Breaking news

Cyprus Warns Smaller Firms Will Bear The Brunt Of Europe’s New Cyber Resilience Rules

Cybersecurity Is Becoming A Product Requirement, Not An Add-On

Cypriot manufacturers and software developers are entering the most demanding phase of Europe’s new cybersecurity regime, Research Deputy Minister Nicodemos Damianou said this week, as the first obligations under the European Union’s Cyber Resilience Act (CRA) begin to take effect and smaller firms confront the practical challenge of compliance.

Addressing the Cyprus government and industry audience at the “Building CRA Compliance through Horizontal Cybersecurity Standards” conference in Nicosia, Damianou used an unusual example to explain why the CRA reaches far beyond the traditional technology sector: a fish tank.

A few years ago, he said, attackers gained access to a casino’s network through a smart thermometer installed in its lobby aquarium, then moved through the system until they reached the high-roller database.

“Nobody who bought that thermometer thought they were making a decision that affected cybersecurity,” Damianou said. “That is precisely the point.”

The CRA, he argued, marks a structural shift. For the first time, security is becoming a property of the product itself — designed in from the outset, maintained throughout the support period and placed squarely on the manufacturer rather than the customer.

The casino incident is not new, but the lesson has become harder to ignore as connected components spread across household appliances, industrial equipment and software. The attack surface is no longer confined to obvious digital products; it now extends to almost anything with a network connection.

AI Agents Add A New Layer Of Risk

Damianou also pointed to newer threats posed by autonomous artificial intelligence agents, citing recent incidents involving OpenAI, Hugging Face and Anthropic.

OpenAI said in August that, during cybersecurity evaluations in July, internal research models bypassed controls intended to isolate them from the internet, exploited vulnerabilities and accessed parts of Hugging Face’s systems. Anthropic has separately reported cases in which Claude models reached the internet during security evaluations and gained unauthorized access to real-world systems.

For Cyprus, Damianou said, the implications are especially significant because of the island’s reliance on connected infrastructure and international supply chains.

“As an island member state, Cyprus is fully cognizant of the consequences,” he said.

From Legislation To Operational Compliance

The remarks come as the CRA moves from legislative adoption to day-to-day compliance.

Since September 11, manufacturers have been required to report actively exploited vulnerabilities and severe security incidents affecting products with digital elements through the European Union’s reporting arrangements overseen by ENISA, the EU Agency for Cybersecurity.

The regulation’s full essential requirements will apply from December 11, 2027.

For Damianou, the more difficult issue is not the principle of compliance, but the mechanics of implementation.

“A regulation tells you what must be achieved. It does not tell a twelve-person company in Lemesos how to achieve it. That is the job of standards,” he said.

European standardization bodies CEN, CENELEC and ETSI are developing harmonized standards intended to help companies meet the CRA’s requirements.

The horizontal standards discussed in Nicosia are designed to apply across categories of digital products, covering secure product design, risk management, vulnerability handling, access management, encryption and security across the full product lifecycle.

Rather than forcing manufacturers to interpret the legislation separately in each EU country, Damianou said the standards should provide “one clear, recognized route to compliance, instead of twenty-seven interpretations of the same article.”

That makes them far more than a technical exercise, he added, placing the work “on the critical path of the end-to-end cybersecurity value chain.”

Why Smaller Businesses Matter Most

Damianou said his main concern in Cyprus is the burden on smaller companies.

“Most Cypriot manufacturers and software developers do not have a compliance department,” he said, arguing that for such firms “a practical, accessible standard is the difference between compliance as a burden and compliance as a competitive advantage.”

The CRA, he added, should be understood not only as cybersecurity legislation but also as a Single Market measure. A company that develops a secure, compliant product should be able to place it across the European market without having to adopt a different approach in each member state.

That point fed into a broader concern about Europe’s strategic position in technology.

Damianou said Cyprus had made cyber resilience one of the three digital priorities of its six-month Presidency of the Council of the EU, which ended in June, alongside efforts to strengthen Europe’s ability to develop and secure its own technologies.

During the presidency, Cyprus advanced work on the revision of the Cybersecurity Act, including proposals for a stronger ENISA and simpler certification procedures, and brought the file before the Telecom Council in June.

It also hosted Europe’s cybersecurity certification community, while work on the Digital Omnibus, including plans for a single entry point for incident reporting, has since moved to the Irish Presidency.

Not every file was completed during Cyprus’ six months at the helm, Damianou acknowledged, but the underlying message remained unchanged.

“Europe cannot afford to be merely a regulator of technologies developed elsewhere,” he said.

Cyprus Tries To Lead By Example

Cyprus is also working to strengthen its own internal arrangements before the CRA applies in full.

Damianou said the Digital Security Authority is central to the country’s preparations, while the Council of Ministers this summer approved, for the first time, a unified cybersecurity policy framework covering the government and the wider public sector.

“We cannot ask manufacturers to lock their products while leaving our own doors open,” he said.

For Damianou, the larger objective behind the rules, reporting requirements and standards is more straightforward than the legislative architecture suggests.

“The huge task at hand is at the end of the day to build products people can trust from a cybersecurity perspective,” he said. That applies, he added, “right down to the thermometer in the fish tank.”

Anthropic’s Opus 5.5 Arrives With Lower Costs, Faster Performance And Sharper Safety Guardrails

Anthropic on Tuesday unveiled Opus 5.5, its latest flagship model and, by the company’s account, a new state of the art in coding and knowledge work.

Opus remains the top tier in Anthropic’s three-model Claude family, positioned above Sonnet and Haiku, which serve the middle and entry-level segments respectively. The company says the new release not only outperforms the larger Fable model on several benchmarks, but also completed a number of informal tasks that Fable could not finish.

A More Efficient Frontier Model

One of the most notable changes is economic, not just technical. Anthropic says output tokens for Opus 5.5 will be priced at $20 per million, down from $25 for the previous version. Other usage metrics have also declined, and the model is faster to run, reflecting lower compute requirements to serve it.

That matters because model economics are increasingly central to enterprise adoption. In practice, a more capable model is only part of the equation; speed and cost often determine whether it can be deployed at scale across software development, research, customer operations, and internal knowledge workflows.

Sharper Communication, Less Jargon

Anthropic says the update also changes how Opus communicates. The new model is less likely to lean on jargon and more likely to lead with the most important information first. For business users, that is more than a stylistic adjustment. It improves readability, reduces friction in decision-making, and makes AI output easier to use in executive settings where time is scarce and clarity matters.

A Rapid Follow-Up To Opus 5

The launch comes just two months after the debut of Opus 5 on July 24. Anthropic said Sonnet 5.5 and Haiku 5.5, the next models in the lineup, will follow “in the coming weeks,” with similar performance gains expected.

Safety Remains Central To The Release

Anthropic says Opus 5.5 is comparable to Mythos in biology and cybersecurity capabilities, which means the model is subject to the same safeguards as the company’s Fable model. Those restrictions limit the model’s use in areas such as discovering exploits in compiled programs or developing recognizable biological weapons, among other sensitive tasks.

The release is also notable because it is Anthropic’s first since CEO Dario Amodei publicly embraced calls to pace the frontier, a strategy designed to slow the rate of capability gains so alignment and safety measures can catch up. In a recent post, Amodei wrote: “I have become convinced that fully addressing the risks requires even more prudence, not just investing in risk prevention, but pacing the rate of capabilities advancement so that risk prevention has time to keep up.”

Preparing The Next Layer Of Oversight

Anthropic said Opus 5.5 underwent safety training broadly similar to earlier models, including alignment testing and pre-release evaluation by external groups such as METR and Frontier Design. At the same time, the company said it is already building more advanced training and evaluation systems for future releases, including stronger security and monitoring infrastructure.

“As AI becomes more capable, public policy should play a larger role in making sure the systems people rely on are safe,” the company wrote in its announcement. “That capacity takes time to build, and we’ve started to put the infrastructure in place to support it. We expect to share more details on these efforts soon.”

The Future Forbes Realty Global Properties
eCredo
Aretilaw firm
Uol

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter