Security Experts:

Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

European Cybersecurity Agencies Issue Resilience Guidance for Decision Makers

The European Union Agency for Cybersecurity (ENISA) and the European Union’s Computer Emergency Response Team (CERT-EU) last week published a set of best practices to help organizations boost their cyber resilience.

The European Union Agency for Cybersecurity (ENISA) and the European Union’s Computer Emergency Response Team (CERT-EU) last week published a set of best practices to help organizations boost their cyber resilience.

The joint guidance is meant for public and private organizations in the EU, specifically CISOs and other decision makers. The document is also recommended for entities that support organizational risk management.

A total of 14 recommendations are outlined, and organizations have been advised to prioritize them based on their specific business needs.

The list includes the implementation of multi-factor authentication, avoiding the reuse of passwords to prevent credential stuffing attacks, ensuring that all software is up-to-date, limiting the access of third parties to internal networks and systems, hardening cloud environments, reviewing data backup strategies, and changing default credentials and disabling protocols that use weak authentication.

The agencies also recommend employing network segmentation, conducting regular training and cyber awareness events, creating a resilient email security environment, deploying protection against denial-of-service (DoS) attacks, limiting internet access for servers and other devices that could be abused for command and control (C&C) purposes by malicious actors, and creating procedures to efficiently communicate with computer security incident response teams (CSIRT).

“By following these recommendations in a consistent, systematic manner, ENISA and CERT-EU remain confident that organisations in the EU will be able to substantially improve their cybersecurity posture and in doing so will enhance the overall cyber resilience of Europe,” the cybersecurity agencies said.

However, the agencies noted that their recommendations can complement guidance issued by national or governmental cybersecurity authorities, but they do not replace it.

While other similar cybersecurity recommendations are available from both the private and public sector, implementing these recommendations is in many cases not an easy task, including due to budget and workforce constraints.

The guidance comes just weeks after major oil terminals in some of Western Europe’s biggest ports were hit by disruptive cyberattacks.

The recommendations also coincide with tensions mounting over a potential Russian invasion of Ukraine. Agencies in the United States have issued several warnings over the past weeks due to the threat posed by Russian cyber groups — while Russia appears to have mainly targeted Ukraine, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) noted that Moscow may expand its “destabilizing actions” outside of Ukraine.

Related: Security Scanners Across Europe Tied to China Govt, Military

Related: Europe’s Hypocrisy Over Personal Data Privacy Exposed

Related: EU Denounces Alleged Russian Hacking Ahead of German Vote

Written By

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Breaches

GoTo said an unidentified threat actor stole encrypted backups and an encryption key for a portion of that data during a 2022 breach.

CISO Strategy

Cybersecurity-related risk is a top concern, so boards need to know they have the proper oversight in place. Even as first-timers, successful CISOs make...

Identity & Access

Hackers rarely hack in anymore. They log in using stolen, weak, default, or otherwise compromised credentials. That’s why it’s so critical to break the...

Management & Strategy

Tens of cybersecurity companies have announced cutting staff over the past year, in some cases significant portions of their global workforce.

Risk Management

A threat-based approach to security often focuses on a checklist to meet industry requirements but overlooked the key component of security: reducing risk.

Audits

Out of the 335 public recommendations on a comprehensive cybersecurity strategy made since 2010, 190 were not implemented by federal agencies as of December...

Management & Strategy

Microsoft making a multiyear, multibillion dollar investment in the artificial intelligence startup OpenAI, maker of ChatGPT and other tools.