Andorra Approves Cybersecurity Law Amendments to Combat Rising Digital Threats
Andorran ministers have updated the 2022 cybersecurity law, requiring incident reporting by all entities and SOCs for critical operators to bolster defenses against surging threats from state actors.
Key Points
- Mandates all entities report incidents to CSIRT-AD; critical ones must establish SOCs
- Strengthens CSIRT-AD-Police cooperation and expands to sectors like public media
- Adjusts penalties for better reporting; boosts agency roles and international ties
- Responds to global attacks, including recent firewall vulnerability hitting Andorra
The Andorran Council of Ministers has approved amendments to Law 22/2022 on measures for the security of networks and information systems, updating the cybersecurity framework to address rising digital threats.
The reforms, aligned with the national Cybersecurity Strategy, mandate that all entities report incidents to the CSIRT-AD response centre at the Andorran National Cybersecurity Agency. This requirement recognizes that even non-critical organizations can serve important operators and cause ripple effects. Critical entities must now establish a Security Operations Centre (SOC) to monitor and alert on external threats, acting as an early warning system to prevent spread to vital infrastructure.
Key measures include a strengthened cooperation protocol between CSIRT-AD and the Police Corps for incidents with potential criminal links. The law expands to cover new essential sectors, such as public radio and television, and adjusts penalties to encourage prompt reporting, proactive measures, and collaboration. National agencies like the Cybersecurity Agency and CSIRT-AD take on expanded roles in supervision, advice, and incident management, while international engagement grows through European networks and partnerships with leading organizations.
The changes follow a global and local uptick in cyberattacks, including a recent vulnerability affecting nearly 74,000 firewalls across 194 countries, which impacted at least one public administration and one company in Andorra. Jordi Ubach, director of the National Cybersecurity Agency, highlighted public administration and healthcare as prime future targets for advanced persistent threats (APTs) from organized groups linked to Russia, China, North Korea, and Iran. These attacks, often state-directed, prioritize data value and have already hit sectors like energy and banking.
Ubach noted that heightened awareness and better detection tools in Andorra have aligned local incident rates with international levels. Over 80% of firms already have SOCs, either internal or national, aiding smaller businesses lacking resources. Interior Minister Marc Rossell, responsible for Public Function and Digital Transformation, said the updates adapt rules to new challenges and "elevate national resilience."
Since the 2022 law's implementation, the government has built prevention and response capabilities. Officials describe the overhaul as advancing a proactive model with stricter standards, coordination, and global alignment to protect critical infrastructure and essential services.
Related Articles
Other articles from Catalan-language sources about the same story: