With European Cybersecurity Month coming to a close, we are taking a closer look at one of the key cybersecurity issues worth following in Brussels, the Directive on Security of Network and Information systems (NIS 2 Directive). Florian Pennings (Microsoft), Issue Lead, Cybersecurity, Digital Economy Committee, AmCham EU shared his insights on how the NIS 2 can help enhance Europe's cyber resilience.
#CyberSecMonth – enhancing Europe's cyber resilience
With European Cybersecurity Month coming to a close, we are taking a closer look at one of the key cybersecurity issues worth following in Brussels, the Directive on Security of Network and Information systems (NIS 2 Directive). Florian Pennings (Microsoft), Issue Lead, Cybersecurity, Digital Economy Committee, AmCham EU shared his insights on how the NIS 2 can help enhance Europe's cyber resilience.

Related items
:focal())
Closing the skills gap to restore Europe’s competitiveness
On Tuesday, 24 February, AmCham EU hosted Stefan Olsson, Deputy Director-General, Jobs, Skills and Social Policies, Directorate-General for Employment, Social Affairs and Inclusion, European Commission to discuss how closing the skills gap can strengthen Europe’s competitiveness. As shortages across sectors continue to affect productivity, investment and innovation, participants reflected on progress one year after the launch of the Union of Skills and the importance of sustained public-private cooperation. The discussion explored how Europe can build a future-ready workforce to support the green and digital transitions while addressing labour market mismatches. Aurelia Takacs (Cisco), Chair, Social Impact, Inclusion and Skills Committee, AmCham EU moderated the discussion and examined practical policy solutions to strengthen skills development, improve labour market alignment and support inclusive economic growth.
:focal())
Choose France, choose the future
Cisco is strengthening France’s role in the global digital economy with the launch of its Global AI Hub, announced at the 2025 Choose France Summit. The hub will focus on secure, energy-efficient artificial intelligence (AI) infrastructure, innovative cooling solutions for data centres and support for the startup ecosystem. To address future workforce needs, Cisco will also train 230,000 people in France over the next three years through its Networking Academy, covering fields such as cybersecurity, data science and AI. Building on nearly 400,000 individuals already trained in France, this investment supports Cisco’s EU-wide commitment to train 1.5 million people by 2030. Read more on Invested in Europe.
:focal())
Cybersecurity Act review: AmCham EU calls for greater industry engagement and evidence-based certification criteria
The European Commission’s proposal to revise the Cybersecurity Act (CSA2) comes at the right moment, as Europe faces an evolving range of cyber threats. With its measures to reinforce ENISA and make harmonisation the key to a more resilient Single Market, the proposal brings the Act closer to the realities of today’s fast-moving cybersecurity ecosystem.
However, the Commission’s proposal still fails to go far enough on providing a platform for more active industry engagement. It rightly formalises existing structures but falls short of creating mechanisms that allow for regular expert-level exchanges and meaningful industry feedback into the CSA2 framework, building on lessons learned from the past years. Such exchanges are essential, given industry’s role as a front-line defender against cyber threats.
Now, as the file moves to the European Parliament and the Council of the EU, the co-legislators must ensure certification schemes under the CSA2 remain based on technical criteria. The EU’s cybersecurity needs should be a matter for sober, technical analysis. AmCham EU therefore supports the proposal's structural distinction between technical certification and non-technical supply chain risks. Maintaining this separation prevents restrictive requirements that limit choice, reduce competition and slow innovation.
The same approach is necessary for the proposal’s provisions to secure critical infrastructure under the new ‘Trusted ICT Supply Chain Framework’ (Title IV). These measures must also be underpinned by an objective, evidence-based approach to ‘non-technical risks’. At the same time, measures involving restrictions on data transfers must be aligned with international agreements to avoid unintended disruptions to global operations.
Ultimately, US companies share the EU’s commitment to securing the region’s digital resilience. AmCham EU members invest heavily in security and stand ready to support the delivery of a framework that keeps Europe open, secure and competitive.
Policy priorities
Insights and advocacy driving Europe’s policy agenda. Our priorities support growth, innovation and a stronger transatlantic economy.
Membership
Connecting business and policymakers to strengthen the voice of American companies in Europe.