Why are some vulnerabilities disclosed responsibly while others are not?

EU’s cybersecurity agency ENISA has delved into the problematics of vulnerability disclosure and has released a report that addresses economic factors, incentives and motivations that influence the behaviour of the various vulnerability disclosur… Continue reading Why are some vulnerabilities disclosed responsibly while others are not?

Guidelines for assessing ISPs’ security measures in the context of net neutrality

According to the EU’s net neutrality regulation, called the Open Internet Regulation, which came into force in 2016, internet providers should treat all internet traffic to and from their customers equally. Security measures, like blocking traffic on c… Continue reading Guidelines for assessing ISPs’ security measures in the context of net neutrality

ENISA launches Cybersecurity Strategies Evaluation Tool

The European Union Agency for Network and Information Security (ENISA) has launched a tool that will help EU Member States evaluate their priorities according to their National Cyber Security Strategies. ENISA supports EU Member States Since 2012, ENIS… Continue reading ENISA launches Cybersecurity Strategies Evaluation Tool

EU telecoms suffered 169 major security incidents in 2017

ENISA, EU’s agency for network and information security, has released a report on major telecom security incidents that occurred in the EU in 2017. About the report Electronic communication providers in the EU have to report significant security … Continue reading EU telecoms suffered 169 major security incidents in 2017

Strengthening information security to protect against fake news

Online disinformation, also refered to as “fake news”, has recently received a lot of attention as a potential disruptor of democratic processes globally. There is a need to initiate a dialogue in the EU around the possible responses to this phenomenon… Continue reading Strengthening information security to protect against fake news

Are legacy technologies a threat to EU’s telecom infrastructure?

Telecommunications is a key infrastructure based on how our society works. It constitutes the main instrument that allows our democracy and our EU core values such as freedom, equality, rule of law and human rights to function properly. Common types of… Continue reading Are legacy technologies a threat to EU’s telecom infrastructure?

EU needs one set of vulnerability disclosure rules, says expert task force

Cybersecurity researchers in the European Union need legal certainty and consistent standards across its 28 member states if they are to hunt for software vulnerabilities, according to a blue-ribbon commission established by the Center for European Policy Studies. “What we should avoid is that there are 27 or 28 different [legal] frameworks for coordinated vulnerability disclosure and also that there are different definitions being used — of hacking or vulnerability or disclosure — so that this again creates uncertainty for people working in the field,” said European Parliament member Marietje Schaake, chair of the CEPS Task Force on Software Vulnerability Disclosure. Only three of 28 member states currently have a policy on responsible disclosure, although 13 are in the stages of developing one, she told a recent roundtable at the European Parliament. Each member-state has been taking their own approach to vulnerability disclosure, Schaake said, “ranging from sophisticated thinking … […]

The post EU needs one set of vulnerability disclosure rules, says expert task force appeared first on Cyberscoop.

Continue reading EU needs one set of vulnerability disclosure rules, says expert task force

Why developing an internal cybersecurity culture is essential for organizations

ENISA published a report providing organisations with practical tools and guidance to develop and maintain an internal cybersecurity culture. Understanding the dynamics of cybersecurity culture The Cybersecurity Culture in Organisations report is based… Continue reading Why developing an internal cybersecurity culture is essential for organizations

ENISA Releases 2017 Threat Report

The European Union Agency for Network and Information Security (ENISA) – has released it’s Annual Threat Landscape 2017 Report (clicking the preceding link will download the artifact in PDF format). H/T to Jart Armin – Principle at CyberDefcon; a Neth… Continue reading ENISA Releases 2017 Threat Report