Brian Sims
Editor
Brian Sims
Editor
EURALARM – THE European Trade Association – and the Confederation of European Security Services (representing the European private security services industry) have jointly published an updated edition of the Cyber Security Guidelines for the Security and Fire Safety Industry.
The revised publication provides practical guidance for organisations across these vital sectors as cyber security becomes an increasingly important operational, technical and regulatory requirement.
The growing connectivity of security and fire safety systems realises significant benefits, including remote monitoring and maintenance, faster access to information and greater integration between systems. At the same time, connectivity introduces cyber security risks that need to be addressed throughout the complete lifecycle of given systems and services.
That being so, the updated guidelines take a broad approach to cyber security. They’re intended for organisations involved in product development, system design, installation and maintenance, monitoring and those businesses delivering alarm response services.
Importantly, the publication combines organisational recommendations with practical technical measures and guidance for working with customers and other partners in the security chain.
Changing regulatory environment
An important reason for updating the publication is the rapidly developing regulatory framework underpinning European cyber security. The new edition provides an overview of legislation relevant to the fire safety and security sector, including the NIS2 Directive and the Cyber Resilience Act.
The updated guidelines also address other relevant European legislation, including the European Union Cyber Security Act, the General Data Protection Regulation, the Radio Equipment Directive and the AI Act.
Rather than treating cyber security solely as a product-focused or IT-centred issue, the updated publication considers risks and responsibilities throughout the security and fire safety value chain. One central element is a five-pillar lifecycle approach covering products, project design, installation and maintenance, monitoring and alarm response. For each stage, the guidelines identify relevant risks and provide practical recommendations for reducing them.
Human and organisational dimensions
The updated guidelines also emphasise the human and organisational dimensions of cyber security. Companies are encouraged to establish clear cyber security governance, define responsibilities, maintain inventories of connected IT and operational technology assets, conduct regular risk assessments and put business continuity and incident response procedures in place.
Training and awareness are equally important. Recommendations include cyber security training for management, compliance, procurement and technical personnel, as well as ongoing awareness programmes targeting employees.
Further, the updated guidelines underline the importance of co-operation between customers, suppliers and service providers so that cyber security responsibilities are maintained throughout the lifetime of a given system or service.
In order to support today’s organisations in implementing these measures, the publication includes references to relevant cyber security standards and elements of work in progress.
*Copies of the updated ‘Cyber Security Guidelines for the Security and Fire Safety Industry’ can be downloaded online by visiting www.euralarm.org
Western Business Media Limited
Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM