A young woman takes a picture of her ice-cream in the Vittorio Emanuele II Gallery during a heatwave in Milan on June 24, 2026. | Stefano Rellandini/AFP via Getty Images Ice cream makers, Christmas lights manufacturers and German landlords may be set to get extra EU protection from cyber attacks. That's right, tech and cybersecurity lawyers are warning POLITICO that these unlikely sectors are on track to be classed as critical infrastructure under an EU cybersecurity law designed to protect cyber targets such as power plants, water facilities and energy grids. It's the latest stumbling block for the European Union's NIS2 Directive, which was originally passed in 2022 but is still being implemented by EU countries. Clarity about how to direct resources to protect infrastructure is more urgent than ever as Europe faces an unprecedented barrage of cyber attacks, super-charged by AI and increasing hybrid forms of aggression. Advertisement Governments were supposed to have their own legislation in place by late 2024, but delays have meant that many companies and their advisers are only now getting into the nitty-gritty of preparing to comply. Operators of the EU's most critical sectors are now being required to register with their national cyber agencies, which means understanding exactly who the law applies to. That has proved difficult, with lawyers and lawmakers citing examples such as chewing gum wholesalers to highlight the confusion and complexity associated with that task. The bizarre cases are emblematic of a real-world puzzle for companies and their legal advisers to solve — and a tricky piece of extra red tape at a time when the EU is trying hard to trim it back. It’s also another example of the difficulties the EU has faced in getting NIS2 up and running. Heavyweights France and Spain have not yet passed corresponding
Ice cream makers as 'critical infrastructure'? EU's new <b>cybersecurity</b> law suffers wobbly rollout
Read the original article
politico.eu →