• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CommentaryCybersecurity

How Companies Should Prepare For Europe’s New Cybersecurity Rules

By
Peter J. Beshar
Peter J. Beshar
Down Arrow Button Icon
By
Peter J. Beshar
Peter J. Beshar
Down Arrow Button Icon
August 3, 2016, 1:00 AM ET
European union and hacking, illustration
European union map showing the threat of hacking, illustration.ANDRZEJ WOJCICKI — Getty Images/Science Photo Library RF

Peter J. Beshar is executive vice president and general counsel of Marsh & McLennan.

Cyber breaches have dominated the headlines in the United States, with public companies, government agencies, universities, and now even political parties reporting attacks. No sector has been spared. Gazing across the Atlantic, however, the landscape appears dramatically and blissfully different. Virtually no large European company has publicly acknowledged a cyber breach. Is there an Iron Dome or magnetic force field protecting Europe against cyber attacks?

Sadly not. Cyber attacks are occurring across Europe every day. The fundamental difference is that the U.S. has 47 state laws mandating the public disclosure of cyber attacks. Up until now, Europe did not. One possible consequence is that the time lag between a cyber intrusion and the detection of that incident is nearly three times longer in Europe than the rest of the world.

That will change — and the ramifications for European companies will be profound.

After years of debate, European authorities recently approved the EU General Data Protection Regulation. For the first time, companies operating in Europe will be required to report cyber breaches to national authorities within 72 hours and, if there is a significant risk of harm, companies would need to report the breaches to affected individuals. In addition, the regulation directs companies to implement “appropriate technical and organizational measures to ensure a level of security appropriate to the risk.” Companies that fail to adhere to these requirements will be subject to penalties of up to 4% of total revenues, as well as private lawsuits by individuals.

While formal implementation of the EU General Data Protection Regulation is two years away, we now have a window into what European companies can expect. Last year, the Dutch authorities adopted a “mini-GDPR” that imposes an obligation on companies operating in the Netherlands to report cyber incidents to the authorities. The fines for failure to do so can range up to 10% of a company’s revenues. In just the first 130 days since the law took effect at the start of this year, more than 1,500 cyber incidents were reported. Additionally, a 2015 study by PwC reported that 90% of large UK-based businesses – and 74% of small businesses – reported being hacked in the previous year.

Once these incidents are subject to public reporting, rather than whispers, public awareness and concern in Europe will increase markedly. If headlines are filled with reports of cyber breaches, supervisory boards of companies across the continent will press their management teams for assurance that proper attention and adequate resources are being allocated to confront this dynamic risk. Policymakers and data protection authorities will closely monitor these developments, particularly when attacks are directed at critical infrastructure.

The best risk mitigation strategy, of course, is preparation. European companies should be conducting comprehensive assessments of their IT security practices and benchmarking their performance against an established industry standard. In developing a plan of action, four key points should be considered.

First, cyber security is not an IT problem.

One of the lessons from the U.S. is that treating cyber risks as solely an IT issue will not work. The most senior members of a management team, including the CEO, CFO and GC, alongside the board of directors, need to be conversant with the principal threats facing their companies and the strategies for mitigating those threats. Too many companies continue to segregate their cyber security strategy within the walls of their IT departments. This must change.

Second, keep current with the most rampant types of attacks.

Though there are many forms and vectors of attack, “spearphishing” tops the list. Hackers send bespoke e-mails with details lifted from an employee’s Facebook page or forward “spoof” job listings from LinkedIn. Once an employee clicks on the attachment or link, malware is loaded on to the company’s system. Not surprisingly, more than 90% of successful cyber attacks begin with phishing campaigns. While there is no simple fix, technology in the form of detonation software that scans and then explodes malware in a quarantined environment, regular training of employees and sound software patch management protocols are crucial.

Third, build relationships with security, law enforcement and data protection authorities.

Trying to solve this issue alone will not work for either the government or industry. We are in this together. Collaboration with law enforcement is particularly important for operators of critical infrastructure — power plants, telecommunications networks, transportation systems, chemical facilities, dams, civilian nuclear plants, and aviation, to name a few. Given the large percentage of critical infrastructure owned and operated by the private sector in the United States, American authorities have worked diligently to forge public-private partnerships to enhance cyber resilience. Replicating this model, the EU just adopted a new Network Information System Directive and a call for a Public-Private Partnership to combat this dynamic risk. Companies should embrace these efforts.

Fourth, assume you will be breached. Not if, but when. Do you have a written incident response plan?

Have you conducted a simulated drill for a cyber attack? Do you have an external and internal communications strategy? The goal is not elimination of the threat, but rather resilience. When a breach takes place, the objective is to be able to maintain the smooth running of your core operations.

Adequate preparation for cyberattacks is complicated, costly, and for many companies, somewhat counterintuitive. But armed with the facts and a clear regulatory roadmap, now is the time to make the necessary investments – and just as important, build the corporate culture – to protect your business and clients.

As cyber attacks grow more sophisticated and cause greater damage to industries and individuals, it will be increasingly difficult to counter this threat unless we learn from each other and incorporate best practices on both sides of the Atlantic.

About the Author
By Peter J. Beshar
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

francis
CommentaryFlorida
Former Miami Mayor Francis Suarez: Why I’m joining Stephen Ross and Ken Griffin in betting big on ambitious business leaders
By Francis SuarezMay 1, 2026
15 hours ago
valerie
CommentaryLayoffs
Tesla’s former HR chief: the AI layoff panic Is built on a false premise—here’s what most workers need to know
By Valerie Capers WorkmanMay 1, 2026
16 hours ago
tamas
CommentaryPolymarket
SEON CEO: Prediction markets can forecast the future. Can they survive their own manipulation problem?
By Tamas KadarMay 1, 2026
19 hours ago
sundar
Commentary250 Years of Innovation
America at 250: immigration and the making of an innovative nation
By Nasser KazeminyMay 1, 2026
21 hours ago
Derek Kilmer
CommentaryEconomics
The U.S. economy is booming — just not where 50 million Americans live
By Derek KilmerMay 1, 2026
21 hours ago
hegseth
CommentaryMilitary
America shot its arsenal empty in 2 wars. Now it needs Beijing’s permission to reload
By Steve H. Hanke and Jeffrey WengApril 30, 2026
2 days ago

Most Popular

Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
Personal Finance
Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
By Fatima Hussein and The Associated PressMay 1, 2026
17 hours ago
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
North America
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
By Jake AngeloApril 30, 2026
1 day ago
The U.S. economy is booming — just not where 50 million Americans live
Commentary
The U.S. economy is booming — just not where 50 million Americans live
By Derek KilmerMay 1, 2026
21 hours ago
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
5 days ago
Accenture's Julie Sweet blew up 50 years of company history. She says the hardest part is still ahead
Conferences
Accenture's Julie Sweet blew up 50 years of company history. She says the hardest part is still ahead
By Nick LichtenbergApril 29, 2026
3 days ago
Current price of oil as of May 1, 2026
Personal Finance
Current price of oil as of May 1, 2026
By Joseph HostetlerMay 1, 2026
17 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.