● SAFER CYBERSPACE
EU STEPS
in cyber security
What did the European Union achieve in cyber security in 2024,
and what lies ahead in 2025?
V
ery few holiday travellers heading to
airports in July 2024 could have
expected that a cyber incident might
suddenly cancel their long-awaited
trip. A failed software update from a US cybersecurity provider caused repeated rebooting of
computers running the Windows operating system, resulting in billions of euros in damages
and disrupting air travel, stock markets, television broadcasts and manufacturing.
The impact of cyber incidents on the general
public is set to increase in the coming years,
and inaction will not provide relief. What steps
is the European Union taking to ensure the continued functioning of individuals, businesses
and societies in the golden age of cyberattacks?
The situation with cyberattacks will not
improve anytime soon, and we must increasingly consider the unthinkable - this was the
observation made in January 2025 by Robert
Viola, head of DG CONNECT, the EU’s directorate-general responsible for cyber security. His
statement, along with the growing number of
cyberattack headlines, explains why the EU has
adopted numerous cybersecurity regulations in
recent years. These regulations aim to enhance
the cyber resilience of European citizens, businesses and institutions. Digital solutions have
become an essential part of societal functioning, rather than being just a convenient alternative to physical services.
With this in mind, let us review what the EU
achieved in cyber security in 2024, and what
lies ahead in 2025.
50
NIS2
In January 2023, the EU’s second cybersecurity
directive, NIS2, came into effect, with the goal of
establishing a consistently high level of cyber
security across all member states. Member states
had until October 2024 to incorporate it into
national law, but Estonia, along with 20 other
countries, missed the deadline. According to
those drafting the legislation, the process was
slowed by continuous refinements to guidelines
and sector-specific inquiries. The goal is now to
implement NIS2 by mid-2025, at which point
the final scope of businesses affected by the
directive will become clear. The directive helps
essential and important service providers adopt
a strategic approach to cyber security, defines
how and whom to notify in case of an attack, and
sets baseline cybersecurity requirements.
CYBER RESILIENCE ACT
On 10 October 2024, member states adopted
the Cyber Resilience Act (CRA), which establishes cybersecurity requirements for digital
components and internet-connected devices
such as smart TVs and home security cameras.
The regulation ensures that products containing digital elements, including Internet of
Things (IoT) solutions, remain secure throughout the supply chain and product lifecycle.
The CRA aims to establish uniform cybersecurity requirements for hardware and software
products, avoiding regulatory overlap. It applies
to products that are directly or indirectly connected to another device or communication
CYBER SECURITY IN ESTONIA 2025