Building cybersecurity is expensive. In a threat environment that is changing daily, newer and newer defence technologies are emerging that would need to be operated in a highly skills-scarce environment. Moreover, new cybersecurity technologies require knowledge that may not be available in the professional domain, such as artificial intelligence. However, compliance requirements such as NIS2 mean that building adequate defence cannot be neglected and money must be invested in this area.
The European Union has recognised that cyberdefence for European businesses is significantly underdeveloped, with a lack of skilled staff, European products on the market and a slow pace in bringing the latest developments to the mainstream. In order to avoid this competitive disadvantage, significant resources are available in the financial cycle from 2021 onwards to improve European cybersecurity, but these are poorly understood. We would therefore like to give some tips for those who want to build a high-quality Security Operation Centre and NIS2 compliant cyberdefence not only on their own budget.
Among the many possibilities, let’s get to know the Digital Europe Programme! This budget totals €7.5 billion, spread over five different areas. These are artificial intelligence, supercomputing, cybersecurity, digital skills development and ensuring widespread access to digital technologies. For the period 2023-24, €375 million is available for cybersecurity alone. A drop in the ocean, you might say, but still a relatively easy amount to access, not only for national cybersecurity centres but also for SOCs working with them, including those providing services to the private sector. For example, the call promises a 75% grant for procurement within joint tenders, which is not a negligible contribution considering the cost of modern solutions. But for example, €30 million is already available for NIS2 organisations in 2023 to help them prepare, typically at a 50% funding intensity. The EU’s key idea, in line with the European Cybersecurity Strategy, is therefore to support critical infrastructures covered by NIS2, in addition to public CSIRTs and private SOCs, to achieve the grand goal of European cyber resilience.
Other interesting features of the Digital Europe programme include the Digital Innovation Hubs (EDIH), which started operating at the end of 2022 and beginning of 2023. These aim, among other things, to help small and medium-sized enterprises access the latest cybersecurity knowledge. To this end, they organise training courses and provide free or low-cost services that can help interested parties to improve their cybersecurity in a meaningful way. Such hubs are available in all European countries and are well embedded in their own cybersecurity ecosystem, so whether you are a prospective customer or a potential service provider, it is worth contacting them to help you build successful national networks.
Finally, there is the Cybersecurity Skills Academy initiative, also to be launched in 2023, which aims to establish a single set of European educational requirements and an extensive list showing clearly where and what cybersecurity skills can be acquired. As a SOC operator or an organisation covered by NIS2, it may be worthwhile to seek out these training centres and access professionals with skills under the European Cybersecurity Skills Framework through them.
It is therefore important for the European Union to strengthen regional and national cyber defences. And access to resources can be greatly facilitated by the National Coordination Centres to be set up in 2023. The following steps are therefore recommended for SOCs or organisations covered by NIS2:
If you have decided to invest in a cybersecurity product or service, it is worth first contacting a local European Digital Innovation Hub and consulting them about what cutting-edge solutions you should be thinking about. A list of EDIHs can be found here: https://european-digital-innovation-hubs.ec.europa.eu/edih-catalogue
A webinar on how and why outsourcing your security to an MSSP can help transforms your organization and create a 24/7 available and alert attack detection and reaction capacity instantly – to help you protect your data and infrastructure even [...]
NIS2 Directive takes effect today in the EU. We highlight key incident handling elements, enhancing detection, reporting and response under the new regulations.
Building cybersecurity is expensive. In a threat environment that is changing daily, newer and newer defence technologies are emerging that would need to be operated in a highly skills-scarce environment. Moreover, new cybersecurity technologies require knowledge that may not be available in the professional domain, such as artificial intelligence. However, compliance requirements such as NIS2 ...
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.