EU adopts “world first” cybersecurity legislation for manufacturers, including oil, gas industry

General News

Summary

The Act will also introduce a legal obligation for manufacturers to provide consumers with timely security updates for several years after the purchase. In the last year, the number of software supply chain attacks have tripled, and every day, small businesses and critical institutions like hospitals are targeted by cyber criminals. George McGregor, VP, Approov Mobile Security said, “Despite a lot of pushback, particularly on the 24 hour breach reporting requirements, the EU Cyber Resiliency Act (CRA) is now on its way to being in force in 2024. Companies will have a 21-month grace period before they must conform with the reporting obligation of manufacturers for incidents and vulnerabilities.” “Any companies who operate in the EU would do well to make it a priority to study this legislation: it provides a cybersecurity framework and rules governing the planning, design, development and maintenance of any products, with obligations to be met at every stage of the value chain. David Ratner, CEO, HYAS Infosec, said, "The Cyber Resiliency Act is a great start and will certainly help to increase transparency and responsibility.

Classifications

industries
No industries detected
applications
Security

AskAI Classifications

Labels
No AI classifications detected

Linked Companies