the reformed Directive is proposed together with a review of the legislation on the resilience
of critical infrastructure35. Energy technologies embedding digital components and the
security of the associated supply chains are important for the continuity of essential services
and for the strategic control of critical energy infrastructure. The Commission will therefore
propose measures, including a ‘network code’ setting rules for cybersecurity in cross-border
electricity flows for adoption by end 2022. The financial sector must also strengthen digital
operational resilience and ensure an ability to withstand all types of ICT-related disruptions
and threats, as the Commission has proposed36. In transport, the Commission added
provisions on cybersecurity37 to the EU legislation on aviation security and will continue its
efforts to enhance cyber resilience across all transport modes. Strengthening the cyber
resilience of democratic processes and institutions is a core component of the European
Democracy Action Plan for safeguarding and promoting free elections, and democratic
discourse and media plurality38. Finally, for the security of infrastructure and services under
the future Space Programme, the Commission will continue to proceed with a deepening of
the Galileo cybersecurity strategy for the next generation of Global Navigation Satellite
System services, and other new components of the Space Programme39.
1.2 Building a European Cyber Shield
With the spread of connectivity and the growing sophistication of cyberattacks, Information
Sharing and Analysis Centres, or ISACs, perform a valuable function, including at the
sectoral level, in allowing information exchange between multiple stakeholders on cyber
threats40. In addition to this, networks and computer systems require constant monitoring and
analysis to detect intrusions and anomalies in real time. Many private companies, public
organisations and national authorities have therefore set up Computer Security Incident
Response Teams (CSIRTs) and Security Operations Centres, or ‘SOCs’.
Security Operations Centres are vital for collecting logs 41 and isolating suspicious events
occurring on the communication networks they monitor. They do this through signal and
pattern identification and threat knowledge extraction from the large quantities of data that
need to be assessed. They have contributed to the detection of the activities of malicious
executables and in turn helped contain cyberattacks. The work required in these centres is
highly demanding and fast-paced, which is why AI and in particular machine learning
techniques can provide invaluable support to practitioners42.
35
[insert reference to proposal for a directive on resilience of critical entities]
Proposal for a regulation on digital operational resilience for the financial sector and amending Regulations
(EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014 and (EU) No 909/2014, COM/2020/595 final.
37
Commission Implementing Regulation 2019/1583.
38
Communication on the European Democracy Action Plan COM(2020) 790. Under the plan, the European
Cooperation Network on Elections, Member State election networks will support the deployment of joint expert
teams
to
counter
threats
–
including
cyberthreats
to
electoral
processes;
https://ec.europa.eu/info/policies/justice-and-fundamental-rights/eu-citizenship/electoral-rights/europeancooperation-network-elections_en
39
This includes new governmental satellite communications initiative (GOVSATCOM) and Space Debris (SST)
40
https://www.enisa.europa.eu/topics/national-cyber-security-strategies/information-sharing
41
In such a manner that law enforcement and the judiciary can use them as evidence.
42
Source: survey by Ponemon Institute Research, ‘Improving the Effectiveness of the SOC, 2019’; for studies on
the use of AI in Security Operation Centres see for example: Khraisat, A., Gondal, I., Vamplew, P. et al. Survey
of intrusion detection systems: techniques, datasets and challenges, Cybersecur 2, 20 (2019).
36
6