This page was translated automatically using artificial intelligence (DeepL). The German version is binding. More information about automatic translation
In today’s digital world, where cyber-attacks are becoming an increasing threat to businesses, public authorities and consumers, cyber security plays a central role. To address the growing challenges posed by digital threats, the European Union has launched two key legislative initiatives: the NIS2 Directive and the Cyber Resilience Act (CRA). Both sets of regulations aim to strengthen cybersecurity in Europe, albeit with different priorities and approaches. Whilst the NIS2 Directive primarily promotes the security of networks and information systems in critical sectors, the CRA places particular emphasis on the security of products containing digital elements, with a view to safeguarding them against cyber threats from the outset.
In early April, a transfer forum for works councils was held at the university on the topic of ‘IT security in the workplace: new EU regulations (NIS2 and CRA) and the role of the works council in the age of data breaches, AI and hacker attacks’.
The event was organised by the ‘PerspektiveArbeit Lausitz’ project and the ‘Transferforum AI and Good Work’ network.
Jochim Selzer (education officer at the German Trade Union Confederation) presented both directives and highlighted their key content, objectives and implications.
NIS2 Directive: Strengthening cyber security for critical infrastructure
The NIS2 Directive, which was adopted in December 2020, builds on the original NIS Directive of 2016 and aims to strengthen cybersecurity in Europe. It extends the requirements for critical infrastructure and digital services and requires Member States to implement stricter security measures and report security incidents more quickly.
One of the key new features of NIS2 is the expansion of the sectors covered. In addition to the sectors previously covered, such as energy, healthcare and transport, digital service providers (e.g. cloud providers, online marketplaces and search engines) are now also subject to stricter obligations. Organisations must not only protect their networks and information systems against threats, but also develop clear measures to detect, prevent and respond to security incidents.
A key element of the NIS2 Directive is the obligation to report security incidents. Should an incident occur, companies must report it to the relevant national authorities within 24 hours. This ensures that incidents are dealt with swiftly and that a coordinated response is guaranteed at European level. Member States must also ensure that their national cybersecurity authorities have sufficient resources to monitor the implementation of the Directive and to promote cooperation at international level.
NIS2 is not yet in force in Germany; implementation of NIS2 is not expected until the second quarter of 2025 at the earliest.
Cyber Resilience Act (CRA): Ensuring the cyber security of products
Unlike NIS2, which focuses on the security of networks and information systems, the Cyber Resilience Act (CRA) is primarily aimed at manufacturers of products containing digital elements. The CRA, which was presented by the European Commission in September 2022, requires manufacturers to ensure that their products are secure and resilient to cyberattacks from the outset. These include products such as software, Internet of Things (IoT) devices and other connected products.
A key aspect of the CRA is that manufacturers of products with digital elements are obliged to meet security-related requirements. These include, amongst other things, carrying out regular security audits and ensuring that products continue to receive regular security updates even after they have been launched on the market. The CRA is designed to ensure that products remain secure throughout their entire lifecycle and can be patched quickly should any security vulnerabilities be discovered.
Furthermore, manufacturers of products that exhibit security vulnerabilities or incidents must report these within a specified timeframe. This is crucial for being able to respond swiftly to discovered vulnerabilities and thus ensure protection for end-users. The CRA thus takes a proactive approach by requiring manufacturers to incorporate cybersecurity into the product development process from the outset.
Jochim Selzer gave the works council members an overview of the NIS2 Directive and the Cyber Resilience Act, as well as their key provisions. In doing so, he addressed the potential implications for working life and predicted stricter regulations on permitted software and hardware (USB sticks, Bluetooth peripherals, printers, messaging apps, video conferencing) as well as the use of multi-factor authentication. During the discussion, the works council members emphasised the vital importance of handling employee data in accordance with data protection regulations, on the one hand, and ensuring information security, on the other.
Another key point was the question of how to gain control over the wide range of cyber-attacks without hindering employees in their work and whilst avoiding placing an additional burden on them. Stricter security measures (e.g. increased use of two-factor authentication or restrictions on external devices) can make employees feel as though they are being restricted in their work. This is also underlined by the statement from Thomas Schläger, an IT specialist at ITSC GmbH: “Freedom is very quickly curtailed in the name of security.” Those present emphasised that it is extremely important to strike a good balance between data protection, legal compliance and personal rights.
Experience four Living Labs
As well as the lively discussion on topics relevant to the field, one of the highlights of the event was a visit to the Living Labs run by the PerspektiveArbeit Lausitz project. In total, four labs were visited, and some of them were even given a go.
In the VR laboratory, Dr Annett Raupach demonstrated ergonomic aspects of workplace design with regard to poor posture and how to avoid it. The settings in the virtual space allow for the optimal alignment of movement zones, reach ranges and accessibility. Furthermore, the laboratory offers the opportunity to compare and adapt prototypes, as well as to test training scenarios – for example, how employees can be introduced virtually to new tasks and workstations.
In the welding laboratory, Professor Julia Zähr explained how cobot-based welding can help SMEs make the transition to automated welding production of small-batch components. As the manual welding process is very demanding, automated production offers an attractive way to ease the workload. To this end, collaborative robots and a control cabinet enclosure are used as demonstration components.
At the Training Factory 4.0, Sebastian Roch demonstrated human-robot collaboration between a hybrid automated parts production line and driverless transport systems, as well as mobile manipulators. The areas of application for businesses are diverse: amongst other things, the laboratory provides support with the planning of flexible manufacturing systems (FFS), with programming and maintenance, and with the set-up and testing of in-house components.
In the Adaptive Manual Assembly laboratory, Falk Gruber provided information on assembly workstations that can be flexibly configured for different objects and operators. Material feeding and supply can thus be individually and optimally adapted to the respective component in order to reduce the workload on employees. Multimedia process descriptions are also used for this purpose.
All four Living Labs attracted a great deal of interest and were praised for their excellent facilities and the hands-on experience they offered.
Further information on the PAL project
Text and photos: Christin Voigt