New EU cybersecurity law avoids making big Internet companies report breaches

Breach rule extends only to companies that own, operate or provide technology for critical infrastructure facilities.

Europe on Thursday approved a new cybersecurity law, but held back from requiring Internet giants such as Google, Amazon, Ebay and Skype, to report security incidents.

Members of the European Parliament voted by a huge majority to approve the Network and Information Security (NIS) directive.

Under the original proposals, so-called "enablers of information society services" would have been required to report any security breach that has "significantly affects the continuity of critical services and supply of goods" to a national authority, whether data had been compromised or not.

But the law as approved by parliament on Thursday now extends only to companies that own, operate or provide technology for critical infrastructure facilities.

Business organizations were quick to welcome the law. "We commend the European Parliament for wisely focusing the directive on the critical infrastructure elements."This Directive will succeed if it is based on clear and future-proof definitions and a proportional, risk-based approach that allows the private sector to continue to innovate," said Thomas Boué, policy director at BSA, the Software Alliance.

But Pirate Party member of the European Parliament, Amelia Andersdotter, said she had been one of the minority voting against the law because "it does all the wrong things and none of the right things."

"This vote today is very positive news for European citizens. Member states need to be ready to address cyber attacks. Today there are gaps in some countries and we need to fill them.

We are only as strong as the weakest link," said Digital Agenda Commissioner Neelie Kroes who put forward the proposals.

It will be up to member states how they write the directive into national law, so sanctions for failing to report an incident will vary from country to country. However Article 15 stipulates that member states must investigate all cases of noncompliance.

Kroes says she wants to reach an agreement with EU member states by the end of 2014.

According to the Commission, 93 percent of large corporations experienced a cyber attack in 2012. Yet nearly three quarters of 160 respondents to an online Commission consultation said that the requirement to report cyber incidents would not incur any additional costs, and more than two thirds said that implementing a state-of-the-art NIS risk-management system would not result in increased costs.

Follow Jennifer on Twitter at @BrusselsGeek or email tips and comments to jennifer_baker@idg.com.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags governmentregulationEuropean Parliament

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jennifer Baker

IDG News Service
Show Comments

Father’s Day Gift Guide

Brand Post

Bitdefender 2019

Bitdefender solutions stop attacks before they even begin! Get cybersecurity that 500 MILLION users already have and trust.

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?