● SAFER CYBERSPACE EU STEPS in cyber security What did the European Union achieve in cyber security in 2024, and what lies ahead in 2025? V ery few holiday travellers heading to airports in July 2024 could have expected that a cyber incident might suddenly cancel their long-awaited trip. A failed software update from a US cybersecurity provider caused repeated rebooting of computers running the Windows operating system, resulting in billions of euros in damages and disrupting air travel, stock markets, television broadcasts and manufacturing. The impact of cyber incidents on the general public is set to increase in the coming years, and inaction will not provide relief. What steps is the European Union taking to ensure the continued functioning of individuals, businesses and societies in the golden age of cyberattacks? The situation with cyberattacks will not improve anytime soon, and we must increasingly consider the unthinkable - this was the observation made in January 2025 by Robert Viola, head of DG CONNECT, the EU’s directorate-general responsible for cyber security. His statement, along with the growing number of cyberattack headlines, explains why the EU has adopted numerous cybersecurity regulations in recent years. These regulations aim to enhance the cyber resilience of European citizens, businesses and institutions. Digital solutions have become an essential part of societal functioning, rather than being just a convenient alternative to physical services. With this in mind, let us review what the EU achieved in cyber security in 2024, and what lies ahead in 2025. 50 NIS2 In January 2023, the EU’s second cybersecurity directive, NIS2, came into effect, with the goal of establishing a consistently high level of cyber security across all member states. Member states had until October 2024 to incorporate it into national law, but Estonia, along with 20 other countries, missed the deadline. According to those drafting the legislation, the process was slowed by continuous refinements to guidelines and sector-specific inquiries. The goal is now to implement NIS2 by mid-2025, at which point the final scope of businesses affected by the directive will become clear. The directive helps essential and important service providers adopt a strategic approach to cyber security, defines how and whom to notify in case of an attack, and sets baseline cybersecurity requirements. CYBER RESILIENCE ACT On 10 October 2024, member states adopted the Cyber Resilience Act (CRA), which establishes cybersecurity requirements for digital components and internet-connected devices such as smart TVs and home security cameras. The regulation ensures that products containing digital elements, including Internet of Things (IoT) solutions, remain secure throughout the supply chain and product lifecycle. The CRA aims to establish uniform cybersecurity requirements for hardware and software products, avoiding regulatory overlap. It applies to products that are directly or indirectly connected to another device or communication CYBER SECURITY IN ESTONIA 2025

Select target paragraph3