EU cybersecurity gets a boost with new partnership
Vulnerability disclosure for Europe’s critical infrastructure is being strengthened with a new agreement between the ENCS and DIVD.

The MoU between the European Network for Cyber Security (ENCS) and the Dutch Institute for Vulnerability Disclosure (DIVD) aims to strengthen cooperation on vulnerability discovery, disclosure and resolution affecting Europe’s power grids and other critical infrastructure.
The agreement establishes a framework for collaboration between the two non-profit organisations, combining ENCS’ security testing expertise with DIVD’s experience in coordinated vulnerability disclosure and common vulnerabilities and exposures registration.
“Strengthening Europe’s cyber resilience requires close cooperation across the cybersecurity ecosystem,” commented Anjos Nijk, Managing Director of ENCS.
“This agreement enhances our ability to identify and resolve vulnerabilities affecting critical infrastructure, while reinforcing responsible disclosure practices that help reduce risk for grid operators and other essential service providers.”
Alongside the signing of the MoU, the ENCS launched its high-power IoT security testing programme.
Vulnerabilities identified by ENCS security testers will be coordinated through DIVD’s disclosure and common vulnerabilities and exposures processes. ENCS security experts will also participate in DIVD testing activities and events.
Chris van ’t Hof, Director of DIVD, added: “Effective vulnerability disclosure depends on trust, coordination and technical expertise. By working with ENCS and its community of security specialists and infrastructure stakeholders, we can help ensure vulnerabilities in high-impact systems are handled efficiently and responsibly.”
The MoU signing took place at the ENCS general assembly, at which members also appointed Wolfgang Löw, CISO of the Austrian EVN energy group, as chair of the ENCS assembly committee. This committee supervises operations and supports the management.
EU cybersecurity
The MoU comes as the European Commission has set out proposals for a new cybersecurity package, including a revision of the cybersecurity act focussed on bolstering the security of ICT supply chains.
The stated aim is to enable the EU to address the increasingly sophisticated cyber attacks that can disrupt critical sectors such as energy and water, among others.
Regarding supply chains, the proposal is to introduce targeted mitigation measures, including the prohibition of the use of ICT components from high-risk suppliers in key ICT assets.
Also of interest
Renewable energy’s hidden risk: Cybersecurity gaps we can’t ignore
Other proposals include simplifying the cybersecurity certification framework to ensure ‘security by design’ and simplifying the guidelines for compliance with EU cybersecurity regulations and risk management standards.
Notable for the energy sector are amendments to the NIS2 directive, including streamlining the collection of data on ransomware attacks and facilitating the supervision of cross-border entities with ENISA, which is also given a strengthened support role in anticipating, preventing, managing and responding to cyber incidents.
Another significant amendment is the requirement for member states to adopt policies for the migration to post-quantum cryptography as part of their national cybersecurity strategy.
While the quantum threat is largely an emerging one, the goal is to ensure preparedness with some degree of urgency.
Under EU policy, migration to post-quantum cryptography is required for critical use cases – such as grid security – by 2030 and for medium and low-level use cases by 2035.
Latest content
US DOE $10m grant to support nation’s first regional cybersecurity center for grids
The center will bring together experts from the private sector, acadThe cybersecurity centre will bring together private sector, academia and government to and attempt solutions to protect the grid.emia and government to share information and attempt solutions to protect the nation’s power grid and other key sectors. It will include a mock utility command center to train participants in real-time cyber defense.
- Smart Energy International
- 24/04/2024








