The European Network for Cyber Security (ENCS) and the Dutch Institute for Vulnerability Disclosure (DIVD) have announced the signing of a Memorandum of Understanding (MoU) to bolster cooperation in discovering, disclosing, and resolving vulnerabilities in Europe's power grids and critical infrastructure.
This agreement was formalised at ENCS' annual General Assembly meeting, which took place at their headquarters in The Hague yesterday.
Framework for collaboration
The newly signed MoU establishes a collaborative framework between the two non-profit organisations, leveraging ENCS’ expertise in security testing alongside DIVD’s proficiency in coordinated vulnerability disclosure and Common Vulnerabilities and Exposures (CVE) registration. This strategic partnership is effective immediately.
Identify and resolve vulnerabilities
ENCS and DIVD are set to jointly address vulnerabilities in high-power IoT components
As part of the agreement, ENCS and DIVD are set to jointly address vulnerabilities in high-power IoT components. During the General Assembly, ENCS introduced its high power IoT security testing programme, featuring a hacking demonstration that emphasised the need for coordinated vulnerability discovery and responsible disclosure within critical infrastructure.
Vulnerabilities detected by ENCS security professionals will be managed through DIVD's disclosure and CVE protocols. Additionally, ENCS experts will participate in DIVD's testing activities and events.
Alignment with EU priorities
This collaboration is in line with the EU's increasing attention to enhancing vulnerability management for critical infrastructure, as outlined in the Cyber Resilience Act. With energy systems becoming more digital and interconnected, the impact of vulnerabilities on a cross-border scale is significant.
Reinforcing responsible disclosure
Anjos Nijk, Managing Director of ENCS, stated, “Strengthening Europe’s cyber resilience requires close cooperation across the cybersecurity ecosystem. This agreement enhances our ability to identify and resolve vulnerabilities affecting critical infrastructure, while reinforcing responsible disclosure practices that help reduce risk for grid operators and other essential service providers.”
Chris van ’t Hof, Director of DIVD, remarked, “Effective vulnerability disclosure depends on trust, coordination and technical expertise. By working with ENCS and its community of security specialists and infrastructure stakeholders, we can help ensure vulnerabilities in high-impact systems are handled efficiently and responsibly.”
Involvement of critical infrastructure operators
Maarten Noom, Director Asset Management at Enexis and Chair of the ENCS General Assembly meeting, expressed, “With its deep industry knowledge and extensive network, ENCS has proven to be a valuable partner, making a crucial difference in addressing real cyber threats to our critical infrastructure.”
During the General Assembly, ENCS members named Wolfgang Löw, CISO of EVN Group, as Chair of the ENCS Assembly Committee. Commenting on his appointment, Löw said, “I am grateful for the trust of the ENCS Assembly, and I look forward to supporting ENCS in strengthening Europe’s cyber resilience. The partnership with DIVD is an important milestone: timely insight into vulnerabilities in high-impact systems is essential for critical infrastructure operators to initiate effective protective measures at an early stage. This collaboration underscores ENCS’ leadership in driving coordinated vulnerability discovery and resolution across the energy sector.”
