Law / Malta

Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, Risk-Management Measures for Essential and Important Entities

S.L. 460.41, arts. 18, 19 and 24, Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order

In force since .

A sector security regimes rule binding public and private bodies.

Obligation class
Security, Governance

As of .

What it requires

  • This binds an essential or important entity under articles 3 and 4 of the Order that falls under Malta's jurisdiction under article 23: an entity established in Malta or, for a DNS service, top-level domain name registry, domain name registration, cloud computing, data centre, content delivery network, managed service, managed security service, online marketplace, online search engine or social networking services platform provider, one whose main establishment in the Union is in Malta or whose Union representative is established in Malta. It reaches you where you qualify as at least a medium-sized enterprise under the EU size-cap rule (Commission Recommendation 2003/361/EC) and are named in the First or Second Schedule, or where the Order names you regardless of size; the Second Schedule names online marketplace, online search engine and social networking services platform providers, and the wider sector classes it reaches (energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT services management, public administration, space and others) are reached by declaring that you are an essential or important entity.
  • Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems you use for your operations or to provide your services, and to prevent or minimise the impact of incidents on the recipients of your services and on other services (article 19(1)).
  • Base those measures on an all-hazards approach and cover at least: policies on risk analysis and information system security; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply chain security; security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure; policies and procedures to assess the effectiveness of the measures; basic cyber hygiene practices and cybersecurity training; policies on cryptography and, where appropriate, encryption; human resources security, insider risk management, access control and asset management; multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communication systems where appropriate; and logging and traceability (article 19(2)).
  • When choosing supply chain measures, take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of its products and cybersecurity practices, including its secure development procedures (article 19(3)).
  • Appoint a security liaison officer with the necessary expertise, who develops and maintains your business continuity plans, ensures risk assessments are carried out, maintains and exercises your operator security plan and acts as your point of contact with the CIP Department or the designated competent authority (article 19(1)(c)).
  • Receive CSIRT monitoring services from an internal CSIRT or an autonomous CSIRT that meets the requirements of article 9(1) (article 19(1)(d)).
  • Have your management body approve the risk-management measures and oversee their implementation, expect its members to follow training, offer similar training to your employees on a regular basis, and expect the natural persons composing the body to be liable for an infringement of article 19 (article 18).
  • Register on the national self-registration mechanism of the CIP Department with your name, the CSIRT providing monitoring services to you, your contact details and IP ranges, your sector and the Member States where you provide services, and notify it of any change without delay and within two weeks (article 7(4) and (5)); a DNS service provider, top-level domain name registry, domain name registration service, cloud computing, data centre, content delivery network, managed service, managed security service, online marketplace, online search engine or social networking services platform provider also submits the article 24(1) registry information by the prescribed date and notifies changes within three months.
  • Where you find you do not comply with the measures in article 19(2), take, without undue delay, all necessary, appropriate and proportionate corrective measures (article 19(4)).

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

The Order's penalty regime for an infringement of articles 19 or 20 is administrative: fines imposed by the Enforcement Committee under articles 32 and 33, appealed to the Administrative Review Tribunal under article 41. No provision of the Order makes the infringement a criminal offence, although article 31(10)(b) lets the CIP Department ask the competent bodies to prohibit temporarily a chief executive or legal representative of an essential entity from exercising managerial functions until the entity complies.

Penalty structure

Article 32(3) sets the maximum administrative penalty for an essential entity that infringes article 19 or 20 at EUR 10,000,000 or 2 percent of the total worldwide annual turnover of the preceding financial year of the undertaking the entity belongs to, whichever is higher. Article 32(4) sets the important-entity tier at EUR 7,000,000 or 1.4 percent of that turnover, whichever is higher. Article 38 lets the Enforcement Committee, on the request of the CIP Department or the designated competent authority, impose a daily penalty payment of EUR 100 for each breach the entity repeatedly fails to cease or rectify, and the payment may be backdated to the date the breach was committed. A decision of the Committee can be appealed to the Administrative Review Tribunal within 20 days under article 41.

Rule
Higher of
As of
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The Critical Infrastructure Protection Department (CIP Department), the national supervisory authority under article 7 of the Order; the Malta Communications Authority is the competent authority the Schedules name for digital infrastructure, digital providers and postal services, and the Enforcement Committee imposes the administrative fines on the report of the CIP Department or the designated competent authority under article 33.

Settledness

As of
Open questions
By what date must the providers named in article 24(1) of the Order submit their registration information to the CIP Department, given that the article says only "by the prescribed date"?

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 19 requires an essential entity or important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems it uses for its operations or services, and to prevent or minimise the impact of incidents on the recipients of its services and on other services.

The measures must follow an all-hazards approach and cover at least the areas article 19(2) lists, which include incident handling, supply chain security and security in the acquisition, development and maintenance of systems including vulnerability handling and disclosure. The entity must also appoint a security liaison officer. It must receive monitoring services from an internal or an autonomous computer security incident response team (CSIRT).

Article 18 requires the entity's management body to approve the measures and oversee their implementation, and the natural persons composing the body may be held liable for an infringement of article 19. The Order applies to a public or private entity of a type listed in its First or Second Schedule that is at least medium-sized.

Regardless of size it also applies to providers of public electronic communications networks or publicly available electronic communications services, trust service providers, top-level domain name registries and DNS service providers. The Second Schedule names online marketplace, online search engine and social networking services platform providers as digital providers.

The First Schedule names cloud computing, data centre and content delivery network providers as digital infrastructure and managed service and managed security service providers under ICT services management. A cloud computing, data centre, content delivery network, managed service, DNS, online marketplace, online search engine or social networking services platform provider must also register with the CIP Department by the prescribed date.

When LexLint raises it

When your app profile says your app handles health records, runs an essential service, operates a social platform, provides financial services or provides telecom services.

Back to the example  ·  Lint your app