Ice Cream, Christmas Lights, and Gum Join EU ‘Critical’ List

How gum wholesalers, ice cream makers, and holiday light manufacturers could fall under EU cybersecurity rules for critical infrastructure

Ice cream makers and Christmas light manufacturers, along with property owners and gum wholesalers, are likely to be classified as “critical infrastructure” for cybersecurity purposes and receive EU protection against cyberattacks.

Technology and cybersecurity lawyers told Politico that these unlikely sectors are on track to be labeled “critical infrastructure” under an EU cybersecurity law designed to protect targets like power plants, water facilities, and energy grids.

It’s the latest hurdle for the European Union’s NIS2 Directive, which was originally passed in 2022 but is still being rolled out by EU countries.

A Bureaucratic Nightmare

Clarity on how resources are allocated to protect infrastructure is more urgent than ever, as Europe faces an unprecedented wave of cyberattacks that use artificial intelligence and increasingly hybrid attack methods.

Governments were supposed to have their own legislation in place by the end of 2024, but delays have left many companies only now starting the process of preparing to comply.

Operators in the EU’s most critical sectors are now required to register with their national cybersecurity agencies, meaning they need to understand exactly who the law applies to.

The odd cases are a sign of a real puzzle that companies and their legal advisers have to solve, and an extra piece of red tape at a time when the EU is working hard to cut back on bureaucracy.

It’s also another example of the difficulties the EU has faced in getting NIS2 up and running. Countries like France and Spain still haven’t passed matching national cybersecurity laws, and company registrations have been notably slow in Germany.

A European Commission official stressed that the law includes “several mechanisms” to keep things fair, including rules that generally exempt small businesses and lighter obligations for less critical organizations.

Food for Thought

Here are some unexpected sectors that, according to the letter of the law, could be considered critical infrastructure.

The NIS2 directive covers food production, processing, and distribution, a fairly logical inclusion, since a cyberattack that cripples the supply chain for what we eat threatens the entire population.

However, this inclusion has had some unexpected consequences.

Markéta Gregorová, a Czech member of the European Parliament who is leading work on a separate cybersecurity package aimed at simplifying the NIS2 law, has publicly questioned how the directive is being applied.

At a recent conference, she noted that ice cream manufacturers, if large enough, could be subject to the law. “You probably wouldn’t need them in a crisis,” she said.

The food sector looks especially complicated under the legislation. Gum wholesalers above a certain size fall within its scope, said Andreas Daum, a partner at the law firm Noerr. A German trade association has already reassured its members that artisan bakeries are not covered by the law.

Hack the Ornament

The maker of Christmas lights could be classified as an NIS2 sector, putting it in the same category as postal services and chemical manufacturing.

That’s because “manufacturing of Christmas tree lighting sets” falls under the relevant economic activity classification referenced in the NIS2 directive, said Jurriaan Jansen, a partner at the law firm Norton Rose in Amsterdam.

Although the wording of the legislation labels Christmas lights as “important,” they don’t meet the threshold of being “essential” under Dutch NIS2 law, Jansen said, because a disruption in the sector wouldn’t pose a risk to public safety or a systemic risk. “That would be an unusual outcome for this sector,” he said.

Schools and Property Owners

Experts also raised the possibility that some organizations could accidentally become operators of critical infrastructure in sectors completely unrelated to what they actually do.

A Belgian member of the European Parliament said last year that large schools with solar panel installations are “formally classified as ‘producers’ of electricity,” meaning they fall within the scope of the legislation, imposing “significant costs on institutions that often lack in-house cybersecurity expertise.”

The Commission, in its response to the lawmaker, didn’t deny that schools could be affected, but said its digital package and the review of the EU Cybersecurity Act would help simplify the rules.

Similarly, property owners in Germany who rent out large numbers of apartments and pass cable or internet service on to their tenants through service charges can be classified as telecom providers, following a 2021 ruling, though this depends on the specific circumstances.

“It’s possible, but it depends on how the lease is structured,” said Daum of the law firm Noerr. Whether that in turn brings them under the new cybersecurity rules hasn’t been tested. “There’s no case law on this, and no guidance from any [relevant] regulator,” he said.

Follow tovima.com on Google News to keep up with the latest stories
Exit mobile version