Athens, 21 January 2025
The EU Agency for Cybersecurity, ENISA welcomes the EU Action Plan for the cybersecurity of hospitals and healthcare providers proposed on 15 January.
ENISA welcomes the initiative and remains committed to collaborating with the European Commission, the Member States, healthcare providers and the cybersecurity community to strengthen the sector’s digital infrastructure and ensure its resilience to cyber threats. This plan is a key priority, in line with the commitment set out by President Von der Leyen’s political guidelines for the new Commission’s mandate for 2024-2029. Several specific actions are foreseen to be implemented progressively in 2025-2026, in collaboration with the Member States, healthcare providers, and the cybersecurity community.
Particularly, it is proposed for ENISA to establish a pan-European Cybersecurity Support Centre for hospitals and healthcare providers, designed to provide them with tailored guidance, tools, services and training. Among others, the proposed tasks include the development of guidance for cybersecurity good practices and procurement, the development of a regulatory mapping tool, the establishment of EU capabilities for detecting cyber threats against the health sector, to introduce an early warning service for the sector, the development of cyber incident response playbooks.
Building on the existing legislative framework for cybersecurity (NIS2, Cybersecurity Act, Cyber Resilience Act, Cyber Solidarity Act), the actions proposed correspond to the current ENISA mandate to help the EU Member States increase the resilience of their critical sectors, while acknowledging that Member States represent different needs. To achieve the goals set out by the Action Plan, a joint effort is needed and adequate resources are required to fulfil the new actions.
- Commission unveils action plan to protect the health sector from cyberattacks | Shaping Europe’s digital future
- Prioritising eHealth cybersecurity against emerging challenges | ENISA
- Health Threat Landscape | ENISA
- Procurement Guidelines for Cybersecurity in Hospitals | ENISA
- CSIRT Capabilities in Healthcare Sector | ENISA
Source – ENISA