European Commission proposes to strengthen the EU's cyber resilience
The European Commission has presented a proposal for a strategic legislative package intended to strengthen cybersecurity across the European Union while reducing the regulatory burden on businesses. The proposal updates the existing Cybersecurity Act and introduces a more risk-based approach to securing ICT supply chains. According to the Commission, the EU and member states will be able to identify and address risks jointly across 18 essential sectors, including healthcare, finance and telecommunications.
What this means for your organisation
Organisations covered by NIS2 or supplying European customers should expect clearer requirements for visibility into their own ICT supply chain. At the same time, the Commission signals simplification, which may make reporting less fragmented. For management, the practical implication is to anchor supplier governance and risk assessment now, rather than when the rules are finalised.
Berigo recommends
- Maintain a current overview of critical ICT suppliers and the services they underpin.
- Track the progress of the package and assess which sector requirements may apply.
- Put supplier risk on the board's fixed annual agenda.
- Use existing ISO 27001 work as the framework so new requirements can be absorbed rather than rebuilt.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch