systematic nor comprehensive24; cyberattacks may be only one facet of concerted malicious
attacks against European societies. There is currently only limited mutual operational
assistance between Member States, and no operational mechanism is in place between
Member States and EU institutions, agencies and bodies, in the event of a large-scale, crossborder cyber incidents or crisis25.
Improving cybersecurity is therefore essential for people to trust, use, and benefit from
innovation, connectivity and automation, and for safeguarding fundamental rights and
freedoms, including the rights to privacy and to the protection of personal data, and the
freedom of expression and information. Cybersecurity is indispensable to the network
connectivity and the global and open Internet that must underpin the transformation of the
economy and society in the 2020s. It contributes to better and more jobs, more flexible
workplaces, more efficient and sustainable transport and farming, and easier and fairer access
to health services. It is also essential for the transition to cleaner energy under the European
Green Deal26, through cross-border grids and smart meters and avoiding unnecessary
duplication of data storage. Lastly, it is essential to international security and stability and the
development of economies, democracies and societies globally. Governments, businesses and
individuals need therefore to use digital tools in a responsible, security-conscious manner.
Cybersecurity awareness and hygiene must underpin the digital transformation of everyday
activities.
The EU’s new Cybersecurity Strategy for the Digital Decade forms a key component of
Shaping Europe’s Digital Future27, the Commission’s Recovery Plan for Europe28, the
Security Union Strategy 2020-202529, the Global Strategy for the EU’s Foreign and Security
Policy30, and the European Council Strategic Agenda 2019-202431. It sets out how the EU
will shield its people, businesses and institutions from cyber threats, and how it will advance
international cooperation and lead in securing a global and open Internet.
II.
THINKING GLOBAL, ACTING EUROPEAN
This strategy aims to ensure a global and open Internet with strong guardrails to address the
risks to the security and fundamental rights and freedoms of people in Europe. Following the
progress achieved under the previous strategies, it contains concrete proposals for deploying
three principal instruments –regulatory, investment and policy instruments – to address
three areas of EU action – (1) resilience, technological sovereignty and leadership, (2)
building operational capacity to prevent, deter and respond, and (3) advancing a global
and open cyberspace. The EU is committed to supporting this strategy through an
unprecedented level of investment in the EU's digital transition over the next seven
24
Member States are required to provide an annual summary report to the Cooperation Group on the
notifications received under Article 10(3) of the Directive on security of network and information systems
(Directive (EU) 2016/1148).
25
Standard Operating Procedures are in place for mutual assistance among members of the CSIRTs Network.
26
The European Green Deal, COM(2019) 640 final.
27
Shaping Europe’s Digital Future, COM(2020) 67 final.
28
Europe’s moment: Repair and Prepare for the Next Generation, COM (2020) 98 final.
29
The EU Security Union Strategy 2020-2025, COM(2020) 605 final.
30
https://eeas.europa.eu/topics/eu-global-strategy_en
31
https://www.consilium.europa.eu/en/press/press-releases/2019/06/20/a-new-strategic-agenda-2019-2024/#
4