iTnews Asia
  • Home
  • News
  • Government

EU proposes stricter cybersecurity risk checks of smart devices

EU proposes stricter cybersecurity risk checks of smart devices

Fines could be as much as S$21 million.

By Foo Yun Chee on Sep 16, 2022 11:12AM

From laptops to fridges to mobile apps, smart devices connected to the internet will have to be assessed for their cybersecurity risks under draft European Union rules announced on Thursday, amid concerns about a spate of cyber attacks.

Companies face fines of as much as 15 million euros (S$21 million) or up to 2.5 percent of their total global turnover if they fail to comply with the European Commission's proposed law known as the Cyber Resilience Act, which will require manufacturers to fix any problems that are identified.

Companies could save as much as 290 billion euros annually in cyber incidents versus compliance costs of about 29 billion euros, the EU executive said.

A series of high-profile incidents of hackers damaging businesses and demanding huge ransoms in recent years have heightened concerns about vulnerabilities in operating systems, network equipment and software.

"It (the Act) will put the responsibility where it belongs, with those that place the products on the market," EU digital chief Margrethe Vestager said in a statement.

Manufacturers will have to assess the cybersecurity risks of their products and take appropriate action to fix problems for a period of five years or during the expected lifetime of the product.

The companies will have to notify EU cybersecurity agency ENISA of any incidents within 24 hours of becoming aware of them, and take measures to resolve them.

Importers and distributors will have to verify that products conform with EU rules.

The Computer & Communications Industry Association (CCIA Europe) warned that the resulting red tape from the approval process could hamper the roll-out of new technologies and services in Europe.

"Instead the new rules should recognise globally-accepted standards and facilitate cooperation with trusted trade partners to avoid duplicate requirements," Public Policy Director Alexandre Roure said.

If companies do not comply with the EU's rules, national surveillance authorities can prohibit or restrict a product from being made available to their national markets.

The draft rules will need to be agreed upon with EU countries and EU lawmakers before they can become law.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright Reuters
© 2019 Thomson Reuters. Click for Restrictions.
Tags:
ccia europe eu european commisson government security

Related Articles

  • Your organisation’s physical security can be a gateway for cybercriminals
  • How regenerative and responsible AI can power transformation
  • Singapore’s healthtech agency to enhance data and AI platforms
  • The best way to outsmart your threat actors is to think like one
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

How regenerative and responsible AI can power transformation

How regenerative and responsible AI can power transformation

Singapore’s healthtech agency to enhance data and AI platforms

Singapore’s healthtech agency to enhance data and AI platforms

Singapore’s OSTIn and IMDA to develop hybrid satellite-terrestrial networks

Singapore’s OSTIn and IMDA to develop hybrid satellite-terrestrial networks

How badly will the trade wars impact APAC businesses and tech industry?

How badly will the trade wars impact APAC businesses and tech industry?

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.