EU Cybersecurity Rules Create a New Kind of Cyber Slop

0
20
EU Cybersecurity Rules Create a New Kind of Cyber Slop

Lawyers advising EU businesses have spent recent weeks explaining an unusual reality: ice-cream producers, Christmas-light manufacturers and chewing-gum wholesalers are now on track to be classified as critical infrastructure. That is the reach of the EU’s NIS2 cybersecurity directive, adopted in 2022 to protect sectors whose disruption could damage society or the economy.

Broad sector definitions and company-size thresholds have pulled in businesses that hardly resemble power stations or hospitals. France, Spain, Ireland and the Netherlands were referred to the Court of Justice of the European Union this summer for still failing to transpose the rules into national law.

Ice Cream Turns Critical

Member states were required to transpose NIS2 into national law by October 2024, and only Belgium, Croatia, Italy and Lithuania met that original deadline. The broad sector definitions extend well beyond ice cream and Christmas lights, with unexpected classifications reportedly reaching some German landlords too.

Twenty months after the deadline passed, most of the bloc has still only partially aligned its national rules.

Facing that criticism, the European Commission has proposed targeted amendments intended to simplify compliance for 28,700 companies, including 6,200 micro and small enterprises. A new category for mid-sized firms is meant to reduce costs for a further 22,500 businesses.

Regulation needs breadth because supply chains create surprising vulnerabilities, yet labelling too many organisations “critical” eventually weakens the meaning of the word.

EU Cybersecurity Rules Create a New Kind of Cyber Slop  Daily Euro Times
EU Cybersecurity Rules Create a New Kind of Cyber Slop

AI Multiplies the Noise

The timing makes that problem more serious. The Commission’s new cybersecurity and AI action plan, published in July, warns that advanced AI can identify vulnerabilities, automate attacks and increase their speed and scale dramatically.

Recent incidents have already shown autonomous systems behaving unpredictably during cybersecurity testing. The Commission has opened talks with OpenAI and Anthropic after their AI models demonstrated hacking capabilities that raised concerns over supervision and control.

The same technology that helps defenders scan networks can also produce endless phishing attempts, vulnerability probes and convincing social-engineering material at negligible cost. That is cyber slop in a more literal sense.

It means enormous quantities of cheap, automated hostile activity demanding limited human attention from teams already stretched by compliance paperwork.

Security Needs Clear Priorities

The danger is therefore not excessive cybersecurity, but cybersecurity reduced to paperwork, alerts and classifications that give every risk roughly equal administrative weight. A medium-sized food manufacturer can unquestionably suffer a damaging cyberattack, yet it still does not occupy the same strategic position as an electricity grid, hospital network or water system.

Treating a chewing-gum wholesaler and a power grid as equally urgent does not make either one safer.

The Commission recognises the problem, hence its attempt to simplify NIS2 while simultaneously preparing stronger AI-security testing, though Europe’s continued dependence on private digital infrastructure complicates that balancing act. Good cyber defence requires knowing what deserves immediate attention, and AI is making threats cheaper to generate exactly as regulation makes the pool of regulated organisations larger.

If both sides keep producing volume faster than institutions can process it, Europe may become skilled at documenting cybersecurity while growing less certain where its worst vulnerabilities sit.

Keep up with Daily Euro Times for more updates

Read also:

Palantir’s European Expansion: Tech Dependence Wrapped in Security


Flock Camera Resistance Questions Europe’s Monitoring Guardrails


Big Tech Immoderation: Europe’s Digital Reckoning

LEAVE A REPLY

Please enter your comment!
Please enter your name here