Cybersecurity Policy Report, ENISA Expresses Commitment to EU Plan for Health Care Cybersecurity, (Jan 22, 2025)
The European Union Agency for Cybersecurity (ENISA) yesterday shared details on its implementation of the European Union’s “action plan” for the cybersecurity of hospitals and health care providers, which was proposed by the European Commission (EC) last week (CPR, Jan. 16).
Under the plan, several specific actions are foreseen to be implemented progressively in 2025 and 2026 in collaboration with member states, health care providers, and the cybersecurity community, ENISA noted in a news release.
The EC proposed that ENISA establish a pan-European Cybersecurity Support Centre for hospitals and health care providers. The center would provide stakeholders with tailored guidance, tools, services, and training.
The proposed tasks include developing guidance for cybersecurity good practices and procurement, developing a regulatory mapping tool, establishing EU capabilities for detecting cyber threats against the health sector, introducing an early warning service for the sector, and developing cyber incident response playbooks.
ENISA said the actions proposed corresponded to its current mandate to help EU member states increase the resilience of their critical sectors, while acknowledging that member states had different needs.
“To achieve the goals set out by the Action Plan, a joint effort is needed and adequate resources are required to fulfil the new actions,” it said.
News: InternationalLegislation DataSecurity