TY - JOUR
T1 - The regulatory framework for the protection of critical infrastructures against cyberthreats
T2 - Identifying shortcomings and addressing future challenges: The case of the health sector in particular
AU - Markopoulou, Dimitra
AU - Papakonstantinou, Vagelis
PY - 2021/7
Y1 - 2021/7
N2 - The concept of “Critical Infrastructures” is constantly evolving in order to reflect current concerns and to respond to new challenges, especially in terms of (cyber)security and resilience. Protection of critical infrastructures against numerous threats has therefore developed into a high priority at national and EU level. During the last two decades a new type of threat has prevailed in the Critical Infrastructure threat landscape, that of cyberattacks; Protection against them is the primary focus of this paper. In order to do so the analysis first aims to drop some light into the differences between Critical Infrastructures and Critical Information Infrastructures, terms that are often confused, and to indicate possible inadequacies in the applicable protection regulatory regime. Finally, the health sector has been chosen as a sector-specific case in an effort to demonstrate how protection of a Critical Infrastructure, challenged as it has been with a constantly increasing number of cyber incidents, could be sufficiently protected in the new digitalised era.
AB - The concept of “Critical Infrastructures” is constantly evolving in order to reflect current concerns and to respond to new challenges, especially in terms of (cyber)security and resilience. Protection of critical infrastructures against numerous threats has therefore developed into a high priority at national and EU level. During the last two decades a new type of threat has prevailed in the Critical Infrastructure threat landscape, that of cyberattacks; Protection against them is the primary focus of this paper. In order to do so the analysis first aims to drop some light into the differences between Critical Infrastructures and Critical Information Infrastructures, terms that are often confused, and to indicate possible inadequacies in the applicable protection regulatory regime. Finally, the health sector has been chosen as a sector-specific case in an effort to demonstrate how protection of a Critical Infrastructure, challenged as it has been with a constantly increasing number of cyber incidents, could be sufficiently protected in the new digitalised era.
UR - https://www.sciencedirect.com/science/article/pii/S0267364920301072#coi0001
UR - http://www.scopus.com/inward/record.url?scp=85102790513&partnerID=8YFLogxK
U2 - 10.1016/j.clsr.2020.105502
DO - 10.1016/j.clsr.2020.105502
M3 - Article
VL - 41
JO - Computer Law & Security Review
JF - Computer Law & Security Review
SN - 0267-3649
M1 - 105502
ER -