3 Things SMBs Need to Know About The EU Cybersecurity Act

Introduction:

Small and medium-sized businesses (SMBs) account for 99 per cent of businesses in the EU and face a variety of cybersecurity challenges, including low management awareness and commitment. In an era of heightened threats and remote work, a low-security budget and a lack of cyber skills can have a significant impact on SMEs’ competitiveness.

The EU can fully benefit from digital transformation and the benefits of a digital single market by boosting resilience across the whole value chain.

The Cybersecurity Act of the European Union is an important step toward establishing the regulatory frameworks and certification systems required for developing cyber-resilience. The Act establishes an EU framework for cybersecurity certification as part of this support. This enables the certification of products, processes, and services that will be valid throughout the EU, hence increasing the security of online services and consumer devices.

In the earlier two instalments, respectively in part 1 and part 2, we’ve delved into the nitty-gritty of the Act and elaborated on crucial points. In this final instalment, we shall undertake the impact of the act on small businesses.

SMB

SMBs and The EU Cybersecurity Act:

Small and medium-sized businesses (SMBs) are increasingly reliant on networks and information technologies to conduct business. Some of them provide digital services and rely substantially on digital technologies in their business models. At the same time, due to limited resources, it is more difficult for SMBs to recover from cyber-attack losses than it is for large businesses: 60% of SMBs that were victims of cyber-attacks did not recover and had to shut down within six months. As a result, cybersecurity is critical for an SMB’s business continuity. This significance, however, will only grow as industrial processes move online.

According to a 2016 survey by the European Union Agency for Cybersecurity (ENISA), despite increased worries about information security risks, the level of information security and privacy standard adoption among SMBs in Europe is rather low. Similarly, their adoption is not widely regarded as a top priority. Therefore, it is important to understand the impact on businesses in Europe and The US:

1. How will the cybersecurity act impact businesses?

This act allows businesses in the European Union to certify that their products, processes, or services comply with EU cybersecurity regulations. Businesses can choose whether or not to engage in the certification procedure for the time being. The key benefit is the guarantee that their conformity would be acknowledged by all Union countries. In fact, the framework attempts to establish a single cybersecurity certification standard to avoid a fragmented approach in which individual member states introduce their own standards. 

Businesses with ICT products, processes, and services can apply to a national assessment body of their choice to request certification once a certification scheme has been developed. Goods that comply with the framework will be certified for a maximum of 3-5 years at one of the three levels. Companies will be allowed to request for renewal at the conclusion of this time period before the certificate’s validity expires.

The certification framework will be a one-stop-shop for cybersecurity certification, resulting in significant cost savings for firms, particularly SMBs, who would otherwise have had to apply for multiple certificates in multiple countries. A single certification will also reduce potential hurdles to market access. Furthermore, businesses are encouraged to invest in the cybersecurity of their products in order to gain a competitive advantage.

2. Will the cybersecurity act affect US businesses?

The Cybersecurity Act affects any firm supplying ICT products, services, or processes within the EU, regardless of size, and businesses should begin watching the ENISA and EU websites for updates on EU cybersecurity certification programmes. ENISA, for example, recently released two papers in favour of the certification scheme. More importantly, the Standards Supporting Certification report focuses on five distinct areas with frameworks, schemes, or standards that could be evolved into EU candidate cybersecurity certification schemes, namely IoT, cloud infrastructure and services, threat intelligence in the financial sector, electronic health records in healthcare, and quality assurance.

Furthermore, US-based enterprises should consider joining the SCCG and determining whether they wish to be certified so that they may compete fairly in EU markets. They should do so by assessing the risks of non-compliance with the certification systems. The Act gives each Member State the authority to set sanctions for non-compliance with certification programmes. Penalties, on the other hand, must be “effective, appropriate, and dissuasive.”

Europe aspires to be the world’s leading centre for cybersecurity certification and standardisation of ICT goods, processes, and services. The EU Cybersecurity Act provides an opportunity to create a harmonised market for cybersecurity, promoting closer international cooperation to improve cybersecurity standards, including the need for common norms of behaviour definitions, the adoption of codes of conduct, the use of international standards, and information sharing.

3. What should US businesses do?

Companies selling an ICT product, service, or process in the EU – which encompasses a wide range of small and major U.S. businesses – should:

  1. Begin keeping an eye on ENISA and EU websites for new information on EU cybersecurity certification systems.
  1. Become a member of the SCCG by submitting an application.
  1. Monitor EU and international standardisation, keeping an eye on any that might be favoured by ENISA but are incompatible with US standards.
  1. Determine whether the company wishes to gain certification in order to compete on an equal footing in EU markets.
  1. Examine the risks of non-compliance with certification schemes. The Act gives each Member State the authority to set sanctions for non-compliance with certification programmes. However, penalties must be “effective, reasonable, and dissuasive.”
  1. Identify the requirements for delivering extra information or notifications in the event that vulnerabilities or “bugs” in the product, service, or process are discovered, as well as whether updates, recalls, or withdrawals are required.
  1. Identify any internal information that is commercially sensitive and needs to be kept private.
  1. Obtain expert guidance on the Act and EU cybersecurity certification programmes, with a focus on any necessary criteria (remember OES and digital service providers have mandatory cybersecurity requirements under the NIS Directive)

Conclusion:

In a world where everything is connected everything can be hacked; cybersecurity can be compromised. Therefore, it is important for small businesses to not only be vigilant but to adhere to compliances issued across the globe. We at Security PIlgrim are here to assist you in maintaining the security of your business and adherence to compliances. 

Please follow and like us:

Leave a Comment

Your email address will not be published. Required fields are marked *

RSS
Follow by Email
Facebook
Facebook
fb-share-icon
Twitter
Visit Us
Follow Me
Tweet
YouTube
YouTube
LinkedIn
LinkedIn
Share
WhatsApp