HomeSecurityParliament: Ambiguities and shadows in the Cybersecurity bill

Parliament: Ambiguities and shadows in the Cybersecurity bill

The new bill of the Ministry of Digital Governance concerning the National Cybersecurity Authority, which is to be discussed today in Parliament, reportedly contains generalities, ambiguities and vagueness.

This is because no clear explanations are provided regarding where the Authority's responsibilities begin and end, as well as whether its action will involve or limit the responsibilities that independent authorities, such as the Personal Data Protection Authority and the Authority for Ensuring the Privacy of Communications, have so far.

Parliament: Ambiguities and shadows in the Cybersecurity bill

Reactions

On a political level, there has already been an initial reaction from PASOK and MP Michalis Katrinis. In a post on X, he noted that "in the bill submitted late last night by the Ministry of Digital Governance, article 32 is noteworthy, where the responsibilities for network and telecommunications security are transferred from ADAE (an independent authority) to the National Cybersecurity Authority (NPDD). Coincidence?".

This was followed by a reaction from Theofilos Xanthopoulos, on behalf of SYRIZA, who attacked the government, claiming that this is "institutional extremism that has no bottom.".

The bill coming to the Plenary today is entitled "Incorporating Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 concerning measures for a high common level of cybersecurity across the Union, amending Regulation (EU) 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) and other provisions".

Supervision of the Cybersecurity Authority

This bill comes as a "tail" of a corresponding piece of legislation a few months ago, which provided for the establishment of a Legal Entity of Public Law under the name "National Cybersecurity Authority".

According to what was announced at the time by the government, "the new Authority will coordinate, implement and control the comprehensive framework of strategies, measures and actions to achieve a high level of Cybersecurity in the country. It will be supervised by the Minister of Digital Governance and will constitute the unified and functional structure that will undertake the design and implementation of the National Cybersecurity Strategy in cooperation with other competent authorities.".

This bill provides, among other things, that there will be "a strengthening of the capabilities, as well as the supervisory and operational role of the Authority, within the framework of the implementation of Directive 2022/2555 (NIS2 Directive)".

The entities that fall within the scope of the NIS 1 Directive are approximately 70, while with the incorporation of NIS 2 into Greek Law, the entities will exceed 2000. At the same time, the Authority will operate as a "National Certification Authority and National Coordination Center for Cybersecurity".

Ambiguities in the bill

The truth is that several of the articles of the bill are characterized by generalities and ambiguities, especially in the area of ​​supervisory control. For example, until today it was known that control over telecommunications - we saw this happen on the occasion of the wiretapping scandal - was held by independent authorities, which also proceeded with relevant controls, as well as the imposition of fines, as happened, for example, with the case of Intellexa.

Experienced lawyers who deal with specific issues told in that "the issues concerning the action of the Authorities in this specific field are constitutionally guaranteed", however, they admitted that the bill in the form it was submitted was quite "general".

The same sources also emphasized that "several times in the field of action, there is involvement, sometimes even a conflict of responsibilities.".

To our question, whether this particular bill "ties the hands" of the authorities, the answer was very specific: "Normally this should not happen, however, as we have seen in certain aspects of the investigation into telephone tapping, other things should not have been done and yet were done.".

The KETYAK

It is also striking that the bill makes no mention of KETYAK, the Center for Technological Development and Innovation, or the "small EYP", within EYP. It is worth noting that until now EYP was responsible for cybersecurity issues for the public sector.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It is recalled that KETYAK was established in 2020 and is an autonomous service within EYP, with its own seal and bank account. A project related to cybersecurity and involving KETYAK, amounting to 40 million euros, was included in the Recovery Fund in 2021, in the pillar under the Ministry of Digital Governance, with EYP as the contracting authority.

For the record, employees of the Krikel company of Yannis Lavranos, directly involved in the wiretapping scandal, have admitted that they provide "unpaid" services at the KETYAK facilities in Agia Paraskevi.

In recent months, the National Cybersecurity Authority has extended an invitation, among others, to executives of the Armed Forces, the Coast Guard, and the Hellenic Police in order to strengthen its services. The question that arises is whether KETYAK will ultimately participate in the cybersecurity program and in what way, as there is no relevant reference in the bill.

What does the Directive include?

The NIS2 Directive concerns: All medium-sized enterprises (employing 50 to 250 employees and having a turnover of up to 250 million euros) or large enterprises operating, for example, in the sectors of Energy, Transport, Health, cloud services and data centers, telecommunications, food production and distribution, production of chemical products, pharmaceutical products, sewage and waste management, and courier companies.

Regardless of their size, providers of public electronic communications networks or publicly available electronic communications services, trust service providers, top-level domain name registries, and domain name system service providers.

With the proposed provisions:

  1. The National Cybersecurity Authority (NCSA) is designated as the single competent authority and as the competent response team.
  2. Cooperation between the public and private sectors is strengthened.
  3. National strategic cybersecurity planning is being strengthened.
  4. A framework for coordinated vulnerability disclosure is established.

It is worth noting that specific sanctions and administrative fines are provided for in case of violation of requirements regarding risk management measures, or non-compliance with incident reporting obligations.

The implementation of NIS2 will increase the demand for cybersecurity services, products and experts. To this end, the National Institute of Cybersecurity will prepare relevant training programs, providing the possibility of certification, in collaboration with other competent bodies, thus contributing to the creation of a domestic cybersecurity ecosystem.

Contest

Finally, since last July, the Information Society announced on behalf of the Ministry of Digital Governance the project "Actions to Strengthen the Security of Public Sector Information and Systems".

This is a project with a budget of over 100 million euros, which concerns the shielding of the Public Sector from cyberattacks. Specifically, the total estimated value of the contract amounts to 102,168,000 euros, including 24% VAT.

Source of information: in.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS