201813. The impact of a cyberattack often cannot be isolated, and can trigger chain reactions
throughout the economy and society, affecting millions of individuals14.
The investigation of nearly all types of crime has a digital component. In 2019, the
number of year-on-year incidents was reported to have trebled. There are an estimated 700
million new samples of malware – the most frequent means of furthering a cyberattack15. The
annual cost of cybercrime to the global economy in 2020 is estimated to be €5.5 trillion,
double that of 201516. This represents the largest transfer of economic wealth in history,
greater than the global drugs trade. For one major incident, the WannaCry ransomware attack
in 2017, the cost to the global economy was estimated at over €6.5 billion17.
Digital services and the finance sector are among the most frequent targets of
cyberattacks, along with the public sector and manufacturing, yet cyber readiness and
awareness among businesses and individuals remain low18, and there is a major
shortage of cybersecurity skills in the workforce19. There were almost 450 cybersecurity
incidents in 2019 involving European critical infrastructures like finance and energy20.
Healthcare organisations and professionals have been hit especially hard during the
pandemic. As technology becomes inextricable from the physical world, cyberattacks put
lives and the wellbeing of the most vulnerable at risk21. Over two-thirds of companies, in
particular SMEs, are considered ‘novices’ in cybersecurity, and European companies are
considered less well prepared than companies in Asia and America22. An estimated 291 000
posts for cybersecurity professionals in Europe remain unfilled. Hiring and training
cybersecurity experts is a slow process leading to greater cybersecurity risks for
organisations23.
The EU lacks collective situational awareness of cyber threats. This is because national
authorities do not systematically gather and share information - such as that available from
the private sector - which could help assess the state of cybersecurity in the EU. Only a
fraction of incidents are reported by Member States, and information sharing is neither
13
Annual Cost of a Data Breach Report, 2020 Ponemon Institute, and based on quantitative analysis of 524
recent
breaches
across
17
geographies
and
17
industries;
https://www.capita.com/sites/g/files/nginej146/files/2020-08/Ponemon-Global-Cost-of-Data-Breach-Study2020.pdf
14
Report
from
Joint
Research
Centre
(JRC),
‘Cybersecurity,
our
digital
anchor’;
https://ec.europa.eu/jrc/en/publication/eur-scientific-and-technical-research-reports/cybersecurity-our-digitalanchor
15
Source: AV-TEST, https://www.av-test.org/en/statistics/malware/
16
JRC, Cybersecurity – Our Digital Anchor.
17
Source: Cyence.
18
Business awareness remains low also with respect to the cyber-theft of trade secrets, especially among SMEs;
PwC, Study on the scale and impact of industrial espionage and theft of trade secrets through cyber:
Dissemination report on measures to tackle and prevent cyber-theft of trade secrets, 2018.
19
See ENISA Threat Landscape 2020. Also, Verizon Data Breach Investigations Report 2020;
https://enterprise.verizon.com/resources/reports/dbir/
20
https://ec.europa.eu/eurostat/documents/2995521/10335060/9-13012020-BP-EN.pdf/f1060f2b-b141-b2507f51-85c9704a5a5f
21
Ransomware has been used to target hospitals and health records, e.g. Romania (June 2020), Düsseldorf
(September 2020) and Vastaamo (October 2020).
22
PwC, The Global State of Information Security 2018; ESI Thoughtlab, The Cybersecurity Imperative, 2019.
23
EU Agency for Cybersecurity, Cybersecurity Skills Development in the EU: The certification of cybersecurity
degrees and ENISA’s Higher Education Database, December 2019.
3