Skip to main content
The European Union Agency for Cybersecurity

The European Union Agency for Cybersecurity

Government agencyWikipedia

Search complete. 57 mentions across 18 episodes found for "The European Union Agency for Cybersecurity".

Oct 5, 2026

David SimonHOST
27:34
So this form is called the Single Reporting Platform.
David SimonHOST
27:38
It's managed by ENISA, the European Cyber Agency.
David SimonHOST
27:41
And the manufacturer will then report through this CRA Single Reporting Platform.
David SimonHOST
27:46
You should register to make sure you have access to it if you're subject to the CRA.
David SimonHOST
27:49
And, and many of our clients are asking for us to make sure we have access to the credentials to support them in, in doing this.
David SimonHOST
27:55
The notification then goes from ENISA to the different national certs or national authorities per member state.
David SimonHOST
28:03
So if you make a product and you're subject to CRA, and there's an exploited vulnerability, and it affects customers or entities in your business in ten countries in, in the EU, you click those different countries, and then your notification will then go to those member states' authorities.
David SimonHOST
28:19
It could be a cert, it could be the telecommunications regulator, it could be their ministry of defense or interior, and they're naturally gonna follow up.
speaker_1HOST
2:13
We're looking at a pretty big stack of sources today.
speaker_1HOST
2:15
We've got ENISA user manuals, European Commission policy guidelines, and this really detailed operational evidence brief.
speaker_0HOST
2:23
Lots of heavy reading.
speaker_1HOST
2:24
Oh, for sure.
speaker_0HOST
2:56
Uh, it's gone from a sort of best effort approach to a strict legal mandate.
speaker_1HOST
3:01
Right.
speaker_0HOST
3:02
Under the CRA, manufacturers are now required to report to ENISA, which is the EU Agency for Cyber Security, and also their national CSIRTs.
speaker_1HOST
3:11
The Computer Security Incident Response Teams, right.
speaker_1HOST
2:48
And that shift from data loss to physical safety is exactly why we need to unpack the threat landscape first.
speaker_1HOST
2:54
Looking at the ENISA threat landscape findings, transport hasn't just, you know, popped up on the radar as a minor concern.
speaker_2HOST
3:00
No, not at all.
speaker_2HOST
3:01
It's been a top five targeted sector for the past two years running.
speaker_1HOST
3:05
Right.
speaker_1HOST
3:06
We are tracking highly focused sustained campaigns targeting European transport infrastructure.
speaker_1HOST
3:11
But the part that really stands out to me is from the ENISA NIS 360 report.
speaker_2HOST
3:15
Oh, yeah, the NIS 360 report.
Giulio CoraggioHOST
1:12
of the framework set out by other cyber-related legislation set out by the EU.
Giulio CoraggioHOST
1:20
From the 11th of September, 2026, the first obligations under the Cyber Resilience Act become applicable because they require to identify the products that are under the regime of the Cyber Resilience Act and to report exploitative vulnerabilities and incidents to the single reporting platform set out by ENISA.
Antonio RavennaGUEST
1:45
There's a safeguard rule in this law that was supposed to be a good news.
Antonio RavennaGUEST
1:50
And this rule protects products already on the market from the lowest technical requirement.
Giulio CoraggioHOST
2:59
Secondly, they set out a policy identifying when an incident or a vulnerability needs to be reported.
Giulio CoraggioHOST
3:08
Thirdly, they identify the roles within the organization.
Giulio CoraggioHOST
3:13
Who's in charge of mapping the products, identifying the vulnerability of the incident? Who's in charge of deciding as to whether the vulnerability needs to be reported? Who's in charge of performing the actual notification to ENISA or to the affected individuals? And then testing this procedure because sometimes we see that procedures are very nice on the paper but they've never been tested and since the first reporting obligation starts within 24 hours from the identification of the vulnerability or the incident, the procedure needs to be very well tested in order to make sure that you're not late.
Antonio RavennaGUEST
3:57
This rule has been defined as asymmetric rather than retroactive.
speaker_1HOST
71:43
The safety functions must remain independent.
speaker_1HOST
71:46
During the ENISA Cyber Europe 2026 exercise, they actually simulated scenarios where incident response teams had to mitigate compromised rail systems under intense pressure.
speaker_2HOST
71:57
And what was the takeaway?
speaker_1HOST
71:59
A recurring lesson from those high-stress simulations is that if your monitoring tools cause system instability or if they override the validated safety logic, you are essentially doing the attacker's job for them.
speaker_0HOST
1:26
really do.
speaker_0HOST
1:27
We are pulling from sources like Gartner, Forrester, CISA, ENISA, all to prepare you for the rapidly approaching October 2026 Cybersecurity Awareness Month.
speaker_1HOST
1:37
Which is going to be a big one this year.
speaker_0HOST
1:39
Huge.

21 MINS LATER

speaker_1HOST
22:59
Exactly.
speaker_0HOST
23:00
And across the Atlantic, we are seeing a very similar shift in mindset.
speaker_0HOST
23:04
ENISA, the European Union Agency for Cybersecurity, is running their campaign under the banner, Cybersecurity is a Shared Responsibility.
speaker_1HOST
23:13
Yes.
Dave BittnerHOST
2:02
Digital forensics executives face charges over alleged Russian ties.
Dave BittnerHOST
2:07
ENISA maps Europe's cyber threats.
Dave BittnerHOST
2:10
The U.S. and China have very different ideas about AI safety.
Dave BittnerHOST
2:14
Our guest is Kurt Dusek, technical product advisor at AppDome, sharing thoughts on segregation of duties and AI agents.

8 MINS LATER

Dave BittnerHOST
10:39
The Justice Department isn't alleging the software contained malicious code, enabled unauthorized access, or produced inaccurate results.
Dave BittnerHOST
10:47
Digital forensics experts say the allegations could nevertheless prompt defense attorneys to scrutinize evidence obtained using Oxygen's tools.
Dave BittnerHOST
10:58
ENISA, the European Union Agency for Cybersecurity, is the EU agency responsible for helping member states and EU institutions improve cybersecurity and resilience.
Dave BittnerHOST
11:11
Their 2026 Threat Landscape Report finds an increasingly interconnected cyber threat environment across the European Union, with dependencies on third parties and supply chains expanding organizations' attack surfaces.
Florian PeddingsHOST
1:21
When preparing for and developing the 2026 INISA Threat Landscape, our analysts collected and analyzed more than 8,000 incidents spanning over 2025.
Florian PeddingsHOST
1:34
Using mainly information from open sources as well as anonymized information shared by EU member states and members of the ENISA Cyber Partnership Program, this is a program in which ENISA cooperates with private sector in advancing EU cyber situational awareness.
LauraHOST
1:52
DDoS attacks feature heavily, but these are generally lower impact, whereas ransomware continues to be far more disruptive.
LauraHOST
2:00
Around 30% of threats were financially motivated.
Florian PeddingsHOST
2:38
Since then, EC3 has become a major hub for coordinating the efforts of EU member states law enforcement agencies and has been supporting countless investigations and operations that have disrupted the cyber crime ecosystem.
Florian PeddingsHOST
2:56
Before becoming head of EC3, Ed Vadas was Deputy Police Commissioner General of the Lithuanian Police.
LauraHOST
3:03
Our second guest is ENISA's Head of Sector for Threat Analysis Services, Jamila Boutemeur, who is one of the authors of the 2026 ENISA Threat Landscape.
LauraHOST
3:13
Jamila specializes in state-aligned activities.
Nicolas SchieliGUEST
6:19
it? So basically, in Europe, you have to report to two entities.
Nicolas SchieliGUEST
6:24
One is ENISA.
Nicolas SchieliGUEST
6:26
This is the European National Body for Europe, basically, where you need to report those incidents if they are severe or actively exploited.
Nicolas SchieliGUEST
6:34
And the second one is for your local country, where there's a C-cert that is another local body that actually is the national body.
speaker_0NARRATOR
0:20
AWS struggles to restore its Bahrain region and a UAE zone six months after drone strikes.
speaker_0NARRATOR
0:27
ENISA uses an OpenAI model to uncover vulnerabilities in EU code.
speaker_0NARRATOR
0:33
And finally, we explore the intersection of API and AI gateways in governance and execution.
speaker_0NARRATOR
0:40
Coming up, MediaTek's leap into the two nanometer chip race with TSMC's technology.
speaker_0NARRATOR
3:51
This situation serves as a stark reminder of the potential risks associated with cloud dependency, especially in conflict-prone regions.
speaker_0NARRATOR
3:59
As businesses increasingly rely on cloud services, the need for robust disaster recovery plans becomes more critical.
speaker_0NARRATOR
4:07
ENISA used an open AI model to find four flaws in EU code, Politico reports.
speaker_0NARRATOR
4:13
The European Union Cybersecurity Agency, ENISA, has successfully used an open AI model to identify four vulnerabilities in EU project code.

8 more episodes mention The European Union Agency for Cybersecurity.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.