New Publication: Comment on the Council Resolution on Encryption and Recital 54 NIS 2.0 Proposal

One year ago, the Council of the European Union published the Council Resolution on Encryption, in which the necessity for security through encryption and for security despite encryption is emphasized. The resolution is based on the assumption that access to encrypted content is becoming increasingly important for competent authorities in the area of security and … Continued

New Publication: Synergies in Cybersecurity Incident Reporting – The NIS Cooperation Group Publication 04/20 in Context

A central element of EU cybersecurity legislation is the reporting of security breaches. Mandatory reporting to national authorities promotes a culture of risk management, while also providing for the sharing of information about vulnerabilities. In this line, the GDPR introduced reporting obligations for data controllers based on the assumption that security challenges and relevant mitigation … Continued

New Research Article published: Don’t tell them now (or at all) – responsible disclosure of security incidents under NIS Directive and GDPR

In this article, we critically analyse the timeline for notifications of third parties under the NIS Directive and the GDPR in the case of security and privacy incidents from a legal and technical perspective. While a need to mitigate an immediate risk of damage for an individual would call for prompt notification of data subjects, … Continued