A laptop, a smart phone, but also a watch, a bracelet, or a home appliance. Smart technologies are not only part of working life. Today they replace wallets or documents. That is why the European Commission has been increasingly focusing in recent years on the highest possible protection of users who share ever-increasing volumes of various types of information in the virtual world.
This does not only affect users as consumers, but also, of course, entrepreneurs who use smart technologies as information databases, marketing tools and payment channels.
According to the European Commission, in 2018, more than 4 thousand ransomware attacks occurred every day, with 8 out of 10 European businesses experiencing a cyber attack. To prevent the information age from bringing an increase in crime and the damage caused by it, the European Union has introduced a system of regulations and directives into the legislation of the Member States, including Slovakia, which serve as a kind of safety net.
For this purpose, the Slovak Republic, among other regulations, transposed the Directive on Network and Information Security (NIS) into the Slovak legal order, and adopted Act No. 69/2018 Coll. on Cybersecurity.
It introduces a number of obligations for operators of essential services and digital service providers to prevent and detect cyber incidents in information systems and networks. It aims to protect information systems and networks from disruptions caused by technical devices, data processed on them or services provided through them, but also to protect customers themselves.
An operator of essential services is considered to be a public authority or a person operating an essential service included in the list of essential services and at the same time which
- depends on networks and information systems and is an activity in at least one sector and subsector according to Annex No. 1 to the Act (e.g. healthcare, banking, transport, energy, etc.)
- is an information system of public administration, or
- is an element of critical infrastructure (i.e. infrastructure whose disruption would have serious adverse consequences for the implementation of the economic and social function of the state, and thus also for the quality of life of the population).
A digital service provider is considered to be a legal entity or a natural person - an entrepreneur who provides a digital service (i.e. an online marketplace, an internet search engine and cloud computing services - IaaS, PaaS, SaaS) and at the same time employs more than 50 employees, achieving an annual turnover or a total annual balance of more than 10 million euros.
In practice, this means several fundamental obligations for operators of essential services, as well as for digital service providers. One could say that it applies de facto to every major player who operates an essential service or provides a digital service.
Every entity that has identified itself as an operator of an essential service or a digital service provider is obliged to notify the National Security Authority (hereinafter referred to as the "NBÚ")
- any exceedance of the identification criteria (number of service users, impact on economic and social interests, market share or geographical expansion) in the case of an operator of an essential service within 30 days from the date on which it discovered the exceedance,
- any exceedance of the identification criteria in the case of a digital service provider within 30 days from the date of commencement of the provision of the digital service.
The primary obligation of both operators and providers is to adopt and comply with security measures to the extent specified in the Cybersecurity Act. Both must implement them within six months of the date of notification of inclusion in the register of operators of essential services and the register of digital service providers.
In this case, the operator of the essential service has an additional obligation, which is obliged to verify the effectiveness of these security measures by conducting a cybersecurity audit, which must be carried out within two years of inclusion in the register of operators of essential services. The final report on the results of the audit must be submitted to the National Security Agency within 30 days of the completion of the audit.
In the event that the operator of the essential service outsources activities directly related to the operation of the service, it is obliged by law to conclude a contract with the supplier to ensure the implementation of security measures and notification obligations, even when concluding a contract with the supplier for the performance of activities directly related to the operation of networks and information systems for the operator of the essential service. The obligation to conclude such a contract also applies to the provider of a digital service if it uses the operator of the essential service to provide it. It follows from this and it should be noted that the law and the obligations arising from it also apply to suppliers who provide services for digital service providers or operators of essential services.
Among other things, the law also brings various notification obligations for operators and providers, such as the obligation to report changes in data, to inform a third party about a reported cybersecurity incident, etc.
The obligations imposed by the Cybersecurity Act are mainly aimed at preventing and detecting cyber security incidents (hereinafter referred to as "CSIs") in networks and information systems. Accordingly, it imposes on operators of essential services and digital service providers the obligation to deal with CSIs, to report any such serious CSIs without delay, to cooperate with the Authority in resolving the incident and to secure evidence for the purposes of criminal proceedings.
For breaching obligations arising from the Cybersecurity Act, operators of essential services and digital service providers face high fines ranging from 1% of the total annual turnover for the previous financial year, up to EUR 300,000. For each breach, the seriousness of the breach (method, duration, consequences) is assessed, and the NBU may impose a fine up to 2 years from the date of detection of the breach of obligations, at the latest up to 4 years from the date on which the obligation imposed by law was breached.
IF you have more questions on the topic of cybersecurity, our team of experienced experts helps you effectively manage and protect your most valuable data across a wide range of cyber threats and scenarios. So do not hesitate to contact us at any time.