EU Cybersecurity and Resilience – What challenges to create a common framework?

preview_player
Показать описание
First announced by President von der Leyen in her State of the Union Address in September 2021, the European Commission is expected to unveil, in September 2022, a Cyber Resilience Act that aims to establish common cybersecurity rules for digital products and associated services such as software that are placed on the European single market.

Although Internet of Things (IoT) products create a wide range of opportunities by connecting people, information, and places, they also increase the risk of cybersecurity incidents affecting entire systems. Indeed, the infinite number of heterogeneous digital connected products, each with their own vulnerabilities, expand the potential attack surface and leave users open to theft of sensitive data and malfunctioning networks, if not worse, as large scale cyberattacks on European critical infrastructure has shown in the past months.

Under a common legal framework requiring digital products to be designed and operated more securely, with duty of care at the heart of their development, the aim is to enhance the security of the entire cyber ecosystem, from consumer to critical industrial infrastructures, while strengthening the functioning of the internal market.

However, « a common approach » remains difficult to define as stakeholders are opposed to the definition of a one-size-fits-all solution that will not achieve the objectives of the text. How can the risk associated with a device be categorised, especially when it is used in contexts as various as home or public entities, and sometimes, used in unforeseen ways? To what extent should the cybersecurity of these devices be assessed? Who should carry out the assessment in order to achieve the highest security level? And how can all stakeholders participate in the reinforcement of the secure cyber framework worldwide?

Join this EURACTIV Hybrid Conference to explore the different options to reinforce the cybersecurity of connected devices and discuss how we can ensure that all digital products are safe and secure in a way that protects end-users, industry, and public entities.

Follow us on Social Media
Рекомендации по теме
Комментарии
Автор

~40:00: EU-CCs a valid CA path for CRA? Also around 1:06:00.

chrisblair