Danish Ports
Member login

About Danish Ports

That's what we think

Ports in numbers

Facts, statistics and figures about cargo turnover and calls in Danish commercial ports.

What's new

Member of Danish Ports

Contact us

Our team of dedicated employees are passionate about networking, service and development.

About Danish Ports

Our members

Bylaws

Board of Directors

Forums and networks

News from Danish Ports

Danish Ports in the media

Industry news

Arrangements

Consultation response

Publications

Press contact

Member benefits

Become a member

About Danish Ports

Our members

Bylaws

Board of Directors

Forums and networks

That's what we think Ports in numbers

News from Danish Ports

Danish Ports in the media

Industry news

Arrangements

Consultation response

Publications

Press contact

Member benefits

Become a member

Contact us

Audible response

Feedback from Danish Ports on the ESPO circular: C-3290 Security- Resilience: the Resilience of critical entities Directive, the NIS 2 Directive

February 3, 2021

Danish Ports association supports that the efforts against cybercrime should be aligned and strengthened to ensure important infrastructure. However, we have some general comments on the proposal:

It is important that the obligations that entities (in this case ports) get from the directive are proportional with the threat from cybercrime. This is both according to cost and administrative burden to the ports. It is important, that a cybersecurity assessment is carried out before a port is subject to all the measures in the directive. Often it is not the port as such that operates all the critical infrastructure in the port, eg container terminals and ferry terminals and therefore not the port that should be the subject of the measures .

Danish Ports can see that the proposal will entail large extra costs to implement and maintain. Against this background, we propose that there is an opportunity for financial support for the companies / ports that are covered by the requirements.

The proposal states that smaller companies (less than 50 employees) are not covered by the requirements for cyber security. However, it is uncertain whether this also applies to ports. The directive refers to ports as defined in the security directive, which covers virtually all Danish commercial ports - also very small ones. Danish Ports therefore wants to ensure that the size of the ports is also taken into account.

Danish Ports proposes that the evaluation of whether a port should be subject to the rules in the directive is done on an individual basis and by the competent national authority. The national authority should make a specific risk assessment of each port and on this basis decide whether it should be covered by the cyber security requirements for critical infrastructure in the

www.danskehavne.dk

26-01-2021

directive. It must also be specified which parts of the port (systems, etc.) are in that case considered critical infrastructure.

Friendly regards

Kasper Ullum, Danish Ports

ku@danskehavne.dk

Danish-Port-response-on-C3290-CypersecurityDownload Danish-Port-responses-on-C3290-Cypersecurity

Footer

Sign up for our newsletter

Follow the most important news in the Danish port industry.

Check your inbox or spam folder to confirm your subscription.

LinkedIn Twitter

2022 Danish Ports.
CVR: 14582428

  • Dansk