home.social

#enisa — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #enisa, aggregated by home.social.

fetched live
  1. @kenji
    Der Leitfaden ist von der @EUCommission und nicht von der #ENISA
    IMHO

    Hilfreich ist er, lässt aber leider noch ein paar Fragen offen.

    #Leitfaden #ENISA #EU #CRA #cybersecurity

  2. Nicht unumstritten, aber trotzdem sinnvoll: Dass es einen #Leitfaden der #ENISA zur Umsetzung des #EU #CRA geben soll, ist schon länger bekannt.

    Nachdem die Konsultation nämlich im April auslief, war das Echo bei Verbänden und Co. zu dem Dokument durchaus gemischt.

    Andererseits ist der CRA selbst deutlich konkretisierungsbedürftig und nicht selbsterklärend. Sinnvoll ist der unverbindliche Leitfaden, der nun veröffentlicht wurde, deshalb in jedem Falle:

    ec.europa.eu/newsroom/dae/redi #cybersecurity

  3. I'm part of the OSS team on the SBOM workstrand within the EU CRA Expert Group; something to entertain me over the summer.

    One issue I have with SBOMs is that all the generators are monoculture- you've got the npm generator, the maven generator, the new ant one, etc. But something like a quarkus app built with gradle, a .js gui (npm) and a rust lib (crates) is three ecosystems and 3 sboms, all of which need immediate integration during the build.

    If the release is a docker container then every command to generate the docker container is potentially a transformation of the aggregate SBOMs of all inputs, where the inputs include all containers you are layered on. Ouch.

    #enisa #cra #cybersecurity

  4. 🚨 Cyber Resilience Act: Die CRA-Meldepflichten rücken näher.
    Ab 11. September 2026 müssen Hersteller aktiv ausgenutzte Schwachstellen und schwerwiegende Sicherheitsvorfälle mit Auswirkungen auf die Produktsicherheit über die von #ENISA bereitgestellte CRA Single Reporting Platform melden.
    🌍 Damit entsteht erstmals ein EU-weit einheitlicher Meldeweg.

    Mehr Infos findet ihr hier: bsi.bund.de/dok/cra

    #CybernationDeutschland #Cybernation #BSI #CyberResilienceAct #CRA

  5. Podcast news
    ⏯️ Bringing you a new format to consume #ENISA news on the go.

    Frontier AI and cybersecurity was covered in a recent publication and now we bring these views via our new podcast.

    Tune in, subscribe and comment. Links to podcasts wherever you get them: enisa.europa.eu/news/enisa-on-

  6. 🚀 Vulnerability-Lookup 5.3.0 has landed with a new email notification service. 📬

    Pick any Known Exploited #Vulnerabilities catalog — #CISA, #ENISA, #Shadowserver, CIRCL, KEVIntel — and get a batched email digest the moment new entries land. Exploited-in-the-wild intel, delivered straight to your inbox. No polling, no scraping.

    Full release notes 👉 vulnerability-lookup.org/2026/

    Try it live at vulnerability.circl.lu

    Feel free to create an account if you want to use the email notification service.

  7. 📰 EU Includes Ukraine in Cybersecurity Reserve for Emergency Incident Response

    🇪🇺🇺🇦 The EU has officially included Ukraine in its Cybersecurity Reserve. This allows Ukraine to call on emergency support from top private-sector responders managed by ENISA to combat major cyberattacks. #CyberSecurity #EU #Ukraine #ENISA

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/eu

  8. Der #ENISA NIS360-Bericht 2026 zeigt: #NIS2 wirkt und treibt Investitionen an, doch die Risikozone wächst.

    Schienen, Wasserversorgung und Raumfahrt sind anfällig, Krankenhäuser und Behörden bleiben bekannte Schwachstellen. Stark regulierte Sektoren wie Banken und Telekommunikation gelten dagegen als Vorbilder, weil sie #Cybersecurity als Geschäftsrisiko verankert haben.

    Die Erkenntnis: Compliance schafft Mindeststandards, aber keine nachhaltige #Resilienz:
    enisa.europa.eu/enisa-nis360-2 #KRITIS #DORA

  9. This year's edition of the ENISA NIS360 report shows improvement in #cybersecurity maturity of #EU critical sectors. This edition (2026) is the third to assess the cybersecurity maturity and criticality of all sectors of high criticality as identified under Annex I of the NIS2 directive.

    ENISA NIS360 2026 Report: enisa.europa.eu/sites/default/

    #europe #cybersecurity #enisa

  10. ENISA’s new strategy for a trusted, cyber-secure Europe! 🛡️ Watch a clear breakdown of seven objectives to boost EU cooperation, resilience and digital sovereignty. Essential for policymakers, IT pros, and anyone who cares about online safety. #ENISA #cybersecurity #EU #infosec #privacy #cybersecure #digitalsovereignty #English
    videos.enisa.europa.eu/videos/

  11. Hello #EUPolicy community! 👋 #Introduction

    As the Sept 2026 #ENISA deadline nears, the industry is moving from "Policy" to "Practice." 🇪🇺

    At craevidence.com, we help manufacturers, importers, and distributors automate #CyberResilienceAct compliance. Replace manual spreadsheets with:

    🛠️ Practical #CRA documentation
    📦 #SBOM & VEX management
    🇪🇺 #CEmarking evidence

    The 24h reporting window is coming. We provide the automated bridge to ENISA notification. 🤝

    #DigitalEU #Sovereignty #CyberSecurity

  12. Borja Luis Cabezón: hasta 10 años de inhabilitación por presidir una empresa pública y tener otra fantasma

    elconfidencial.com/espana/2026

    Del PSOE, miembro de la Ejecutiva de Ferraz fue consejero de la compañía de #energíasrenovables #Renerstorex SL hasta enero de 2025 pese a ser nombrado consejero delegado de #Enisa, Empresa Nacional de Innovación S.A, un año antes

  13. La UE presentó una nueva Caja de Herramientas de Seguridad de la Cadena de Suministro de TIC, que proporciona un enfoque de la UE para identificar, evaluar y mitigar los riesgos de ciberseguridad en las cadenas de suministro de TIC

    administracionelectronica.gob.

    Alcance:
    For the purpose of the ICT Supply Chain Security Toolbox, the subject matter of the risk assessments are ICT services, ICT systems or ICT products supply chains,
    encompassing hardware, software including free and open-source software (FOSS) ...

    The CRA will play a key role in securing ICT supply chains by:
    ... Providing a light-touch regulatory regime on the FOSS and the so-called open-
    source software stewards.

    ICT supply chain and Supply chain entities:
    .. (e.g. microchip manufacturers, open-source libraries, or third-country
    subcontractors).

    A resilient, trusted, and transparent industrial base
    Promote the security and visibility of open-source software and hardware, particularly where this could help secure the supply chain of critical entities, and promote the adoption of secure open-source alternatives, for instance by
    ▪ open-sourcing existing public sector solutions,
    ▪ through the creation of open-source programme offices, and
    ▪ diversifying digital internet infrastructures, such as code
    repositories or encryption certificate authorities

    #LeyDeCiberseguridad #CRA #SupplyChain #CadenaDeSuministro #NIS2 #ENISA