The Cyber Security Review | Monday, October 31, 2022
The European Union is advancing legislation to strengthen security requirements for all digital hardware and software products. The proposal aims to curb cybercrime, which will cost the global economy an estimated Euro 5.5 trillion in 2021.
FREMONT, CA: Legislators are pursuing new legislation to improve security criteria for all digital hardware and software goods to tighten cybersecurity regulations across the European Union. The Cyber Resilience Act, a proposed law, would apply to everything from computers and cell phones to smart kitchen appliances and electronic toys for kids.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Thierry Breton, the EU's commissioner for the internal market, stated that when it comes to cybersecurity, Europe is just as strong as its weakest link: a susceptible Member State or a dangerous product along the supply chain.
Earlier this month, the European Commission presented a law draft requiring products to be made, developed, and designed to reduce cybersecurity risks. This includes, among other cybercrime disclosure laws, requirements to offer products with secure default settings, keep a detailed product identification system, and ensure that exploitable vulnerabilities may be fixed through security upgrades.
The number of personal gadgets online has substantially increased in recent years.
However, many of these so-called Internet of Things items are extremely susceptible to hacking and online crimes. Ransomware attacks happened last year and damaged the global economy by an estimated Euro 20 billion. They happen globally every 11 seconds. DDoS assaults, which aim to interrupt or block access to websites or online services, will alone cost the EU economy some Euro 65 billion in 2020.
Approximately 1,000 businesses in Belgium were victimised by cybercrimes in 2021, a 300 per cent rise from the year before. Malware and ransomware assaults made up the majority of cyberattacks. A Microsoft Digital Crimes Unit representative displays a heat map of malicious computer networks in Western Europe in 2013. Companies and manufacturers, especially smaller enterprises that do not have the technological resources or financial means to survive a cyberattack are projected to benefit from strengthened cybersecurity policies.
The World Economic Forum's Global Cybersecurity Outlook published research earlier this year stating that a business's average cost of a cyber breach was USD 3.6 million. In addition, targeted businesses experienced a drop in stock values and needed, on average, 280 days to recognise and respond to a cyberattack.
Daniel Dobrygowski, the head of governance and trust at the Forum's Centre for Cybersecurity, said that technology leaders, businesses, and their boards of directors would do well to pay attention to these developments and recognise that understanding cyber risk is part of good governance in the digital age and that cyber strategy is a business strategy.
Industry associations like the TIC Council, a global organisation that represents the independent testing, inspection, and certification sectors, applauded the proposed Cyber Resilience Act. Ursula von der Leyen, president of the European Commission, originally proposed the proposal in November 2021. The EU countries will have two years to implement the new regulations if the legislation is approved by the European Council and the European Parliament.
More in News