the reformed Directive is proposed together with a review of the legislation on the resilience of critical infrastructure35. Energy technologies embedding digital components and the security of the associated supply chains are important for the continuity of essential services and for the strategic control of critical energy infrastructure. The Commission will therefore propose measures, including a ‘network code’ setting rules for cybersecurity in cross-border electricity flows for adoption by end 2022. The financial sector must also strengthen digital operational resilience and ensure an ability to withstand all types of ICT-related disruptions and threats, as the Commission has proposed36. In transport, the Commission added provisions on cybersecurity37 to the EU legislation on aviation security and will continue its efforts to enhance cyber resilience across all transport modes. Strengthening the cyber resilience of democratic processes and institutions is a core component of the European Democracy Action Plan for safeguarding and promoting free elections, and democratic discourse and media plurality38. Finally, for the security of infrastructure and services under the future Space Programme, the Commission will continue to proceed with a deepening of the Galileo cybersecurity strategy for the next generation of Global Navigation Satellite System services, and other new components of the Space Programme39. 1.2 Building a European Cyber Shield With the spread of connectivity and the growing sophistication of cyberattacks, Information Sharing and Analysis Centres, or ISACs, perform a valuable function, including at the sectoral level, in allowing information exchange between multiple stakeholders on cyber threats40. In addition to this, networks and computer systems require constant monitoring and analysis to detect intrusions and anomalies in real time. Many private companies, public organisations and national authorities have therefore set up Computer Security Incident Response Teams (CSIRTs) and Security Operations Centres, or ‘SOCs’. Security Operations Centres are vital for collecting logs 41 and isolating suspicious events occurring on the communication networks they monitor. They do this through signal and pattern identification and threat knowledge extraction from the large quantities of data that need to be assessed. They have contributed to the detection of the activities of malicious executables and in turn helped contain cyberattacks. The work required in these centres is highly demanding and fast-paced, which is why AI and in particular machine learning techniques can provide invaluable support to practitioners42. 35 [insert reference to proposal for a directive on resilience of critical entities] Proposal for a regulation on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014 and (EU) No 909/2014, COM/2020/595 final. 37 Commission Implementing Regulation 2019/1583. 38 Communication on the European Democracy Action Plan COM(2020) 790. Under the plan, the European Cooperation Network on Elections, Member State election networks will support the deployment of joint expert teams to counter threats – including cyberthreats to electoral processes; https://ec.europa.eu/info/policies/justice-and-fundamental-rights/eu-citizenship/electoral-rights/europeancooperation-network-elections_en 39 This includes new governmental satellite communications initiative (GOVSATCOM) and Space Debris (SST) 40 https://www.enisa.europa.eu/topics/national-cyber-security-strategies/information-sharing 41 In such a manner that law enforcement and the judiciary can use them as evidence. 42 Source: survey by Ponemon Institute Research, ‘Improving the Effectiveness of the SOC, 2019’; for studies on the use of AI in Security Operation Centres see for example: Khraisat, A., Gondal, I., Vamplew, P. et al. Survey of intrusion detection systems: techniques, datasets and challenges, Cybersecur 2, 20 (2019). 36 6

Select target paragraph3