DIRECTORY

  • Alerts
  • APTs
  • Blog
  • Books
  • Certifications
  • Cheat Sheets
  • Courses
  • Cyber Briefing
  • CyberDecoded
  • CyberReview
  • CyberStory
  • CyberTips
  • Definitions
  • Domains
  • Entertainment
  • FAQ
  • Frameworks
  • Hardware Tools
  • Incidents
  • Malware
  • News
  • Papers
  • Podcasts
  • Quotes
  • Reports
  • Tools
  • Threats
  • Tutorials
No Result
View All Result
  • Login
  • Register
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
Get Help
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
No Result
View All Result
Get Help
CyberMaterial
Home DeFi Protocol

France’s new cyber law prompts confusion

Reading Time: 2 mins read
in News

 

A new French law mandating companies to report cyber incidents to authorities within 72 hours or lose their eligibility for cyber insurance reimbursement has left industry experts confused.

The law, which comes into effect on April 24, aims to cover various cyber incidents, including illegal access to information systems and data deletion, theft, or modification.

Additionally, the law authorizes cyber insurers to cover ransomware payments, with the idea being that the threat of losing insurance coverage will encourage more companies to disclose cyber incidents, thus providing more data for law enforcement and policymakers to counter cyber threats. However, the question remains: report to whom?

French companies have two federal agencies to approach for cyber events: the national information system security agency, or ANSSI, and the French data protection authority, or CNIL.

The law requires companies to report the breach to “competent authorities” and file an impact assessment with police and judicial authorities, according to legal analysis by law firm Orrick.

However, the law doesn’t specify whether there will be a specific mechanism for filing such complaints. Global companies with headquarters in France will have the most uncertainty, as the law will add an extra layer of compliance to organizations with servers in multiple jurisdictions.

Another question raised by the law is the deadline for reporting incidents – within 72 hours of what? Companies are uncertain if they should report 72 hours after their log files show signs of unauthorized access or 72 hours after staff determines it is a security incident.

Jean Bayon de La Tour, managing director and European head of cyber at Marsh McLennan, points out that the vast majority of small and medium-scale enterprises tend not to buy cyber insurance, meaning the law will not incentivize them to report data breaches to the French government.

Read More

Tags: Cyber InsuranceFranceincidentsLawMarch 2023NewsNews 2023Ransomware
ADVERTISEMENT

Related Posts

Microsoft releases Windows 11 update preview

Microsoft releases Windows 11 update preview

March 29, 2023
Nigerian man sentenced for BEC fraud

Nigerian man sentenced for BEC fraud

March 29, 2023
Microsoft launches AI-based Security Copilot

Microsoft launches AI-based Security Copilot

March 29, 2023
Latitude Financial Data Breach

Latitude Financial Data Breach

March 28, 2023

More Articles

Entertainment

Management Cast – Podcasts

February 13, 2023

Password to incorrect…

October 17, 2020
Alerts

HHS Warn of Threats Facing Healthcare Sector

August 30, 2022
Incidents

Bitter APT Hackers Continue to Target Bangladesh Military Entities

July 6, 2022
Alerts

Microsoft Edge (Chromium-based) Security Advisory

October 5, 2021
Alerts

Critical vulnerabilities in remote monitoring software: Netop Vision Pro

March 24, 2021
Course

Ransomware: Identify, Protect, Detect, Recover

October 8, 2022
Incidents

Smart Contract Auditing Firm Suffers Smart Contract Exploit

September 6, 2022
Load More

Security through data

Cybersecurity Domains

  • API Security
  • Business Continuity
  • Career Development
  • Compliance
  • Cryptography
  • HSM
  • KPIs / KRIs
  • Penetration Testing
  • Shift Left
  • Vulnerability Scan

Emerging Technologies

  • 5G
  • Artificial Intelligence
  • Blockchain
  • Cryptocurrency
  • Deepfake
  • E-Commerce
  • Healthcare
  • IoT
  • Quantum Computing

Frameworks

  • CIS Controls
  • CCPA
  • GDPR
  • NIST
  • 23 NYCRR 500
  • HIPAA

Repository

  • Books
  • Certifications
  • Definitions
  • Documents
  • Entertainment
  • Quotes
  • Reports

Threats

  • APTs
  • DDoS
  • Insider Threat
  • Malware
  • Phishing
  • Ransomware
  • Social Engineering

© 2023 | CyberMaterial | All rights reserved.

World’s #1 Cybersecurity Repository

  • About
  • Legal and Privacy Policy
  • Site Map
No Result
View All Result
  • Audience
    • Cyber Citizens
    • Cyber Professionals
    • Institutions
  • Highlights
    • Blog
    • CyberDecoded
    • Cyber Review
    • CyberStory
    • CyberTips
  • Cyber Risks
    • Alerts
    • Attackers
    • Domains
    • Incidents
    • Threats
  • Opportunities
    • Events
    • Jobs
  • Repository
    • Books
    • Certifications
    • Cheat Sheets
    • Courses
    • Definitions
    • Frameworks
    • Games
    • Hardware Tools
    • Memes
    • Movies
    • Papers
    • Podcasts
    • Quotes
    • Reports
  • Report Cyber Incident
  • GET HELP

Subscribe to our newsletter

© 2022 Cybermaterial - Security Through Data .

Welcome Back!

Sign In with Google
Sign In with Linked In
OR

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
Sign Up with Linked In
OR

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.