Insurance Europe, the organisation representing the European insurance and reinsurance sector, is welcoming the European Commission’s review of the Cybersecurity Act (CSA), a move aimed at simplifying regulations and easing the administrative burden on companies.
Launched in April 2025, the CSA review aims to address the fast evolution of technology and increasingly complex cyber threats. Key areas of focus include the ENISA (the EU Agency for Cybersecurity), the European Cybersecurity Certification Framework, and security risks in the ICT supply chain.
Insurance Europe highlighted that the current regulatory environment for insurers is a “patchwork of rules”, with insurers often having to report the same incident to multiple authorities under differing rules and timelines.
These regulations include the General Data Protection Regulation (GDPR), the ePrivacy Directive, the Artificial Intelligence Act, and the Cyber Resilience Act.
In its response to the consultation, the organisation stated that “the European insurance industry supports efforts to streamline cybersecurity reporting requirements and eliminate unnecessary overlaps and duplications.”
Noting that recent regulatory developments, such as the implementation of the Digital Operational Resilience Act (DORA), have already significantly increased compliance obligations for insurers.
To address the simplification of EU cybersecurity regulation, Insurance Europe calls for:
- Standardised reporting formats to ensure consistency across different jurisdictions
- An end to duplicate reporting, especially between DORA supervisors and ENISA, the EU Agency for Cybersecurity
- Clear and consistent guidance from the EU to prevent conflicting national frameworks from emerging.
Additionally, Insurance Europe also emphasised the need for legal clarity across the EU, noting that some national guidelines are outdated and contradict newer EU laws – particularly challenging for insurers operating across borders.
Finally, with regard to potential changes to the mandate of ENISA, the organisation stressed the importance of transparency in ENISA’s processes and called for greater stakeholder involvement in its work.
The post Insurance Europe calls for streamlining EU cybersecurity regulations appeared first on ReinsuranceNe.ws.