Analystinnen und Analysten in einem Lagezentrum für IT-Sicherheit

Projekt

Reporting the breach, protecting the reporter: whistleblowing at the intersection of NIS2, the Cyber Resilience Act and Directive (EU) 2019/1937

Abstract European cybersecurity law increasingly runs on reports. The NIS2 Directive obliges essential and important entities to notify significant incidents within a staggered 24-hour, 72-hour and one-month cascade and to operate coordinated vulnerability disclosure; from 11 September 2026, Article 14 of the Cyber Re…

Abstract European cybersecurity law increasingly runs on reports. The NIS2 Directive obliges essential and important entities to notify significant incidents within a staggered 24-hour, 72-hour and one-month cascade and to operate coordinated vulnerability disclosure; from 11 September 2026, Article 14 of the Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities and severe incidents through a single reporting platform operated by ENISA. Both regimes address organisations. Yet virtually every report originates with an individual—an employee, an administrator, an external security researcher—whose own legal position is governed, if at all, by a third instrument: the Whistleblowing Directive (EU) 2019/1937. This article maps that intersection and identifies three structural gaps. First, breaches of NIS2 fall within the Whistleblowing Directive’s material scope through the substitution of references to the repealed NIS1 Directive, but national transpositions—the German Hinweisgeberschutzgesetz prominent among them—track this coverage only partially. Second, the Cyber Resilience Act is absent from the Directive’s annex, producing a marked asymmetry between a harshly sanctioned entity duty and an unprotected individual reporter. Third, independent security researchers generally fall outside the Directive’s personal scope, and its acquisition shield does not reach conduct constituting a self-standing criminal offence. Drawing on the incentive-theoretic and empirical literature on whistleblowing, the article analyses incentive design and the emerging risk of AI-generated false reports before proposing proportionate reforms: annex maintenance, an EU-wide researcher safe harbour, channel interoperability and abuse-resistant incentives.

Technologien

Hochschulen