Get all your news in one place.
100’s of premium titles.
One app.
Start reading
Reuters
Reuters
Health
Foo Yun Chee

Companies may face 2% fine for breaching EU cybersecurity rules

FILE PHOTO: European Commission vice-president Margaritis Schinas wears a protective mask during a news conference on the EU's cybersecurity strategy, in Brussels, Belgium December 16, 2020. Kenzo Tribouillard/Pool via REUTERS

Large energy, transport and financial companies as well as digital providers and makers of medical and computer devices could be fined up to 2% of their global turnover for breaching EU cybersecurity rules under a European Commission proposal.

Concerns about the cybersecurity of key assets have mounted in recent months, especially over cyber attacks by state actors and other malicious players.

European Commission vice-president Josep Borrell wears a protective mask during a news conference on the EU's cybersecurity strategy, in Brussels, Belgium December 16, 2020. Kenzo Tribouillard/Pool via REUTERS

U.S. federal agencies and thousands of companies are now investigating a sweeping hacking campaign that officials suspect was directed by the Russian government. The European Medical Agency was also targeted earlier this month.

With two in five EU employees working from home due to the COVID-19 pandemic and one in eight businesses hit by cyber attacks, the EU executive says its proposal is meant to bolster Europe's collective resilience against cyber threats.

The proposal includes beefing up the 2016 EU cybersecurity law (NIS) with sanctions and expanding its scope to cover all medium and large companies in 10 essential sectors - energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, public administration and space.

EU Commissioner for Internal Market Thierry Breton attends a news conference on the EU's cybersecurity strategy, in Brussels, Belgium December 16, 2020. Kenzo Tribouillard/Pool via REUTERS

Also deemed important entities and falling under the proposed rules would be all medium and large firms in postal and courier services, waste management, chemicals, food manufacturing, medical devices, computers and electronics, machinery equipment, motor vehicles, and digital providers such as online market places, online search engines, and social networking service platforms.

Companies face a range of sanctions for non-compliance, which would also target management, EU Internal Market Commissioner Thierry Breton said.

"Fines for these entities, which are essential and important entities, if these are...repeated actions (in) not fulfilling requirements, (range) from 10 million euros ($12.2 million) to 2% of global revenue," Breton told a news conference.

European Commission vice-presidents Margaritis Schinas and Josep Borrell, and EU Commissioner for Internal Market Thierry Breton attend a news conference on the EU's cybersecurity strategy, in Brussels, Belgium December 16, 2020. Kenzo Tribouillard/Pool via REUTERS

"In a case where a company continues not to fulfil its obligations, in this category, we can go up to suspension of authorisation. That is the last resort. We may also have temporary bans against any persons discharging managerial responsibility," he said.

Companies would be subject to strict cybersecurity requirements covering supply chains and supplier relationships, and also a stringent supervisory regime.

The Commission proposal includes setting up an EU-wide network of security operations centres to detect early signals of imminent cyberattack, and creating a joint cyber unit to boost cooperation between EU bodies and national authorities.

European Commission vice-presidents Margaritis Schinas and Josep Borrell, and EU Commissioner for Internal Market Thierry Breton attend a news conference on the EU's cybersecurity strategy, in Brussels, Belgium December 16, 2020. Kenzo Tribouillard/Pool via REUTERS

The proposal will have to be approved by EU member states and the European Parliament before it can go into effect, a process which could take several years.

($1 = 0.8201 euros)

(Reporting by Foo Yun Chee; Editing by Mark Heinrich)

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.