Improving civilian cyber security is an important factor which contributes to overall network and information security resilience. The proposal for a Directive on Network and Information Security (NIS) is expected to increase preparedness at the national level, and strengthen cooperation at Union level between Member States both at strategic and operational level. This cooperation should involve both national authorities overseeing cybersecurity policies as well as national CERTs and CERT-EU. The public-private NIS platform aims to identify technologically neutral best practices to enhance cybersecurity and develop incentives to adopt secure ICT solutions. Research and technology in cooperation with the private sector and academia Operators of infrastructure and Information and Communication Technology (ICT) services for civilian and defence purposes are confronted with similar cyber security challenges, as a result of common technology and operational capability requirements. Common R&T needs and common requirements for systems are anticipated to improve the interoperability of systems in the long run, as well as to reduce the costs of solutions development. Achieving economies of scale is a necessity in order to face the ever increasing number of threats and vulnerabilities. This should in turn facilitate the preservation and growth of a competitive cyber defence industry in Europe. Cyber defence capability development has an important R&T dimension. Within the framework of the Cyber Defence Research Agenda (CDRA) the EDA has provided a sound basis for the prioritisation of future R&T spending and capability development in both national and European environment. The development of strong technological capacities in Europe to mitigate threats and vulnerabilities is essential. Industry will remain the primary driver for cyber defence related technology and innovation. So it will be crucial to maintain close cooperation with the private sector, seeking synergy with civilian solutions, services and capabilities wherever possible (in particular in cryptography, embedded systems, malware detection, simulation and visualisation techniques, network and communication systems protection, identification and authentication technology areas). It is also important to foster an assured and competitive European industrial cyber security supply chain by supporting the development of a robust European cybersecurity sector including through involvement with Small and Medium sized Entreprises (SMEs). 15585/14 ANNEX FP/oza DG C 2B 9 EN

Select target paragraph3