International Edition
Latest News
Business

New law for more cybersecurity

Austria Strengthens Cybersecurity Measures Amidst Rising Russian Threats Introduction: Austria is moving to bolster its cybersecurity defenses with a revised Network and Facts Security Act (NIS Act), aiming to align with an EU directive and address escalating cyber…

New law for more cybersecurity

Austria Strengthens Cybersecurity Measures Amidst Rising Russian Threats

Introduction:

Austria is moving to bolster its cybersecurity defenses with a revised Network and Facts Security Act (NIS Act), aiming to align with an EU directive and address escalating cyber threats, notably those originating from russia. The legislation, currently under parliamentary review, seeks to establish a centralized cybersecurity authority and enhance national coordination to protect critical infrastructure and essential services. This comes after a delay in implementing the original EU directive, highlighting the complexities of achieving consensus on national security measures.

Background: The EU NIS2 Directive

The impetus for Austria’s updated legislation stems from the EU’s NIS2 Directive (https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2060), which came into effect in October 2024.NIS2 aims to strengthen the resilience of critical entities and digital service providers across the European Union against cyberattacks. It broadens the scope of entities covered, introduces stricter cybersecurity requirements, and enhances information sharing mechanisms. The directive mandates member states to establish national cybersecurity strategies and incident reporting frameworks.

Key Provisions of the Austrian NIS Act Amendment

The proposed Austrian amendment focuses on several key areas:

* Centralized Cybersecurity authority: The Interior Ministry will establish a dedicated cybersecurity authority to serve as a central point of contact for all cybersecurity matters. This authority will be responsible for overseeing implementation of the NIS2 Directive and coordinating national responses to cyber incidents.
* National Coordination Center: A national coordination center will be created to pool existing cybersecurity expertise and facilitate information sharing between government agencies, businesses, and other stakeholders.
* Expanded Scope: The legislation extends beyond government authorities to include companies and institutions operating within critical infrastructure sectors, such as energy, transportation, healthcare, and food supply. This broader scope reflects the interconnected nature of modern cyber threats and the potential for cascading impacts.
* Mandatory Security standards: The Act will introduce uniform and binding cybersecurity standards for entities within its scope, requiring them to implement appropriate technical and organizational measures to mitigate cyber risks.
* Incident Reporting: Organizations will be obligated to report significant cybersecurity incidents to the national authority, enabling a swift and coordinated response.

Addressing the Russian Threat

The urgency behind the legislation is underscored by growing concerns about cyberattacks and sabotage attributed to Russian state-sponsored actors and affiliated groups. Douglas Hoyos, Secretary General of NEOS, explicitly stated that the new cybersecurity authority would address the “rapidly growing threats from russian attacks and sabotage.” (https://www.neos.eu/).

Recent reports from Austrian intelligence agencies and international cybersecurity firms confirm an increase in malicious cyber activity targeting Austrian organizations.These attacks range from espionage and data theft to disruptive attacks aimed at critical infrastructure.Russia has been identified as a primary source of these threats, motivated by geopolitical tensions and a desire to destabilize European nations.

Parliamentary Hurdles and Future Outlook

While the legislative proposal was introduced in the National Council in November 2025, its passage requires a two-thirds majority due to constitutional provisions. Previous attempts to implement the EU directive faced opposition, highlighting the political challenges of enacting complete cybersecurity legislation.

Interior Minister Gerhard Karner emphasized the focus on “advice and precaution,” while State Secretary Jörg leichtfried recognized the amendment as a crucial step towards a “robust safety net.” Triumphant passage of the NIS Act amendment is vital for austria to enhance its cybersecurity posture, protect its critical infrastructure, and effectively counter the evolving threat landscape.

Primary topic: Cybersecurity Legislation in Austria
Primary Keyword: Austrian Cybersecurity Act
Secondary keywords: NIS2 Directive,Cyber Threats,Russian Cyberattacks,Critical Infrastructure protection,Cybersecurity Authority,Network and Information Security,Austria,EU Cybersecurity,Cyber Resilience.

About the author: Marcus Liu - Business Editor

MBA and ex‑B bureau chief specializing in global finance and fintech. Marcus speaks Mandarin, Japanese, and English, and has interviewed CEOs from the Fortune 50 to Y‑Combinator unicorns. Marcus Liu delivers sharp analysis on markets, startups, and corporate strategy for investors and entrepreneurs alike.