EU Cybersecurity Directive Could Ensnare Ice Cream Makers, Christmas Light Producers
Translated from Slovenian, summarized and contextualized by DistantNews.
At a glance
- The EU's NIS2 directive aims to bolster cybersecurity for critical sectors but faces implementation challenges.
- Its broad definition of critical infrastructure may inadvertently include businesses like ice cream makers and Christmas light producers.
- Concerns exist about the directive's scope, potentially burdening smaller entities and requiring expertise they may lack.
The European Union's new NIS2 directive, designed to enhance cybersecurity across vital sectors, is encountering unexpected complications during its implementation. While intended to protect energy, water, and transport systems from cyber threats, the directive's wide-ranging definitions could ensnare businesses far removed from traditional critical infrastructure.
According to Politico, the directive's scope is so broad that it might classify ice cream manufacturers and producers of Christmas lights as essential entities. This broad classification stems from the directive's inclusion of the food production, processing, and distribution sectors, aiming to safeguard supply chains. However, this could inadvertently bring large ice cream producers or even chewing gum sellers under its purview, as highlighted by Czech European Parliament member Markรฉta Gregorovรก.
Similar confusion surrounds the inclusion of Christmas light manufacturers. While they fall under a classification of significant economic activities, it remains unclear how their operational issues would pose a public safety risk. The directive also presents challenges for educational institutions with solar power installations, as they might be formally categorized as electricity producers, incurring additional costs and demanding cybersecurity expertise that schools often lack.
In Germany, even landlords providing cable or internet connections to multiple tenants could potentially be considered telecommunication service providers, raising questions about their automatic inclusion under NIS2 requirements. The European Commission maintains that the directive includes safeguards, exempting smaller businesses and imposing lighter obligations on less critical organizations. Nevertheless, these unusual cases underscore the difficulty in precisely defining which entities require enhanced protection against rising cyber threats and which would merely face increased bureaucratic burdens.
I am surprised that BPR Kota Bandung has received additional capital several times but still incurs losses. We need to see what is actually happening within the company.
Originally published by Delo in Slovenian. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.