Defining the reporting threshold for a cybersecurity incident under the NIS Directive and the NIS 2 Directive

被引:9
|
作者
Schmitz-Berndt, Sandra [1 ,2 ]
机构
[1] Univ Luxembourg, Fac Law Econ & Finance, L-2721 Luxembourg, Luxembourg
[2] 4 Rue Alphonse Weicker, L-2721 Luxembourg, Luxembourg
来源
JOURNAL OF CYBERSECURITY | 2023年 / 9卷 / 01期
关键词
NIS Directive; incident reporting; cybersecurity; NIS; 2; Directive;
D O I
10.1093/cybsec/tyad009
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
The NIS Directive and sector-specific cybersecurity regulations require the reporting of (security) incidents to supervisory authorities. Following the risk-based approach adopted in the NIS Directive, the NIS 2 Directive enlists as a basic security element the reporting of significant incidents that (i) have caused or (ii) are capable to cause harm, as well as (iii) notifying the service recipients of cyber threats. Although during the interinstitutional negotiations between the European Commission, the European Parliament, and the Council of the European there was consensus that the NIS Directive's reporting framework needs to be reformed, views on the determination of what needs to be reported varied. This paper outlines and analyses the different concepts of a report-worthy significant incident that have been proposed during the legislative procedure for the NIS 2 Directive from a legal and policy perspective. Irrespective of further motives that may inhibit reporting, legal compliance is difficult to achieve where legal requirements are vague. In that regard, the difficulties to determine the reporting thresholds in the past and in the future are addressed. In consideration of the increased attack surface and threat scenario, it is argued that incidents where no harm has materialized should not be treated any different than incidents that have actually resulted in harm in order to acquire the envisaged full picture of the threat landscape and create value for business and society.
引用
收藏
页数:11
相关论文
共 50 条
  • [1] Refining the Mandatory Cybersecurity Incident Reporting Under the NIS Directive 2.0: Event Types and Reporting Processes
    Schmitz-Berndt, Sandra
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON CYBERSECURITY, SITUATIONAL AWARENESS AND SOCIAL MEDIA, CYBER SCIENCE 2022, 2023, : 343 - 351
  • [2] A NIS Directive compliant Cybersecurity Maturity Assessment Framework
    Drivas, George
    Chatzopoulou, Argyro
    Maglaras, Leandros
    Lambrinoudakis, Costas
    Cook, Allan
    Janicke, Helge
    2020 IEEE 44TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2020), 2020, : 1641 - 1646
  • [3] The Transnational Dimension of Cybersecurity: The NIS Directive and Its Jurisdictional Challenges
    Contreras, Paula
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON CYBERSECURITY, SITUATIONAL AWARENESS AND SOCIAL MEDIA, CYBER SCIENCE 2022, 2023, : 327 - 341
  • [4] Implementing the NIS Directive, driving cybersecurity improvements for Essential Services
    Wallis, Tania
    Johnson, Chris
    2020 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA 2020), 2020,
  • [5] The NIS 2 Directive: securing critical assets
    Kenny S.
    Network Security, 2023, 2023 (11)
  • [6] Beyond "Complacency and Panic": Will the NIS Directive Improve the Cybersecurity of Critical National Infrastructure?
    Michels, Johan David
    Walden, Ian
    EUROPEAN LAW REVIEW, 2020, 45 (01) : 25 - 47
  • [7] Cybersecurity in the EU: How the NIS2-directive stacks up against its predecessor
    Vandezande, Niels
    COMPUTER LAW & SECURITY REVIEW, 2024, 52
  • [8] Pan-European Cybersecurity Incidents Information Sharing Platform to support NIS Directive
    Skias, Dimitrios D.
    Tsekeridou, Sofia S.
    Zahariadis, Theodore T.
    Voulkidis, Artemis A.
    Terpsichori-Helen, T-H
    Fotiadou, Konstantina K.
    ARES 2021: 16TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, 2021,
  • [9] Cybersecurity of medical devices: new challenges arising from the AI Act and NIS 2 Directive proposals
    Elisabetta Biasin
    Erik Kamenjašević
    International Cybersecurity Law Review, 2022, 3 (1): : 163 - 180
  • [10] Time to act: EU NIS 2 Directive comes into Force
    Waldeck, Boris
    ATP MAGAZINE, 2023, (05): : 40 - 42