October 14, 2015 By Douglas Bonderud 2 min read

It’s taken four years and some serious negotiating, but the joint data protection agreement spearheaded by the U.S. and the European Union — also known as the Umbrella Agreement — is finally moving forward. According to SC Magazine, both American and European officials have now signed off on the agreement. If the bill passes ratification in the U.S., it represents a solid first step in cleaning up the often confusing mess of capturing and prosecuting global cybercriminals and malware creators.

One critical aspect of the new agreement is reciprocal extradition. Ideally, this developing Umbrella legislation should help force more bad guys out of hiding in other countries and into the driving wind and rain of U.S. courtrooms.

The Off-Soil Issue

Tackling the issue of extradition helps mitigate one of the biggest problems with existing cybersecurity laws: They only work if attackers are physically located in the U.S. As noted by CSO Online, lawmakers often make the mistake of designing laws to deter cybercrime but have no viable way to deal with attackers who live outside American borders.

Thanks to the new Umbrella Agreement, however, cybercriminals captured in other nations will now be extradited to the U.S., where they’ll face justice for their crimes as if they occurred on U.S. soil. Congress needs to reciprocate these privileges for EU governments, but this is an excellent starting point.

Under the Umbrella

Extradition isn’t the only thing covered by the Umbrella Agreement. According to the European Commission, the new legislation includes a number of provisions to safeguard personal data:

  • There are limitations on data use when transferred between government agencies; data may only be used for “preventing, investigating, detecting or prosecuting criminal offenses.”
  • There are specific and limited data retention periods that must be made publicly available.
  • There must be notification of all data breaches by agencies to the affected parties.

The agreement also creates a kind of equity between American and European citizens: Under the new Umbrella, residents of the EU will be able to seek judicial redress in U.S. courts if their data is misused or incorrectly processed.

Necessary Collaboration

Dropping the hammer on malware-makers is a necessary step for both the U.S. and Europe, which in many respects lag behind when it comes to sharing information about malicious code and high-profile attackers. Consider the emergence of new malware strains such as Ghost Push, which hides inside popular mobile apps sold in official app stores. Once installed, Ghost Push can both root devices and install unwanted apps. And as noted by the International Business Times, private companies like Visa and FireEye have now partnered to create a malware sharing Web portal designed to “increase threat awareness between merchants and the cybersecurity company” and detect just these kinds of emerging threats.

The Umbrella Agreement represents the first of many catch-up steps from both the American and EU governments since it effectively levels the playing field by giving malicious actors no safe place to hide. While this new agreement isn’t perfect, beefed-up extradition agreements and better data protection should help keep out the worst of any mal-weather.

More from

Change Healthcare attack expected to exceed $1 billion in costs

3 min read - The impact of the recent Change Healthcare cyberattack is unprecedented — and so are the costs. Rick Pollack, President and CEO of the American Hospital Association, stated, “The Change Healthcare cyberattack is the most significant and consequential incident of its kind against the U.S. healthcare system in history.”In a recent earnings call, UnitedHealth Group, the parent company of Change Healthcare, speculated on the overall data breach costs. When all is said and done, the total tally may reach $1 billion…

Remote access risks on the rise with CVE-2024-1708 and CVE-2024-1709

4 min read - On February 19, ConnectWise reported two vulnerabilities in its ScreenConnect product, CVE-2024-1708 and 1709. The first is an authentication bypass vulnerability, and the second is a path traversal vulnerability. Both made it possible for attackers to bypass authentication processes and execute remote code.While ConnectWise initially reported that the vulnerabilities had proof-of-concept but hadn’t been spotted in the wild, reports from customers quickly made it clear that hackers were actively exploring both flaws. As a result, the company created patches for…

Evolving red teaming for AI environments

2 min read - As AI becomes more ingrained in businesses and daily life, the importance of security grows more paramount. In fact, according to the IBM Institute for Business Value, 96% of executives say adopting generative AI (GenAI) makes a security breach likely in their organization in the next three years. Whether it’s a model performing unintended actions, generating misleading or harmful responses or revealing sensitive information, in the AI era security can no longer be an afterthought to innovation.AI red teaming is emerging…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today