Reported by The Register. A UK-based think tank, the Royal United Services Institute (RUSI), is urging the European Union to develop a more robust and harmonized risk assessment framework for technology vendors supplying critical infrastructure across member states. The report highlights that reliance on Chinese technology poses significant risks that not all EU countries are adequately addressing.
RUSI's report suggests the EU needs a new framework to help member states assess and mitigate risks associated with high-risk ICT vendors, particularly concerning Chinese technology like Huawei and ZTE. Currently, the EU's voluntary 5G Security Toolbox has seen low adoption, with only 10 of 27 members fully implementing it since January 2020. While the European Commission has proposed amendments to the Cyber Security Act to create a list of untrusted vendors for 18 critical sectors, RUSI argues there's no clear definition of a 'high-risk vendor.' The think tank points to differing approaches in Germany, Spain, and the UK regarding Chinese tech, with Germany heavily reliant on Chinese suppliers for its 5G network, Spain showing mixed adoption, and the UK aiming for complete eradication by the end of next year. RUSI emphasizes that concerns about Chinese vendors are well-founded due to potential government control and data access, and that technical vulnerabilities exist across vendors, not just Chinese ones. The report advocates for a more courageous approach to tech procurement as a security measure rather than just a compliance exercise.
Source: The Register

