Getting Critical: Making Sense of the EU Cybersecurity Framework for Cloud Providers
Ian Walden, Johan David Michels

TL;DR
This paper analyzes the EU cybersecurity regulations affecting cloud providers, highlighting regulatory complexities, compliance challenges, and the implications of recent and proposed frameworks for cloud service security and oversight.
Contribution
It provides a comprehensive review of EU cybersecurity regulations for cloud providers, examining their impact, challenges, and the potential effects of regulatory divergence and new assurance mechanisms.
Findings
Cloud providers face complex, divergent regulations from GDPR and NISD.
Regulatory compliance costs are high due to multiple overlapping requirements.
Proposed revisions and voluntary schemes aim to improve security but may add complexity.
Abstract
In this chapter, we review how the EU cybersecurity regulatory framework impacts providers of cloud computing services. We examine the evolving regulatory treatment of cloud services as an enabler of the EU's digital economy and question whether all cloud services should be treated as critical infrastructure. Further, we look at how the safeguarding and incident notification obligations under the General Data Protection Regulation ('GDPR') and the Network and Information Systems Directive ('NISD') apply to cloud providers. We also consider the proposed revision of the NISD and look at newly developed voluntary assurance mechanisms for cloud providers, including codes of conduct and certification schemes. We conclude that, since cloud providers are typically subject to both NISD and GDPR and to the jurisdiction of multiple regulators, they face divergent regulatory approaches, which can…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCybersecurity and Cyber Warfare Studies · Legal and Policy Issues · Blockchain Technology Applications and Security
