Netgroup achieves ECSO Cyber Security Europe Label
On Feb. 3, 2023, Netgroup S.p.a. was awarded the coveted ‘ECSO Label,’ also known as the ‘Cybersecurity Made in Europe Certificate.’
How did the ECSO label come into being? What is its concrete purpose?
To understand the value and very nature of the Label, it is necessary to introduce ECSO, the organization that conceived and promoted it. The European Cyber Security Organization is an industry organization committed to building a robust European cybersecurity ecosystem. Among ECSO’s main goals is to consolidate Europe’s digital sovereignty and strategic autonomy, along with strengthening its cyber resilience.
The ECSO Label is among the initiatives supporting these goals, as on the one hand it makes it easy to identify industry players who support, through their investments in research and development, the achievement of the aforementioned goals of digital sovereignty and strategic autonomy, on the other hand, it provides customers of companies that achieve the Label with a form of assurance – from an authoritative third party – that the products and services offered by these companies have been developed in accordance with the fundamental criteria of cyber resilience, consistent with the guidelines issued by the European Cybersecurity Agency (ENISA).
What is the accreditation process? What requirements must be met?
In order to make the accreditation process more effective and widespread, the ECSO collaborates with those institutional partners in each EU member country capable of performing, with the necessary expertise and authority, the evaluation of the applications received. In Italy, the role of evaluator for the ECSO Label is held by the Istituto di Informatica e Telematica del Consiglio Nazionale delle Ricerche (IIT-CNR). The request for accreditation made by Netgroup was overseen by Dr. Chiara Pratali, to whom our heartfelt thanks go for being a rigorous but always affable and clear interlocutor in articulating requests for evidence and insights.
There are two sets of requirements that must be met in order to obtain the Label: the first set of requirements is mainly administrative, aimed at ascertaining not only the origin and ownership of the company but also the destination of its investment in research and development; the second set is more pertinent to the practices and procedures designed to impart the right level of cyber resilience to the products and services offered to its customers.
Specifically, the administrative requirements met by Netgroup are as follows:
- European base: Netgroup is a legal entity having its registered office in a European Union country;
- European ownership: Netgroup is a company wholly owned and controlled by European individuals or legal entities;
- activity carried out in Europe: Netgroup conducts more than 50 percent of its cybersecurity R&D and has more than 50 percent of its staff in Europe, the EEA, or the UK;
- secure cybersecurity products and services: the Netgroup offering is found to comply with the core security requirements established by ENISA for the procurement of secure ICT products and services;
- data protection: Netgroup is committed to observing the principles and obligations enshrined in EU Regulation 679/2016 (GDPR) and national data protection laws.
In addition to complying with the general requirements just stated, companies wishing to achieve the Label must be able to demonstrate, analytically, the compliance of their offerings with respect to the specific requirements set forth in points 4. (cyber resilience) and 5. (data protection) above by submitting a representative sample of their products and services for examination by IIT-CNR evaluators. The areas placed under examination are:
- Application of the principle of Security by Design to the development of new products and services;
- compliance with the principle of Least Privilege in the design and configuration of products and services;
- use of a mechanism of Strong Authentication for access to its products or services;
- Adoption of specific measures for the Asset Protection with respect to its products or services;
- Adoption of appropriate measures aimed at Supply Chain Security, throughout the entire service life-cycle;
- commitment to ensuring the Documentation Transparency, for the benefit of reuse and maintainability;
- demonstrable application of the processes of Quality Management, for controlled and measurable results;
- commitment to ensuring the Service Continuity, throughout the life cycle of products and services;
- Application of all applicable rules and regulations in the EU Jurisdiction and in the different member states;
- compliance with the principle of Data Usage Restriction, with justified and documented data processing.
Both at the application stage and as a result of requests for further study received from the IIT-CNR evaluators, Netgroup has provided all the evidence to demonstrate the adherence of its practices to the principles outlined above.
What is the role of the ECSO Label in the Netgroup strategy? Are similar initiatives underway?
The value of the ECSO Label for Netgroup lies in building the so-called ‘Digital Trust’, i.e., the trust that current and future customers can place in the services provided by Netgroup, confident that these services will work to protect the value of their businesses (image, profitability, intellectual property, etc.) while enabling them to seize further growth opportunities in the digital market, supporting the creation of new value. The ECSO Label is in line with other initiatives already undertaken by Netgroup in order to demonstrate, to its stakeholders in the public and private sectors, the possession of a culture of quality, service and security – a corporate culture that is virtuously projected into the development of new services and continuous improvement (so-called ‘continuous improvement’) of existing services.
In this regard, Netgroup has achieved and renewed over the years the formal certification of its Quality Management Systems (SGQ/QMS), Service (SGS/SMS) and Information Security (SGSI/ISMS), according to ISO 9001, ISO/IEC 20000-1 and ISO/IEC 27001 standards – the latter extended to the integrative controls for the management of Cloud services, according to ISO/IEC 27017 standard, and to the integrative controls for the protection of personal data in the Cloud, according to ISO/IEC 27018 standard. Netgroup will continue to invest in the certification of its management systems, its professional practices and its specialized personnel, with the aim of further consolidating its brand reputation and gathering the trust of all those interlocutors – potential partners and prospective customers – who have not yet had the opportunity to get to know Netgroup’s commitment and seriousness and who consider it necessary to be able to rely on attestations from third, authoritative and qualified parties, such as the evaluating bodies RINA, AUDISO or, in the case of the ECSO Label, the IIT-CNR.
