mstdn.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A general-purpose Mastodon server with a 500 character limit. All languages are welcome.

Administered by:

Server stats:

15K
active users

#NIS2

7 posts7 participants0 posts today

“I love deadlines. I love the whooshing noise they make as they go by.” – Douglas Adams

Happy NIS2 deadline wooshing by day!

“Article 3(4) of Directive (EU) 2022/2555 refers to Article 3(3) of that Directive, which requires the Member States to establish a list of essential and important entities, as well as entities providing domain name registration services, by 17 April 2025. Member States must review and, where appropriate, update that list regularly and at least every two years thereafter.”

“According to Article 3(5) of Directive (EU) 2022/2555, by 17 April 2025 and every two years thereafter, Member States must notify the Commission and the Cooperation Group, at least the number of essential and important entities listed pursuant to Article 3(3) of that Directive for each sector and subsector referred to in Annexes I and II of the Directive”

Can, should the #EU step in with filling the gap left behind by #MITRE & #CVE ?

Sure: this is clearly for the public good, and plays nicely with the work on #CRA #PLD #NIS2 etc.

A key problem is the sheer velocity: destruction via tyranny&fascism is fast, building up structures via democratic processes relatively slow.

The EU needs a Fast Track Program to respond to the chaos of the US. The time is ... yesterday.

Continued thread

The European Commission released its "AI Continent Action Plan" last week. This high-level communication lays down the various initiatives the European Commission is pursuing to support Europe's AI ambitions and AI uptake: iapp.org/news/a/a-view-from-br

IAPP · A view from Brussels: What is and isn't in the EU's AI Continent Action PlanBy Isabelle Roccia

#Datensicherheit in der #Politik - wenn die #Dropbox immer noch der Goldstandard ist: Schon die gescheiterte #NIS2-Umsetzung hat im vergangenen Jahr gezeigt, dass das Thema #Cybersecurity definitiv noch nicht nicht überall in der Politik angelangt ist. Nun wurden im Rahmen einer Recherche über 500 Darknet-Datenleaks von Politiker:innen festgestellt - u.a. für Dropbox. In einem Fall konnten gar 14 Passwörter im Klartext einer Einzelperson zugeordnet werden:

golem.de/news/grossteil-im-kla

Golem.de · Großteil im Klartext: Passwörter deutscher Politiker im Darknet entdeckt - Golem.deBy Marc Stöckel

❓Interested in a NIS2 Readiness Assessment❓

EU has released NIS2 to all countries within the European Union. In 2024 NIS will be adopted to local law enforcement and become relevant for a large amount of companies. Check Point can help you preparing your company for NIS2 and assist you in improving your security standards and procedures.

A team of senior Check Point consultants will analyze your business for compliance with the NIS2 directive. The assessment is typically done on site but can also be performed remotely on request. We will summarize the findings in a report and provide a recommended action plan to increase compliance with the NIS2 directive.

Benefits:

✅ Determine what areas of your cyber landscape are impacted
✅ Get an overview of the necessary technical requirements
✅ Present the processes needed for full compliance
✅ Risk management
✅ Asset management
✅ Business continuity management
✅ Vulnerability management
✅ Supply chain management
✅ Incident response procedures
✅ Current security architecture and controls review
✅ Obtain details to help train your security team

checkpoint.com/services/infini

Check Point SoftwareNIS2 Readiness Assessment - Check Point Software

Umsetzung von #NIS2 verzögert sich, doch das Gesetz gilt ohne Übergangsfrist, sobald es in Kraft tritt.🔗 heise.de/hintergrund/NIS2-Umse

@privacyDE: „IT-Angriffe auf Systeme mit personenbezogenen Daten gelten als Datenschutzvorfälle. BSI-Chefin Plattner fordert den BSI-Grundschutz, der auch datenschutzrechtliche Anforderungen abdeckt, durchgängig in der Verwaltung. Mangelnde Regelungen im IT-Schwachstellenmanagement stellen ein Risiko für IT-Sicherheit und betroffene Personen dar.“

#TeamDatenschutz

iX MagazinNIS2-Umsetzung verzögert sich – Unternehmen müssen trotzdem handelnAuch wenn die EU-Cybersicherheitsrichtlinie NIS2 noch nicht in nationales Recht umgesetzt ist, werden Firmen nicht drumherum kommen, jetzt aktiv zu werden.

In parallel to a boycott of mainstream US products by EU citizens to push back on Trump tariffs, a New big deal should be negotiated now between EU, japan, Vietnam and China related to GPUs and other electronics needed to rebuilt EU computer industry for scientific theoritical and applied computer/AI research, quantum cryptanalysis/cryptography, space satellites belts, and supporting serious EU scientific's no commercial bullshit AI with both civil and military defense applications.

Opt out of US cloud should start now with EU Datacenters belonging to companies whose shareholders and applications hosted must remain EU based (only submitted to EU laws and EU companies only operating controls (continuity). This should be part of DORA and other cybersecurity regulations (NIS2, GDPR). GDPR could be relaxed, but only for complete EU sovereign stack (AI algorithmes, AI framework, application/middleware/datacenters, locations, shareholders,...).

Diversity in supply chains and enhanced autonomy of actions in business, science and war is required in those complex times.

Not all eggs in the same basket.

Nobody must be in position to disrupt remotely by design the EU business, society and military intelligence, decisions making and execution processes.

Ooda loop confidentiality, integrity and availability must become at light speed 100% sovereign in current and immediate future context. Tools that are close to Trump/musk such as palantir should not be used by EU critical insfrastructures/businesses as the information they collect on EU business, military and citizens could be used in nefarious ways and these tools (like other AI tools) learn a lot of their users/gov concerns/plans by observing the questions asked to them.

#tariffs#democracy#EU

Der Podcast @DieSicherheits_luecke soll Wissenslücken füllen – mit praxisnahen Einblicken und verständlichen Erklärungen rund um #Cybersicherheit. 🔍 🔐

In der aktuellen Episode zu Gast ist @kenji, der als Teil des GI-Präsidiums die Empfehlungen und Positionen der GI mitgestaltet. Er und die Hosts Volker Skwarek, Monina Schwarz und Ingo Timm nehmen die #NIS2 unter die Lupe, die IT-Sicherheit in der EU verbessern soll.

Hier reinhören 👉 sicherheitsluecke.fm/5-nis-2-k