In recent years, the issue concerning digital security has become increasingly important. Academics within an interdisciplinary approach are debating the topic and how to ensure and implement digital information security from the perspective of both companies and consumer users. The issue affects both the public and private sectors and requires coordinated and effective policy action.
The risks associated with such attacks are closely linked to identity theft, cyber fraud, and money laundering.
In order to address the security-related emergency, the European legislator has enacted several legislative acts. The purpose of this paper is to explain, through a legal analysis, the current regulatory framework examining the new developments and identifying any remaining gaps.
From this analysis, it appears that the topic has recently been the subject of several legislative actions. In this scenario, the NIS 2 Directive (Directive EU 2022/2555) represents a crucial update in the European Union’s legislation for network and information security. This work points out the lack of remedies for individuals in the case where the parties addressed by all regulatory interventions fail to respect their obligations.
At the same time, there is no doubt that cyber incidents have a significant impact on the profits of companies. In this regard, the Corporate Sustainability Reporting Directive (CSRD 2022/2464) introduced the inclusion of cybersecurity information in the annual report as non-financial information. For this reason, it is useful to investigate how the cybersecurity obligations contribute to the quality of sustainability reporting.
To address the application problems of these regulations, in the final part of the paper, it could be proposed to use blockchain tools to implement the certainty of digital identity and the integrity of the entered information.