Urgent.News

What's breaking now, across thousands of outlets.

Tech

EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank

RUSI wants procurement rethink that could put US suppliers under scrutiny too

EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank

The Royal United Services Institute (RUSI) has warned that European Union (EU) members may face security risks through their reliance on Chinese technology for infrastructure. In a report, the UK-based think tank suggested that the EU needs to develop a new risk assessment framework for all members to safeguard the bloc better. RUSI emphasized the need to balance the need to secure the union while maintaining flexibility for members to set their domestic policies and lawmakers to account for different risk profiles across various sectors.

The EU currently has a voluntary EU Toolbox for 5G Security framework, which only 10 of the 27 members have fully implemented since its launch in January 2020. The European Commission proposed amendments to the Cyber Security Act (CSA) earlier this year to create a list of untrusted vendors that must be excluded from critical sectors' networks.

However, before the EU can create a high-risk vendor designation system, it first needs to define what constitutes a high-risk vendor, as there is no official definition, nor is it a legal category at present.

RUSI provided examples of how Germany, Spain, and the UK treat foreign tech vendors, such as Huawei and ZTE, very differently. While Germany, which is China's most important trading partner, opts to preserve economic ties despite the risks, Spain often favors cost-effective options and does not share the same national security concerns about China as the UK or US. Meanwhile, the UK is set to completely remove Chinese technology from its telecoms network by the end of next year.

RUSI stated that concerns about Chinese IT vendors "are well-founded" due to the Chinese government's ability to exercise control over companies like Huawei, such as providing data on demand, hosting CCP representatives, and reporting activities that signal a threat to national security. Moreover, China's willingness to launch cyberattacks against critical national infrastructure of political adversaries further highlights the security risks associated with relying on Chinese vendors.

However, RUSI cautioned that blanket bans on China or specific countries may not address the underlying security issues that make products vulnerable to attack.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 2 other outlets

Read the original at theregister.com →

More in Tech

More from Thursday 1 October →