Existing situation
Only telecom companies have an obligation to report significant security incidents and to ensure the security of their networks and services.
Udo Helmbrecht, head of the EU Network and Information Security Agency, told EuroparlTV in March: "There is a regulation where there is an article that telecoms companies have to report but in the other areas you can say that everyone can still do what they want."
New proposal
The European Commission adopted in 2013 its first ever EU cybersecurity strategy and proposed a new directive that would require owners of critical infrastructure such as energy, banking, health and transport to ensure a minimum level of security and step up cooperation on security.
"What we do aim to ensure is that whenever citizens deal with critical infrastructure they are protected from hacking attacks," said Andreas Schwab in an interview with EuroparlTV last October. The German EPP member is leading negotiations on the new directive on behalf of the EP with the Council and the Commission.
REF. : 20150526STO59635