsletter icon\"\/>\n                <\/div>\n<div class=\"gdm-newsletter-banner-info__container\">\n<h3 class=\"gdm-newsletter-banner__heading wp-noreslt\">Sign up for our daily news round-up!<\/h3>\n<p class=\"gdm-newsletter-banner__sub-heading\">Give your business an edge with our leading industry insights.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<\/div>\n<p><!-- Newsletter banner end --><\/p>\n<footer class=\"article-footer\">\n                                <!-- article-actions start --><\/p>\n<p><!-- .gdm-article-actions -->                                <!-- article-actions end --><br \/>\n                            <\/footer>\n<\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.packaging-gateway.com\/news\/ecso-proposes-changes-to-eu-cybersecurity-rules\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>ECSO offers recommendations to ensure the Act effectively strengthens cybersecurity across Europe \/ Credit: Tero Vesalainen via Shutterstock ECSO, the European organisation for cybersecurity, comprising over 300 members, has shared its views on the recently published NIS2 Implementing Act. While acknowledging the progress towards enhancing cybersecurity across Europe, ECSO has identified several areas of concern [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":1352,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[165],"tags":[742],"class_list":["post-1351","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packaging-news","tag-changes-to-eu-cybersecurity-rules"],"_links":{"self":[{"href":"https:\/\/www.packagingindustrynews.com\/index.php?rest_route=\/wp\/v2\/posts\/1351","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.packagingindustrynews.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.packagingindustrynews.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.packagingindustrynews.com\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.packagingindustrynews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1351"}],"version-history":[{"count":0,"href":"https:\/\/www.packagingindustrynews.com\/index.php?rest_route=\/wp\/v2\/posts\/1351\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.packagingindustrynews.com\/index.php?rest_route=\/wp\/v2\/media\/1352"}],"wp:attachment":[{"href":"https:\/\/www.packagingindustrynews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1351"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.packagingindustrynews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1351"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.packagingindustrynews.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1351"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}