🎁 💸 Warren Buffett's Top Picks Are Up +49.1%. Copy Them to Your Watchlist – For FreeCopy Portfolio

EU mulls wider scope for cybersecurity certification scheme - paper

Published 23/11/2023, 20:25
© Reuters. FILE PHOTO: European Union flags fly outside the European Commission in Brussels, Belgium November 8, 2023. REUTERS/Yves Herman/File Photo
MSFT
-
GOOGL
-
AMZN
-

By Foo Yun Chee

BRUSSELS (Reuters) - The European Union is considering broadening the scope of proposed cybersecurity labelling rules that would affect not just Amazon (NASDAQ:AMZN), Alphabet (NASDAQ:GOOGL)'s Google and Microsoft (NASDAQ:MSFT) but also banks and airlines, according to the latest draft of the rules.

The EU move to set up such a system comes as Big Tech looks to the government cloud market to drive growth in the coming years while a potential boom in artificial intelligence after the viral success of OpenAI's ChatGPT could also boost demand for cloud services.

The latest proposal from EU cybersecurity agency ENISA concerns an EU certification scheme (EUCS) which vouches for the cybersecurity of cloud services and determines how governments and companies in the bloc select a vendor for their business.

The document retains key provisions contained in earlier drafts such as a requirement that U.S. tech giants set up a joint venture with an EU-based company to qualify for the EU cybersecurity label.

Another provision states that cloud service must be operated and maintained from the EU, while all cloud service customer data must be stored and processed in the EU, with EU laws taking precedence over non-EU laws regarding the cloud service provider.

These obligations apply to the highest security level, of which there are four. The latest draft sets out the possibility for these tough requirements to be extended to the third highest security level.

EU countries are now reviewing the latest draft after which the European Commission will adopt a final scheme.

Tech lobbying group CCIA said broadening the scope would affect a bigger swath of industries.

"Perhaps the most striking part of this new draft is that ENISA now suggests the requirements that discriminate against foreign cloud providers could also be extended to lower levels of assurance," said Alexandre Roure, CCIA Europe's public policy director.

© Reuters. FILE PHOTO: European Union flags fly outside the European Commission in Brussels, Belgium November 8, 2023. REUTERS/Yves Herman/File Photo

"That would include banks, but also airlines, utility companies, and heavily regulated sectors," he said.

The European Banking Federation (EBF), together with the European Savings Banks Group (ESBG), the Association for Financial Markets in Europe (AFME), the European Payment Institutions Federation (EPIF), and Insurance Europe on Tuesday criticsed the sovereignty requirements.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.