years – potentially quadrupling previous levels – as part of new technological and industrial
policies and the recovery agenda32.
Cybersecurity must be integrated into all these digital investments, particularly key
technologies like Artificial Intelligence (AI), encryption and quantum computing, using
incentives, obligations and benchmarks. This can stimulate the growth of the European
cybersecurity industry and provide the certainty needed to ease the phasing out of legacy
systems. The European Defence Fund (EDF) will support European cyber defence solutions,
as part of the European defence technological and industrial base. Cybersecurity is included
in external financial instruments to support our partners, notably the Neighbourhood,
Development and International Cooperation Instrument. Preventing the misuse of
technologies, protecting critical infrastructure and ensuring the integrity of supply chains also
enables the EU’s adherence to the UN norms, rules and principles of responsible state
behaviour33.
1. RESILIENCE, TECHNOLOGICAL SOVEREIGNTY AND LEADERSHIP
The EU’s critical infrastructure and essential services are increasingly interdependent and
digitised. All Internet-connected things in the EU, whether automated cars, industrial control
systems or home appliances, and the whole supply chains which make them available, need
to be secure-by-design, resilient to cyber incidents, and quickly patched when vulnerabilities
are discovered. This is fundamental to provide the EU’s private and public sector with the
possibility to choose from the most secure infrastructures and services. The upcoming decade
is the EU’s opportunity to lead in the development of secure technologies across the whole
supply chain. Ensuring resilience and stronger industrial and technology capacities in
cybersecurity should mobilise all necessary regulatory, investment and policy instruments.
Cybersecurity by design for industrial processes, operations and devices can mitigate risks,
potentially reduce costs to companies as well as to wider society, and thereby increase
resilience.
1.1
Resilient infrastructure and critical services
EU rules on the security of Network and Information Systems (NIS) are at the core of the
Single Market for cybersecurity. The Commission proposes to reform these rules under a
revised NIS Directive to increase the level of cyber resilience of all relevant sectors, public
and private, that perform an important function for the economy and society 34. The
review is necessary to reduce inconsistencies across the internal market by aligning scope,
security and incident reporting requirements, national supervision and enforcement and the
capabilities of competent authorities.
A reformed NIS Directive will provide the basis for more specific rules that are also
necessary for strategically important sectors, including energy, transport and health. In order
to ensure a consistent approach as announced under the Security Union Strategy 2020-2025,
32
Investments in the whole digital technology supply chain, contributing to the digital transition or to addressing
the challenges resulting from it, should amount to at least 20% - equivalent to €134.5 billion - of the €672.5
billion Recovery and Resilience Facility, consisting of grants and loans. EU funding in the 2021-2027
Multiannual Financial Framework envisaged for cybersecurity under the Digital Europe Programme, and for
cybersecurity research under Horizon Europe, with special focus on support for SMEs, could amount to €2
billion overall, plus Member States and industry investment.
33
https://undocs.org/A/70/174
34
[insert reference to NIS proposal ]
5