From: EPHA.org

At the beginning of 2013 the European Commission launched two major initiatives on cyber security – the EU Cyber Security Strategy and a proposal for a Directive on network and information security. Concerns have been raised about both initiatives and recent reports suggest that the Directive may not make it through the European Parliament’s current legislature, as previously hoped.

A report by EurActiv (a website devoted to EU affairs) quoting a number of administrators from within the European institutions, suggests that, given the complexity of the file, it is unlikely that the Parliament will be able to analyse and process the Commission’s proposal before the end of its mandate next year. At present, a lead committee for the dossier has yet to be assigned, but the file is expected to receive input from the committees for civil liberties (LIBE), home affairs, internal market (IMCO), legal affairs and industry (ITRE). Should the proposal not be debated before the next parliamentary elections, the Commission will most likely be forced to present a revised proposal to the new Parliament, since only legislation which has reached an advanced stage of agreement can usually be held over for the next elected Parliament to consider [1]. This will significantly delay the progress of harmonised EU rules on cyber security.

The proposed Directive, along with the Cyber Security Strategy, identifies a number of ’critical infrastructure’ sectors where more cyber security action is needed, including the energy, transport, banking and healthcare sectors. Current EU legislation makes little reference to health sectors as strategically weak and provides little regulation or guidance on better protection of such networks. However, research has repeatedly highlighted vulnerabilities in a range of health technologies, from relatively simple medical devices to complex medical equipment and health service information systems.

Numerous recent reports have highlighted weaknesses in the proposed Directive, citing the limited scope of the computer emergency response teams (CERTs) [2] and the problems created by the different approaches taken by EU and US legislators [3]. Discussion of the proposed Directive in the Parliament, once it gets under way, is likely to focus on these issues, as well as the proposed requirements for mandatory reporting of significant cyber security breaches. Meanwhile, the Cyber Security Strategy has also caused controversy, with many stakeholders questioning the legal framework and provisions which force companies to report attacks and breaches that occur on data sites that are within their ’control’, even where these are outside of the EU [4].