Urgent.News

What's breaking now, across thousands of outlets.

Science

EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank

RUSI wants procurement rethink that could put US suppliers under scrutiny too

EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank

A Royal United Services Institute (RUSI) report suggests that depending on Chinese technology for European infrastructure poses significant risks that not all member countries take seriously. The think tank recommends the EU develop a new risk assessment framework applicable to all member states, while preserving their right to set national security policies.

Currently, only 10 of the 27 EU members have fully implemented the voluntary EU Toolbox for 5G security, which aims to mitigate security risks associated with 5G technology. The European Commission has proposed amendments to the Cyber Security Act (CSA) that would allow it to create a list of untrusted vendors and force precluded vendors out of the networks of 18 critical sectors within 36 months.

However, before implementing such a system, the EU must first define what constitutes a high-risk vendor and decide on appropriate measures. The report highlights that Germany, Spain, and the UK treat foreign tech vendors, such as Huawei and ZTE, differently due to varying national security concerns and economic ties. Germany's significant trade relationship with China, worth €251.8 billion ($284.4 billion) annually, leads to a slower shift away from Chinese tech, while Spain and the UK have taken more aggressive stances, with the latter aiming to eliminate Chinese technology from its telecoms network by the end of next year.

RUSI states that concerns about Chinese IT vendors are well-founded, as the Chinese government can exert control over companies like Huawei, demanding data, hosting CCP representatives, and reporting potentially sensitive information. The report also notes that China has demonstrated its willingness to launch cyberattacks against critical national infrastructure of political adversaries.

Technical security aside, China's technological advancements and lower prices introduce economic risks for EU and US members reliant on Chinese vendors. RUSI argues that a high-risk designation system may not effectively address security issues if alternative vendors from trusted countries similarly fail to deliver secure software.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Science

More from Thursday 1 October →