We’re also due for a legislation roundup.
Last week, the European Parliament approved two new laws — the Digital Markets Act (DMA) and the Digital Services Act (DSA). The DMA focuses on digital service gatekeepers who break the rules on promoting competition. At the same time, the DSA puts more responsibility on large platforms to police and take down illegal content, with fines if they fail to comply. Tech giants won’t be allowed to give their own products, apps, or services preferential treatment within the EU. Companies will have to get consumer consent before moving the personal data of EU citizens around. Companies face a fine of up to 10% of annual global turnover for violations of the DMA and 6% of breaches of the DSA.
A warning from the UK’s cybersecurity agency to attorneys there – don’t advise clients to pay ransoms hoping to reduce data breach penalties. Also noted – A Hartford unit told an Ohio federal Court that an IT company can’t get coverage for costs incurred when it was forced to transfer customer data to new servers.
And FYI, the investigation of the SolarWinds hack doesn’t quite appear to be done — the vice chairman of the House Homeland Security Committee introduced a bill this week that would task the Cybersecurity and Infrastructure Security Agency with a report, in consultation with the Office of the National Cyber Director, detailing the impact of the SolarWinds hack on federal information systems, federal agencies and other critical infrastructure.
And that’s not the only possible item to come. There’s the possibility of a statistics group within CISA, codification of “systemically important entities” which would be required to enact strong digital security standards, a possible reward program for cybersecurity operations, allowing the Defense secretary and leaders of the service branches to give “honorary recognitions and monetary awards” up to $2,500 for “innovation” in digital operations to military personnel, and finally, an amendment to incorporate existing legislation that would extend the CISA director’s tenure to five years, trying to avoid political hold-ups on the position.
The EU gets things done, that’s for sure. These are laws with teeth, and it seems ever-increasing levels of fierceness. I’m less focused on the EU’s specific laws and more on the willingness TO regulate, which is what matters. Will they lead the way for US lawmakers? Maybe – if only from a security perspective- as clearly new regulations are coming. Privacy maybe not, but security… yes.
Also, note that the items are happening in Court cases. Paying ransoms will become less viable, and I’d expect to see continued regulation via insurance precedent too.

