The European Network for Cyber Security (ENCS) and the Dutch Institute for Vulnerability Disclosure (DIVD) have formalized their collaboration by signing a Memorandum of Understanding (MoU) aimed at enhancing efforts to discover, disclose, and address vulnerabilities in Europe's power grid and other key infrastructure. This agreement was signed during ENCS's annual General Assembly at its headquarters in The Hague.
Framework for Collaboration
This newly established MoU provides a collaborative framework that blends ENCS's proficiency in security testing with DIVD's expertise in coordinated vulnerability disclosure and Common Vulnerabilities and Exposures (CVE) registration.
The agreement becomes effective immediately, marking the start of joint initiatives to improve cybersecurity in critical infrastructure.
Identifying and Resolving Vulnerabilities
The collaboration dictates that ENCS and DIVD will unite their efforts to identify and resolve issues in high-power IoT components.
ENCS kicked off its high-power IoT security testing program at the General Assembly
Highlighting the importance of such work, ENCS kicked off its high-power IoT security testing program at the General Assembly, showcasing a hacking demonstration. Vulnerabilities discovered by ENCS will be managed using DIVD's disclosure and CVE procedures. Additionally, ENCS security experts will join DIVD in various testing activities and events.
EU Cyber Resilience Efforts
This partnership aligns with the European Union's increasing emphasis on bolstering vulnerability management within critical infrastructure, as supported by initiatives such as the Cyber Resilience Act.
Given the digital and interconnected nature of current energy systems, addressing vulnerabilities is crucial to preventing potential cross-border disruptions.
Advancing Responsible Disclosure Practices
ENCS's Managing Director, Anjos Nijk, remarked on the collaboration: “Strengthening Europe’s cyber resilience requires close cooperation across the cybersecurity ecosystem. This agreement enhances our ability to identify and resolve vulnerabilities affecting critical infrastructure, while reinforcing responsible disclosure practices that help reduce risk for grid operators and other essential service providers.”
Chris van ’t Hof, Director of DIVD, echoed these sentiments: “Effective vulnerability disclosure depends on trust, coordination, and technical expertise. By working with ENCS and its community of security specialists and infrastructure stakeholders, we can help ensure vulnerabilities in high-impact systems are handled efficiently and responsibly.”
Commitment from Critical Infrastructure Operators
Enexis's Director of Asset Management and Chair of the ENCS General Assembly, Maarten Noom, noted ENCS's valuable partnership: “With its deep industry knowledge and extensive network, ENCS has proven to be a valuable partner, making a crucial difference in addressing real cyber threats to our critical infrastructure.”
During the General Assembly, ENCS members appointed Wolfgang Löw, CISO of EVN Group, as Chair of the ENCS Assembly Committee. On assuming the position, Löw stated: “I am grateful for the trust of the ENCS Assembly, and I look forward to supporting ENCS in strengthening Europe’s cyber resilience. The partnership with DIVD is an important milestone: timely insight into vulnerabilities in high-impact systems is essential for critical infrastructure operators to initiate effective protective measures at an early stage. This collaboration underscores ENCS’s leadership in driving coordinated vulnerability discovery and resolution across the energy sector.”