BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP
• Requests for technical reports, security documen - tation and evidence of incident response readiness. • Orders for remediation and additional reporting. Incident response • Operators typically maintain internal CSIRTs that co-ordinate with CERT.be. Transport sector • Aviation and land transport: Federal Minister for Transport. • Maritime and port infrastructure: Federal Minister for Maritime Mobility. Powers • Inspections, security audits and mandatory cyber - security assessments. Incident response • Sub-sectors such as air navigation services and port authorities maintain dedicated response teams that escalate major incidents to CERT.be. Health sector – Federal Public Service Public Health Mandate • Oversight of cybersecurity requirements applicable to hospitals, laboratories and other NIS 2-desig - nated health entities. Powers • Access to IT system documentation, incident response plans and security controls. • Verification of adequate cybersecurity risk manage - ment measures. Incident response • Large hospitals often operate internal CSIRTs. Digital infrastructure and digital services – BIPT Mandate • Oversight of electronic communications networks, digital infrastructure, cloud providers, DNS opera - tors and certain online platforms. Powers • On-site inspections and technical vulnerability assessments.
• Binding instructions and enforcement of sector- specific rules. • Broad administrative enforcement authority. Incident response • BIPT collaborates closely with CERT.be. National Crisis Center (NCCN) Mandate • The NCCN co-ordinates national cyber crisis man - agement, including risk assessments, emergency planning and international information exchange on threats to critical infrastructure. Powers • Ability to request detailed reporting for national threat assessments. • Co-ordination of emergency plans and activation of crisis response mechanisms. • Oversight of crisis communication and support for regional authorities. Incident response While not a CSIRT, the NCCN works closely with the CCB and CERT.be during major cyber incidents affecting public safety or national security. Belgian Data Protection Authority (DPA) Mandate • The DPA enforces GDPR requirements relating to data security and personal data breach notifica - tions. Powers • Investigations via its Inspection Body. • Requests for policies, logs, breach documentation and technical evidence. • Corrective measures, reprimands and administra - tive fines. • Orders to improve data security controls. Incident response • The DPA may co-operate with the CCB when a cybersecurity incident also constitutes a personal data breach or raises national level cybersecurity concerns.
38 CHAMBERS.COM
Powered by FlippingBook