EU Cybersecurity Act 2.0: When good regulation goes bad Over recent years we’ve witnessed the EU becoming increasingly serious about cybersecurity. After years of watching high profile breaches, many resulting from supply chain attacks targeting our critical infrastructure, that seriousness is welcome. But good intentions and good policy are not the same thing, and the proposed EU Cybersecurity Act 2.0 is starting to look a lot more like the former than the latter. The problem with CSA 2.0 The original EU Cybersecurity Act, which came into force in 2019, was a solid foundation. CSA 2.0 was supposed to be a measured evolution to deal with the current threat landscape. What has emerged instead is something more ambitious and more troubling: For the first time, the European Commission would gain the power to designate certain countries as “high-risk,” with vendors from those countries automatically inheriting that label and facing strict restrictions across the EU. The consequences of this are potentially enormous and could cause more harm than good. The old saying “the road to hell is paved with good intentions” is starting to ring true for CSA 2.0. The Irish Business and Employers Confederation (IBEC) has warned that the proposed changes could threaten stability across 18 critical sectors in Ireland alone, and land the Irish telecoms industry with a bill of approximately €730 million for ripping out and replacing equipment. Research prepared by my firm, BH Consulting, for Digital Business Ireland, found that companies well outside the direct regulatory scope of CSA 2.0 will still be hit hard through tighter supply-chain requirements, procurement rules, and investor caution. But the question I think too few people are asking publicly is “who exactly ends up on that “high-risk” list, and how?” The honest answer is that nobody knows yet. The current framing ties
EU <b>Cybersecurity</b> Act 2.0: When good regulation goes bad
Read the original article
helpnetsecurity.com →