Launched on January 15, 2025, by the European Commission, this action plan aims to significantly bolster the cybersecurity of hospitals and healthcare providers across Europe. As part of the 2024-2029 Commission’s Political Guidelines, the initiative focuses on enhancing threat detection, improving preparedness, and strengthening crisis response capabilities within the healthcare sector. The plan outlines the deployment of tailored guidance, tools, services, and training specifically designed for healthcare environments. Scheduled for progressive rollout in 2025 and 2026, the initiative involves collaboration with healthcare providers, Member States, and the broader cybersecurity community. This marks a pioneering sector-specific effort to apply comprehensive EU cybersecurity measures in healthcare.
Repositories
Access a wealth of resources including articles, whitepapers, tools, and guides to support your learning.
- Emerging Technologies
Cybersecurity Standards for Artificial Intelligence
- Published date:
- Author: European Network and Information Security Agency (ENISA)
This document provides a comprehensive overview of current and emerging standards related to the cybersecurity of artificial intelligence (AI), particularly focusing on machine learning. It evaluates the extent of existing standards, those in draft, under consideration, or planned, and identifies gaps in standardization efforts. By adopting a broad view of cybersecurity that includes the traditional confidentiality-integrity-availability paradigm and the expansive concept of AI trustworthiness, the report highlights how standardization can align with and support the implementation of the EU’s proposed regulations on AI (COM(2021) 206 final). The aim is to enhance the cybersecurity framework for AI technologies, ensuring they are robust, reliable, and trustworthy.
- Emerging Technologies, Threat Intelligence
Integrated Security Strategies for Modern Critical Infrastructures: A Cyber-Physical Systems Approach
- Published date:
- Author: John Soldatos (ed.), James Philpot (ed.), Gabriele Giunta (ed.)
This guidebook explores the integrated security challenges and solutions for modern critical infrastructures, which are increasingly interconnected as large-scale cyber-physical systems. It presents advanced, unified security techniques encompassing both cyber and physical elements, utilizing cutting-edge technologies such as machine learning, IoT security, and distributed ledger infrastructures. The book details how traditional security technologies like SIEM and pen-testing are adapted for comprehensive protection across key sectors including finance, healthcare, energy, and communications. With in-depth case studies and sector-specific analyses, it provides valuable insights for stakeholders planning robust security strategies in the context of Industry 4.0, highlighting the critical interplay between cyber and physical security componen
- Compliance Standards
Strategic Insights and Directions: ECSO Cybersecurity Market Analysis and Recommendations
- Published date:
- Author: European Cyber Security Organisation (ECSO)
This publication by the European Cyber Security Organisation (ECSO), authored by Secretary General Luigi Rebuffi, provides a comprehensive analysis of the European cybersecurity market. Divided into two main sections, it begins with detailed market data and an overview of key drivers, challenges, and barriers facing European cybersecurity stakeholders. The document concludes with targeted recommendations for European and national decision-makers, aimed at enhancing cyber resilience, competitiveness, and strategic autonomy. These recommendations are supported by a framework that stakeholders can utilize to implement strategic cybersecurity measures effectively.
- Emerging Technologies
Securing the Software Supply Chain: Challenges and Strategies in Modern Development
- Published date:
- Author: European Cyber Security Organisation (ECSO)
This technical paper explores the complexities and cybersecurity challenges inherent in modern software development, with a particular focus on the software supply chain. It delves into the lifecycle of software development, the widespread use of third-party components, and the associated risks from these dependencies. The paper highlights the significance of the software supply chain in the context of European sovereignty and outlines how vulnerabilities in upstream components can affect the broader ecosystem. Recommendations are provided on frameworks, best practices for development, maintenance, and reducing risk exposure. Additionally, the paper identifies areas needing innovation to enhance security in software development, emphasizing automation and open-source methodologies.
- Forensic Analysis and Incident Response
Strategic Development of Cyber Exercise Scenarios: Enhancing Incident Response through Simulation
- Published date:
- Author: European Cyber Security Organisation (ESCO)
This White Paper provides a detailed guide on developing technical scenarios for cyber exercises, crucial for enhancing organizational preparedness against cybersecurity threats. It outlines methodologies, scenario development processes, and customization techniques, drawing from real-life use cases and contributions from European cyber exercise service providers. The document emphasizes the importance of cyber exercises in testing and refining organizational response capabilities through simulated real-world scenarios. Targeted at cybersecurity professionals, organizations, educators, and decision-makers, this guide aims to strengthen understanding and execution of cyber exercises, enhancing the overall cybersecurity defenses of an organization.
- Cybersecurity Ethics and Laws
Regulation (EU) 2022/2555 on Digital Operational Resilience for the Financial Sector (DORA)
- Published date:
- Author: European Parliament and the Council of the European Union
Enhances digital operational resilience in the EU financial sector, setting requirements for risk management, incident reporting, testing, and third-party risk management for financial entities.
- Cybersecurity Ethics and Laws
Regulation (EU) No 910/2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS Regulation)
- Published date:
- Author: European Parliament and the Council of the European Union
Establishes a framework for secure and reliable electronic transactions in the EU by enabling electronic identification and trust services (e.g., electronic signatures, seals, timestamps).
- Cybersecurity Ethics and Laws
General Data Protection Regulation (GDPR)
- Published date:
- Author: European Parliament and the Council of the European Union
The GDPR is a comprehensive regulation that sets out rules for the processing of personal data of individuals within the European Union (EU). It aims to protect individuals’ fundamental right to privacy and data protection.