The European Union Agency for Cybersecurity
Government agencyWikipedia
57
MENTIONS
18
EPISODES
14
PODCASTS
Search complete. 57 mentions across 18 episodes found for "The European Union Agency for Cybersecurity".
Oct 5, 2026
Hugging Face and the ‘Rogue AI’ Question — With the FT’s Elaine Moore
D
27:34David SimonHOST
So this form is called the Single Reporting Platform.
D
27:38David SimonHOST
It's managed by ENISA, the European Cyber Agency.
D
27:41David SimonHOST
And the manufacturer will then report through this CRA Single Reporting Platform.
D
27:46David SimonHOST
You should register to make sure you have access to it if you're subject to the CRA.
D
27:49David SimonHOST
And, and many of our clients are asking for us to make sure we have access to the credentials to support them in, in doing this.
D
27:55David SimonHOST
The notification then goes from ENISA to the different national certs or national authorities per member state.
D
28:03David SimonHOST
So if you make a product and you're subject to CRA, and there's an exploited vulnerability, and it affects customers or entities in your business in ten countries in, in the EU, you click those different countries, and then your notification will then go to those member states' authorities.
D
28:19David SimonHOST
It could be a cert, it could be the telecommunications regulator, it could be their ministry of defense or interior, and they're naturally gonna follow up.
CRA’s 24-Hour Clock: Deciding Under Incomplete Evidence
S
2:13speaker_1HOST
We're looking at a pretty big stack of sources today.
S
2:15speaker_1HOST
We've got ENISA user manuals, European Commission policy guidelines, and this really detailed operational evidence brief.
S
2:23speaker_0HOST
Lots of heavy reading.
S
2:24speaker_1HOST
Oh, for sure.
S
2:56speaker_0HOST
Uh, it's gone from a sort of best effort approach to a strict legal mandate.
S
3:01speaker_1HOST
Right.
S
3:02speaker_0HOST
Under the CRA, manufacturers are now required to report to ENISA, which is the EU Agency for Cyber Security, and also their national CSIRTs.
S
3:11speaker_1HOST
The Computer Security Incident Response Teams, right.
Schneider Electric’s CVE-2026-77120: The Dangerous Assumption Behind Authenticated Access
S
2:48speaker_1HOST
And that shift from data loss to physical safety is exactly why we need to unpack the threat landscape first.
S
2:54speaker_1HOST
Looking at the ENISA threat landscape findings, transport hasn't just, you know, popped up on the radar as a minor concern.
S
3:00speaker_2HOST
No, not at all.
S
3:01speaker_2HOST
It's been a top five targeted sector for the past two years running.
S
3:05speaker_1HOST
Right.
S
3:06speaker_1HOST
We are tracking highly focused sustained campaigns targeting European transport infrastructure.
S
3:11speaker_1HOST
But the part that really stands out to me is from the ENISA NIS 360 report.
S
3:15speaker_2HOST
Oh, yeah, the NIS 360 report.
Cyber Resilience Act: What Does the September 11 Deadline Mean?
G
1:12Giulio CoraggioHOST
of the framework set out by other cyber-related legislation set out by the EU.
G
1:20Giulio CoraggioHOST
From the 11th of September, 2026, the first obligations under the Cyber Resilience Act become applicable because they require to identify the products that are under the regime of the Cyber Resilience Act and to report exploitative vulnerabilities and incidents to the single reporting platform set out by ENISA.
A
1:45Antonio RavennaGUEST
There's a safeguard rule in this law that was supposed to be a good news.
A
1:50Antonio RavennaGUEST
And this rule protects products already on the market from the lowest technical requirement.
G
2:59Giulio CoraggioHOST
Secondly, they set out a policy identifying when an incident or a vulnerability needs to be reported.
G
3:08Giulio CoraggioHOST
Thirdly, they identify the roles within the organization.
G
3:13Giulio CoraggioHOST
Who's in charge of mapping the products, identifying the vulnerability of the incident? Who's in charge of deciding as to whether the vulnerability needs to be reported? Who's in charge of performing the actual notification to ENISA or to the affected individuals? And then testing this procedure because sometimes we see that procedures are very nice on the paper but they've never been tested and since the first reporting obligation starts within 24 hours from the identification of the vulnerability or the incident, the procedure needs to be very well tested in order to make sure that you're not late.
A
3:57Antonio RavennaGUEST
This rule has been defined as asymmetric rather than retroactive.
Detecting the Attack Is Not Proving Safety: IAM4RAIL and Railway Cybersecurity
S
71:43speaker_1HOST
The safety functions must remain independent.
S
71:46speaker_1HOST
During the ENISA Cyber Europe 2026 exercise, they actually simulated scenarios where incident response teams had to mitigate compromised rail systems under intense pressure.
S
71:57speaker_2HOST
And what was the takeaway?
S
71:59speaker_1HOST
A recurring lesson from those high-stress simulations is that if your monitoring tools cause system instability or if they override the validated safety logic, you are essentially doing the attacker's job for them.
Cyber Horizon 2026: The Year in Review; October Awareness Kickoff
S
1:26speaker_0HOST
really do.
S
1:27speaker_0HOST
We are pulling from sources like Gartner, Forrester, CISA, ENISA, all to prepare you for the rapidly approaching October 2026 Cybersecurity Awareness Month.
S
1:37speaker_1HOST
Which is going to be a big one this year.
S
1:39speaker_0HOST
Huge.
21 MINS LATER
S
22:59speaker_1HOST
Exactly.
S
23:00speaker_0HOST
And across the Atlantic, we are seeing a very similar shift in mindset.
S
23:04speaker_0HOST
ENISA, the European Union Agency for Cybersecurity, is running their campaign under the banner, Cybersecurity is a Shared Responsibility.
S
23:13speaker_1HOST
Yes.
No factoring necessary.
D
2:02Dave BittnerHOST
Digital forensics executives face charges over alleged Russian ties.
D
2:07Dave BittnerHOST
ENISA maps Europe's cyber threats.
D
2:10Dave BittnerHOST
The U.S. and China have very different ideas about AI safety.
D
2:14Dave BittnerHOST
Our guest is Kurt Dusek, technical product advisor at AppDome, sharing thoughts on segregation of duties and AI agents.
8 MINS LATER
D
10:39Dave BittnerHOST
The Justice Department isn't alleging the software contained malicious code, enabled unauthorized access, or produced inaccurate results.
D
10:47Dave BittnerHOST
Digital forensics experts say the allegations could nevertheless prompt defense attorneys to scrutinize evidence obtained using Oxygen's tools.
D
10:58Dave BittnerHOST
ENISA, the European Union Agency for Cybersecurity, is the EU agency responsible for helping member states and EU institutions improve cybersecurity and resilience.
D
11:11Dave BittnerHOST
Their 2026 Threat Landscape Report finds an increasingly interconnected cyber threat environment across the European Union, with dependencies on third parties and supply chains expanding organizations' attack surfaces.
ENISA On Air Episode 2: ENISA Threat Landscape 2026
F
1:21Florian PeddingsHOST
When preparing for and developing the 2026 INISA Threat Landscape, our analysts collected and analyzed more than 8,000 incidents spanning over 2025.
F
1:34Florian PeddingsHOST
Using mainly information from open sources as well as anonymized information shared by EU member states and members of the ENISA Cyber Partnership Program, this is a program in which ENISA cooperates with private sector in advancing EU cyber situational awareness.
L
1:52LauraHOST
DDoS attacks feature heavily, but these are generally lower impact, whereas ransomware continues to be far more disruptive.
L
2:00LauraHOST
Around 30% of threats were financially motivated.
F
2:38Florian PeddingsHOST
Since then, EC3 has become a major hub for coordinating the efforts of EU member states law enforcement agencies and has been supporting countless investigations and operations that have disrupted the cyber crime ecosystem.
F
2:56Florian PeddingsHOST
Before becoming head of EC3, Ed Vadas was Deputy Police Commissioner General of the Lithuanian Police.
L
3:03LauraHOST
Our second guest is ENISA's Head of Sector for Threat Analysis Services, Jamila Boutemeur, who is one of the authors of the 2026 ENISA Threat Landscape.
L
3:13LauraHOST
Jamila specializes in state-aligned activities.
COREDUMP #024: Shipping Firmware Under the CRA: Nicolas Schieli on the Questions Everyone’s Asking, and the Ones They Should Be Link:
N
6:19Nicolas SchieliGUEST
it? So basically, in Europe, you have to report to two entities.
N
6:24Nicolas SchieliGUEST
One is ENISA.
N
6:26Nicolas SchieliGUEST
This is the European National Body for Europe, basically, where you need to report those incidents if they are severe or actively exploited.
N
6:34Nicolas SchieliGUEST
And the second one is for your local country, where there's a C-cert that is another local body that actually is the national body.
MediaTek is using TSMC's cutting edge 2nm process for its latest chip — 2026-09-15
S
0:20speaker_0NARRATOR
AWS struggles to restore its Bahrain region and a UAE zone six months after drone strikes.
S
0:27speaker_0NARRATOR
ENISA uses an OpenAI model to uncover vulnerabilities in EU code.
S
0:33speaker_0NARRATOR
And finally, we explore the intersection of API and AI gateways in governance and execution.
S
0:40speaker_0NARRATOR
Coming up, MediaTek's leap into the two nanometer chip race with TSMC's technology.
S
3:51speaker_0NARRATOR
This situation serves as a stark reminder of the potential risks associated with cloud dependency, especially in conflict-prone regions.
S
3:59speaker_0NARRATOR
As businesses increasingly rely on cloud services, the need for robust disaster recovery plans becomes more critical.
S
4:07speaker_0NARRATOR
ENISA used an open AI model to find four flaws in EU code, Politico reports.
S
4:13speaker_0NARRATOR
The European Union Cybersecurity Agency, ENISA, has successfully used an open AI model to identify four vulnerabilities in EU project code.
8 more episodes mention The European Union Agency for Cybersecurity.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.