News: 1683809048

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

ENISA leans into EU-based clouds with draft cybersecurity label

(2023/05/11)


Cloud services providers that aren't based in Europe — like the Big Three — may have to team up with a cloud that is operated and maintained from the EU if they want ENISA's stamp of approval for handling sensitive data.

ENISA, the European Union's cybersecurity agency, is currently developing a [1]cybersecurity certification scheme that aims to better protect member-state governments' and businesses' data. This reportedly includes a new proposal that would require any non-European cloud providers to form a joint-venture with an EU-based provider if they want to earn a coveted ENISA cybersecurity label.

According to a draft of the new rules [2]seen by Reuters , US cloud giants like Amazon, Microsoft and Google — or any other non-EU provider — can only have a minority stake in the joint venture. Additionally, any employees with access to EU data would be required to reside in one of the 27 member countries, and undergo specific screening to handle EU data.

[3]

The majority company in the cloudy JV must be operated and maintained from the EU, all customer data must be stored and processed in the EU, and, unsurprisingly, EU laws take precedence over other countries' regulations, according to the draft proposal.

[4]

[5]

ENISA has't yet responded to The Register 's request to see the proposal, but according to Reuters, it specifically says:

Certified cloud services are operated only by companies based in the EU, with no entity from outside the EU having effective control over the CSP (cloud service provider), to mitigate the risk of non-EU interfering powers undermining EU regulations, norms and values.

Member countries will review the proposal later this month, and the regulations must be approved by the European Commission before they go into effect.

As of the first quarter of 2023, US-based companies dominate the European cloud infrastructure services market, with Amazon Web Services controlling 34 percent, Microsoft Azure coming in second with 26 percent, Google in third place with 13 percent, and IBM holding on to 3 percent, according to Synergy Research Group.

"The highest-ranked European companies in Q1 were SAP (ranked No. 7) and Deutsche Telekom (No. 8), both with a 2 percent share. No other European company had a share of 2 percent," John Dinsdale, chief analyst and research director at Synergy Research Group, told The Register .

[6]US lobbyists commission report dismissing proposed EU cloud regulations

[7]US commerce bosses view EU rules as threat to its clouds

[8]EU proposes spyware Tech Lab to keep Big Brother governments in check

[9]Microsoft floats Cloud for Sovereignty

Microsoft declined to comment on the EU proposal, while Amazon and Google didn't respond to The Register 's inquiries.

The US Chamber of Commerce has [10]previously opposed adding these types of sovereignty requirements to the EU cybersecurity certification scheme. "This may ultimately lead to the very real threat of practically excluding American and other international cloud providers from the EU market," the American business lobbying group [11]warned .

[12]

Additionally, in a [13]joint statement on the European Cybersecurity Certification Scheme for Cloud Services, the US Chamber and a dozen other international organizations urged EU countries "to refrain from adopting requirements of a political – rather than technical – nature, which would exclude legitimate cloud suppliers and would not enhance effective cybersecurity controls." ®

Get our [14]Tech Resources



[1] https://www.enisa.europa.eu/topics/certification

[2] https://www.reuters.com/technology/eu-draft-rules-propose-tougher-cybersecurity-labelling-rules-amazon-google-2023-05-09/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZF0RIIWdgGLLBAL5pUAYQgAAAI0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZF0RIIWdgGLLBAL5pUAYQgAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZF0RIIWdgGLLBAL5pUAYQgAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/03/06/proposed_eu_cloud_regulation/

[7] https://www.theregister.com/2022/12/02/us_eu_cloud_regulation/

[8] https://www.theregister.com/2023/05/09/pega_commitee_report/

[9] https://www.theregister.com/2022/07/20/microsoft_cloud_for_sovereignty/

[10] https://www.theregister.com/2022/12/02/us_eu_cloud_regulation/

[11] https://www.uschamber.com/security/cybersecurity/issue-briefing-the-european-unions-proposed-cybersecurity-certification-scheme-for-cloud-services-eucs

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZF0RIIWdgGLLBAL5pUAYQgAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.uschamber.com/security/coalition-joint-industry-statement-on-european-cybersecurity-certification-scheme-for-cloud-services-eucs

[14] https://whitepapers.theregister.com/



OhForF'

"practically excluding American and other international cloud providers from the EU market"

is not a problem and might even be seen as a positive side effect if your job is to promote european interests.

Not allowing foreign companies access to sensitive data is at least as good an argument to ban foreign providers as alleged security issues in 5G kit is to ban Huawei from the US market.

ParlezVousFranglais

Simple protectionism which the eurocrats will love themselves for:

Step 1: create a certification that the big 3 will never agree to

Step 2: mandate that all EU governments and institutions have to use a provider with said certification

Step 3: realise that you can now only use SAP and their prices are 3 times as much as you were paying before...

Lars

@ParlezVousFranglais

Wrong, the big 3 will have to agree to it, and they will.

ParlezVousFranglais

I think that's what the EU is probably hoping, but all they are going to do is mandate themselves into paying a shedload more money for a lesser product

Let's assume I'm Amazon and I provide "cloud". My intellectual property, what defines "my" cloud and makes it better (or worse) than MS or Google is how I create and manage my cloud, the tools, the processes, the procurement etc

Now I'm told I can only provide "my" cloud, if I actually agree to give away all that IP to a third-party that I'm only allowed a minority stake in - a huge risk given that this is exactly how countless technology firms have had their fingers seriously burned when trying to operate in China

The only possible way to do that is to retain a minority stake and license my IP to the other cloud provider at an extortionate rate. Now there are two "Amazons", my own native product un-certified, and a new certified product running exactly the same tech (or maybe a "lite" version), just with a badge that says it's somehow more secure and for three times the price.

However, in exactly the same way as it has done for other areas of technology and defence, all this takes to unravel is a US edict forbidding any of the three to license their cloud IP to overseas third-party providers on the grounds of US national security - in fact right now they are probably actively lobbying the US behind the scenes to do exactly this.

So with that, yes you might get your "ringfenced" EU cloud, working in exactly the same way but for a ton more money, and very probably in some kind of "cloud-lite" mode.

So the EU governments and probably their various procurement teams will be mandated to use it, and all it will achieve is to cost them more. As we've seen with several high profile leaks from the US, you can have all the vetting you like, all the firewalls and security you like, and be sitting wherever you are instructed to sit, but if you want to leak info, you're gonna do it anyway, regardless of whether your platform has a pretty little logo attributed to it, and any "backdoors" hidden away in the system are going to be duplicated into the system you are licensing anyway. The EU majority owner of the JV won't actually develop anything in house as they will have to license in the whole platform, and those license fees will be fed back to the US companies anyway, thereby making them even richer than if said EU governments just licensed their normal product, and the majority owner will effectively be nothing more than a reseller

Pure protectionism, the eurocrats will claim a victory, and one way or another the EU's citizens will pay way over the odds for a what will very likely be only a marginal increase in "security".

I never met a piece of chocolate I didn't like.