Application security, Critical Infrastructure Security, Supply chain

EU urged to strengthen risk assessment for critical infrastructure vendors

Data protection, binary code with European Union flag

Reported by The Register. A UK-based think tank, the Royal United Services Institute (RUSI), is urging the European Union to develop a more robust and harmonized risk assessment framework for technology vendors supplying critical infrastructure across member states. The report highlights that reliance on Chinese technology poses significant risks that not all EU countries are adequately addressing.

RUSI's report suggests the EU needs a new framework to help member states assess and mitigate risks associated with high-risk ICT vendors, particularly concerning Chinese technology like Huawei and ZTE. Currently, the EU's voluntary 5G Security Toolbox has seen low adoption, with only 10 of 27 members fully implementing it since January 2020. While the European Commission has proposed amendments to the Cyber Security Act to create a list of untrusted vendors for 18 critical sectors, RUSI argues there's no clear definition of a 'high-risk vendor.' The think tank points to differing approaches in Germany, Spain, and the UK regarding Chinese tech, with Germany heavily reliant on Chinese suppliers for its 5G network, Spain showing mixed adoption, and the UK aiming for complete eradication by the end of next year. RUSI emphasizes that concerns about Chinese vendors are well-founded due to potential government control and data access, and that technical vulnerabilities exist across vendors, not just Chinese ones. The report advocates for a more courageous approach to tech procurement as a security measure rather than just a compliance exercise.

Source: The Register

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds